|
Log-Analyse und Auswertung: Windows blockiert-Aufforderung: bitte zahlen!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.04.2012, 09:04 | #1 | |
| Windows blockiert-Aufforderung: bitte zahlen! Hallo, seit gestern Abend funktioniert mein PC nicht mehr, es erscheint immer eine Aufforderung: Windows funktioniert nicht mehr - bitte zahlen. Ich hab dann unter dem anderen Nutzer ein bischen in euerm Forum gestöbert und schon mal im abgesicherten Modus OTL laufen lassen, was folgenden liefert: Zitat:
Kann mir bitte jemand helfen? Vielen Dank schon mal im Vorraus!!! |
13.04.2012, 10:42 | #2 |
/// Malware-holic | Windows blockiert-Aufforderung: bitte zahlen! hi
__________________dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code:
ATTFilter :OTL O4 - HKU\S-1-5-21-956422759-1335185491-3708336468-1001..\Run: [SkypePM] C:\Users\Wombatsfamily\AppData\Local\Skype\SkypePM.exe (Microsoft Corporation) :Files C:\Users\Wombatsfamily\AppData\Local\Skype :Commands [purity] [EMPTYFLASH] [emptytemp] [Reboot] • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! Drücke bitte die + E Taste.
__________________ |
13.04.2012, 13:33 | #3 | |
| Windows blockiert-Aufforderung: bitte zahlen! Vielen Dank!
__________________Also jetzt bekam ich folgenden Text: Zitat:
Der Upload hat gleich funktioniert. Vielen Dank noch einmal!!! Bin ich jetzt das lästige Ding los? |
13.04.2012, 14:54 | #4 | |
/// Malware-holic | Windows blockiert-Aufforderung: bitte zahlen! dann mal weiter: Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!Downloade dir bitte Combofix von einem dieser Downloadspiegel Link 1 Link 2 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
13.04.2012, 19:59 | #5 |
| Windows blockiert-Aufforderung: bitte zahlen! ok, vielen dank. hier der text: Combofix Logfile: Code:
ATTFilter ComboFix 12-04-13.01 - Wombatsfamily 13.04.2012 20:31:16.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6038.4000 [GMT 2:00] ausgeführt von:: c:\users\Wombatsfamily\Desktop\ComboFix.exe AV: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming . . ((((((((((((((((((((((( Dateien erstellt von 2012-03-13 bis 2012-04-13 )))))))))))))))))))))))))))))) . . 2012-04-13 18:45 . 2012-04-13 18:45 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2012-04-13 18:45 . 2012-04-13 18:45 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-04-13 12:29 . 2012-04-13 12:30 -------- d-----w- c:\programdata\WinZip 2012-04-13 12:11 . 2012-04-13 12:31 -------- d-----w- C:\_OTL 2012-04-12 18:22 . 2012-04-12 18:22 -------- d-----w- c:\programdata\Graboid Inc 2012-04-12 18:22 . 2012-04-12 18:22 -------- d-----w- c:\users\Wombatsfamily\AppData\Local\Geckofx 2012-04-12 18:20 . 2012-04-12 18:42 -------- d-----w- c:\program files (x86)\Graboid 2012-04-11 10:38 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-11 10:38 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll 2012-04-11 10:38 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll 2012-04-11 10:38 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2012-04-11 10:38 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll 2012-04-11 10:38 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2012-04-11 10:38 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2012-04-07 17:03 . 2012-04-07 17:12 -------- d-----w- c:\users\Wombatsfamily\AppData\Local\Spotify 2012-04-07 17:02 . 2012-04-13 18:17 -------- d-----w- c:\users\Wombatsfamily\AppData\Roaming\Spotify 2012-04-06 09:04 . 2012-04-06 09:04 -------- d-----w- c:\program files\Dell Support Center 2012-04-01 18:45 . 2012-04-01 18:45 8767136 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-04-01 18:34 . 2012-04-01 18:45 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-03-22 11:17 . 2012-03-22 11:17 592824 ----a-w- c:\program files (x86)\Mozilla Firefox\gkmedias.dll 2012-03-22 11:17 . 2012-03-22 11:17 44472 ----a-w- c:\program files (x86)\Mozilla Firefox\mozglue.dll 2012-03-14 19:30 . 2012-04-12 14:44 -------- d-----w- c:\users\Janina\AppData\Roaming\Skype . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-01 18:45 . 2012-01-26 20:00 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-08 09:08 . 2012-03-08 09:08 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2012-03-01 01:07 . 2012-03-01 01:07 162664 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin 2012-02-17 06:38 . 2012-03-13 21:26 1031680 ----a-w- c:\windows\system32\rdpcore.dll 2012-02-17 05:34 . 2012-03-13 21:26 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll 2012-02-17 04:58 . 2012-03-13 21:26 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-17 04:57 . 