|
Plagegeister aller Art und deren Bekämpfung: Polizeivirus ÖsterreichWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.08.2012, 17:51 | #1 |
| Polizeivirus Österreich Hallo liebes Trojaner-Board Team, ich bin froh bei euch bzgl. meinem aktuellen Fall des Polizei Virus gefunde zu haben. Ich hoffe ihr könnt mir helfen. Ich habe mir heute Nachmittag den Polizei Virus (Österreich Version) eingefangen (zeigt eine Polizeiseite, die sich nicht mehr entfernen lässt und mich drängt 100€ zu überweisen). Habe Windows 7 (64 bit). Scan mit McAffee Total Protection hat nichts geholfen.Malwarebytes (aktuellste Versionen) hat mehrere Probleme gefunden, welche ich unter Quarantäne gestellt habe. Habe wie von euch empfohlen den Defogger laufen lassen (ohne error) und OTL laufen lassen. Sämtliche Logfiles (Malwarebytes, Defogger, OTL) befinden sich im Anhang. Ich hoffe Ihr könnt mir dabei helfen meinen erst einen Monat alten Laptop zu bereinigen. Falls ihr weitere Infos benötigt stelle ich euch diese gerne zur Verfügung. Vielen Dank im Voraus und schöne Grüße aus Österreich, Alex |
02.08.2012, 05:25 | #2 |
/// Helfer-Team | Polizeivirus ÖsterreichFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.) IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{FAD81A55-6E74-4C0B-A61B-45B4091FBCD5}: "URL" = http://rover.ebay.com/rover/1/5221-29898-16445-29/4?mpre=http://shop.ebay.at/?oemInLn=ieSrch-Q112&_nkw={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\media\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 :Files C:\Users\media\AppData\Local\Temp\* ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
02.08.2012, 18:55 | #3 |
| Polizeivirus Österreich Hallo t'john,
__________________vielen Dank. Ich bin deinen Anweisungen gefolgt. Anbei findest du das Logfile des Fixes. Gruß, Alex Code:
ATTFilter All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}\ deleted successfully. File move failed. c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll scheduled to be moved on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FAD81A55-6E74-4C0B-A61B-45B4091FBCD5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FAD81A55-6E74-4C0B-A61B-45B4091FBCD5}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface deleted successfully. C:\Users\media\AppData\Local\Akamai\netsession_win.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\An OneNote s&enden\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xcel exportieren\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\An OneNote s&enden\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xcel exportieren\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! ========== FILES ========== C:\Users\media\AppData\Local\Temp\+~JF1009139747219330962.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1033561589781497990.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1062984928437181884.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1116231677917700145.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1148630582044115878.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF124570987245087506.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF125127215752284804.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1257460213829940506.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1325913713178127477.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF135433206181382624.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1390055932585697578.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1462542099964841897.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1491401577231741866.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1524061349459023613.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF155537535953553623.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1558571944403788194.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1634196529497866814.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1686453567336350040.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1797842263273061011.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1840121435556919518.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1888986143185254834.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1891281540579760980.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1892607761330052567.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF194331776364089036.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF1984085707596753706.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2004554067482016702.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2007298508224182431.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2034679223517953620.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF203700112792410069.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2094742378270027949.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2132796638575226941.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2153922587611353313.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2182159664275634696.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2182900296935795219.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2200098761789057128.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2214255069156164010.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2223192760669591896.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2290870544060737861.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2298370053809170868.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2344149772422531495.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2447063469663454034.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2449900318588453221.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2464047339265347451.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2506051920784335926.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF251009213953703151.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2662379667550413136.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2746797240577862556.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2776254393628656722.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2877293323677090888.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2882275794945043060.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2932696637949766542.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF297855221578036454.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2987971816160990437.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF2990331259175552387.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3022638388465870694.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3036272658752502663.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3086314731205622667.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3095409088598401359.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3123905481088799412.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3159988116791112552.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3160462459924013211.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3367762497209988494.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3480049227302616625.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3616515319433096918.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3698206893640992948.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3731949357795064640.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3757308976121705823.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3802928134982877344.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3803651497915689249.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF382192667278498243.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF38887194810238209.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3989862179225692726.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF3994095064269096419.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4063746196411832902.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4077572485398099041.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4236358342528936053.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4237233595563816179.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4258089503836784850.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4282724690896616241.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4291375299317900970.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4337734027607814154.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4356246730052907051.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4359378749703977275.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4363965616327100526.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4367625786906080886.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4403441150009253500.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4521216491093831236.