2012-03-13 21:26 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-14 10:09 . 2012-02-14 10:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2012-02-10 06:36 . 2012-03-13 21:28 1544192 ----a-w- c:\windows\system32\DWrite.dll 2012-02-10 05:38 . 2012-03-13 21:28 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll 2012-02-03 04:34 . 2012-03-13 21:28 3145728 ----a-w- c:\windows\system32\win32k.sys 2012-02-02 18:49 . 2010-06-24 17:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-01-31 22:23 . 2012-01-31 22:23 49152 ----a-r- c:\users\Wombatsfamily\AppData\Roaming\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe 2012-01-31 22:21 . 2012-01-31 22:21 335872 ----a-r- c:\users\Wombatsfamily\AppData\Roaming\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe 2012-01-31 22:12 . 2003-03-19 01:05 106496 ----a-w- c:\windows\SysWow64\ATL71.DLL 2012-01-31 22:01 . 2012-01-31 22:01 57344 ----a-r- c:\users\Wombatsfamily\AppData\Roaming\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe 2012-01-26 21:42 . 2012-01-26 21:42 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe 2012-01-26 21:42 . 2012-01-26 21:42 778752 ----a-w- c:\windows\system32\mssvp.dll 2012-01-26 21:42 . 2012-01-26 21:42 75264 ----a-w- c:\windows\system32\msscntrs.dll 2012-01-26 21:42 . 2012-01-26 21:42 666624 ----a-w- c:\windows\SysWow64\mssvp.dll 2012-01-26 21:42 . 2012-01-26 21:42 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll 2012-01-26 21:42 . 2012-01-26 21:42 591872 ----a-w- c:\windows\system32\SearchIndexer.exe 2012-01-26 21:42 . 2012-01-26 21:42 491520 ----a-w- c:\windows\system32\mssph.dll 2012-01-26 21:42 . 2012-01-26 21:42 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2012-01-26 21:42 . 2012-01-26 21:42 427520 ----a-w- c:\windows\SysWow64\SearchIndexer.exe 2012-01-26 21:42 . 2012-01-26 21:42 337408 ----a-w- c:\windows\SysWow64\mssph.dll 2012-01-26 21:42 . 2012-01-26 21:42 31232 ----a-w- c:\windows\SysWow64\prevhost.exe 2012-01-26 21:42 . 2012-01-26 21:42 31232 ----a-w- c:\windows\system32\prevhost.exe 2012-01-26 21:42 . 2012-01-26 21:42 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2012-01-26 21:42 . 2012-01-26 21:42 288256 ----a-w- c:\windows\system32\mssphtb.dll 2012-01-26 21:42 . 2012-01-26 21:42 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe 2012-01-26 21:42 . 2012-01-26 21:42 2315776 ----a-w- c:\windows\system32\tquery.dll 2012-01-26 21:42 . 2012-01-26 21:42 2223616 ----a-w- c:\windows\system32\mssrch.dll 2012-01-26 21:42 . 2012-01-26 21:42 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll 2012-01-26 21:42 . 2012-01-26 21:42 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe 2012-01-26 21:42 . 2012-01-26 21:42 1549312 ----a-w- c:\windows\SysWow64\tquery.dll 2012-01-26 21:42 . 2012-01-26 21:42 1401344 ----a-w- c:\windows\SysWow64\mssrch.dll 2012-01-26 21:42 . 2012-01-26 21:42 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe 2012-01-26 21:42 . 2012-01-26 21:42 861696 ----a-w- c:\windows\system32\oleaut32.dll 2012-01-26 21:42 . 2012-01-26 21:42 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax 2012-01-26 21:42 . 2012-01-26 21:42 613888 ----a-w- c:\windows\system32\psisdecd.dll 2012-01-26 21:42 . 2012-01-26 21:42 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll 2012-01-26 21:42 . 2012-01-26 21:42 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll 2012-01-26 21:42 . 2012-01-26 21:42 331776 ----a-w- c:\windows\system32\oleacc.dll 2012-01-26 21:42 . 2012-01-26 21:42 233472 ----a-w- c:\windows\SysWow64\oleacc.dll 2012-01-26 21:42 . 2012-01-26 21:42 108032 ----a-w- c:\windows\system32\psisrndr.ax 2012-01-26 21:42 . 2012-01-26 21:42 81920 ----a-w- c:\windows\SysWow64\odbccr32.dll 2012-01-26 21:42 . 2012-01-26 21:42 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll 2012-01-26 21:42 . 2012-01-26 21:42 212992 ----a-w- c:\windows\system32\odbctrac.dll 2012-01-26 21:42 . 2012-01-26 21:42 163840 ----a-w- c:\windows\SysWow64\odbctrac.dll 2012-01-26 21:42 . 2012-01-26 21:42 163840 ----a-w- c:\windows\system32\odbccp32.dll 2012-01-26 21:42 . 2012-01-26 21:42 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll 2012-01-26 21:42 . 2012-01-26 21:42 106496 ----a-w- c:\windows\system32\odbccu32.dll 2012-01-26 21:42 . 2012-01-26 21:42 106496 ----a-w- c:\windows\system32\odbccr32.dll 2012-01-26 21:42 . 2012-01-26 21:42 86016 ----a-w- c:\windows\SysWow64\odbccu32.dll 2012-01-26 21:42 . 2012-01-26 21:42 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2012-01-26 21:42 . 2012-01-26 21:42 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2012-01-26 21:42 . 2012-01-26 21:42 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-01-26 21:42 . 2012-01-26 21:42 421888 ----a-w- c:\windows\system32\KernelBase.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 362496 ----a-w- c:\windows\system32\wow64win.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 338432 ----a-w- c:\windows\system32\conhost.exe 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll 2012-01-26 21:42 . 2012-01-26 21:42 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408] "Spotify"="c:\users\Wombatsfamily\AppData\Roaming\Spotify\Spotify.exe" [2012-04-07 4011184] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942] "Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-11-22 1675160] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-04-04 35736] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-01 136176] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 253600] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [x] R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-01 136176] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [x] R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-03-08 224704] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-10-19 661504] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-10-21 135440] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-12-06 208536] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-04 687400] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-22 2009704] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-22 378472] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [x] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064] S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 cyhid;Cypress Input Device;c:\windows\system32\DRIVERS\cyhid.sys [x] S3 cykbfltrService;Cypress Keyboard Filter Driver;c:\windows\system32\DRIVERS\cykbfltr.sys [x] S3 cymfltrService;Cypress Trackpad Filter Driver;c:\windows\system32\DRIVERS\cymfltr.sys [x] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - mfeavfk01 . Inhalt des "geplante Tasks" Ordners . 2012-04-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 18:45] . 2012-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-01 21:08] . 2012-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-01 21:08] . 2012-03-06 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-03-28 23:04] . 2012-04-13 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-03-28 23:04] . 2012-04-13 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-03-28 23:04] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CyCpIo"="c:\program files\Cypress\TrackPad\CyCpIo.exe" [2011-10-20 2375168] "CyHidWin"="c:\program files\Cypress\TrackPad\CyHidWin.exe" [2011-10-19 2354176] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-05-26 7214696] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024] "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-04-22 312936] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-10-18 10357008] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-07-13 4146848] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-06-28 2022976] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.hiergehtslos.de/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 Trusted Zone: samsungsetup.com\www TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Wombatsfamily\AppData\Roaming\Mozilla\Firefox\Profiles\29h61fnx.default\ FF - prefs.js: browser.startup.homepage - Google . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Toolbar-Locked - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2012-04-13 20:51:48 ComboFix-quarantined-files.txt 2012-04-13 18:51 . Vor Suchlauf: 13 Verzeichnis(se), 194.432.589.824 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 193.678.422.016 Bytes frei . - - End Of File - - 31362B87B7F839E61367D489A919375A |
14.04.2012, 20:11 | #6 |
/// Malware-holic | Windows blockiert-Aufforderung: bitte zahlen! malwarebytes: Downloade Dir bitte Malwarebytes
__________________ --> Windows blockiert-Aufforderung: bitte zahlen! |
15.04.2012, 18:14 | #7 | |
| Windows blockiert-Aufforderung: bitte zahlen! Vielen Dank. Also er hat nix gefunden... Zitat:
|
Themen zu Windows blockiert-Aufforderung: bitte zahlen! |
adobe, adobe flash player, autorun, bho, defender, document, error, explorer, firefox, flash player, format, funktioniert nicht mehr, google earth, helper, home, logfile, mcafee windows bezahlen, microsoft, monitor, mozilla thunderbird, nicht starten, nvidia, nvpciflt.sys, nvstor.sys, plug-in, realtek, registry, required, rundll, scan, searchscopes, software, starten, version=1.0, windows, winlogon, winlogon.exe, wscript.exe |