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4549045119479794911.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4642528028703306698.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4670546804125190876.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4671072706101182785.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4671611352262932214.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4688176721155529568.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4688177676828359583.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF47589891085111716.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4777490745570899972.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4800100234023070316.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4940495218003593630.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF4990203098868096490.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5033152133493625126.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5070268170892577829.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5177086071860183550.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5192962873172459661.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5196093194409038904.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF521063083637411677.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5219499280402778148.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5384839256401717384.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5416573384853386866.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF557779304588316976.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5595215526136944204.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5708055979768193209.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5749208873202890541.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5758584028177344249.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5796449027560108575.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5821606571821553997.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5845420179141558306.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5886354773214398996.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5908722443459319640.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5930667024644124905.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5978226231638265905.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF5996861559266077424.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6077873453226819291.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6099082875755921838.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6124148544476235619.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF62399934214864757.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6240619110883819463.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6269103034764719071.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6371249126935659990.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6386027080829634240.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6386683404134374851.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF642308688846699948.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6426912259268583012.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6470298527091985564.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6512159181574032247.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6515251048385538587.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6539052067405206564.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6559973351301976024.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6575768225113134281.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6603524681767494189.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6678250932652418610.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6829531232294143924.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6967198265260162491.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6976778106695727223.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF6980499128884231367.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7053793049951740072.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7075256120819149989.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7187444781550924219.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7296650002650390893.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7307707731206034143.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7319273403098154465.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7364849769483697414.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7368679277080607460.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7379008274898767037.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7401816716355736479.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7436813823444609074.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7443362138772696754.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7566112359436476393.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF765323847210513043.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7654010413203578369.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF768914981246392090.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7691871387282741012.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7749764118557767666.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7755178060980122251.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7793517655260146122.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF782676584543593319.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF7922709030295032696.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8105023579612863992.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8124819589660377759.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8183744919546062399.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8208178633357491391.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8278342018703125621.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF828502996460119827.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF835798719967217907.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8368720726278135546.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8380258434697155347.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8388422352726261985.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8415655498728254168.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8465129867743162123.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8546058833710007815.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8554997540443286913.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8563123687154316639.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8623601340348644976.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8704730304035083195.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8739380008960240035.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8795135591523308772.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8950321583087494622.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF8982229373487998687.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF9001961382658355323.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF901180487886076649.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF9068722132810155400.tmp moved successfully. C:\Users\media\AppData\Local\Temp\+~JF9076420994667302886.tmp moved successfully. C:\Users\media\AppData\Local\Temp\.Sony_PMBrowser3000_BrowserDiskCache moved successfully. C:\Users\media\AppData\Local\Temp\.Sony_PMBrowser3000_BrowserDiskCache.idx moved successfully. C:\Users\media\AppData\Local\Temp\008ba1a4 folder moved successfully. C:\Users\media\AppData\Local\Temp\42D9.tmp moved successfully. C:\Users\media\AppData\Local\Temp\4F58.tmp moved successfully. C:\Users\media\AppData\Local\Temp\62A8.tmp moved successfully. C:\Users\media\AppData\Local\Temp\6CB6.tmp moved successfully. C:\Users\media\AppData\Local\Temp\Adobe\Online Services folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe\Acrobat\10.0 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe\Acrobat folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\ReadMe folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content\Adobe Premiere Elements 9 HD Content 3 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content\Adobe Premiere Elements 9 HD Content 2 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content\Adobe Premiere Elements 9 HD Content 1 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content\Adobe Premiere Elements 9 Content 3 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content\Adobe Premiere Elements 9 Content 2 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content\Adobe Premiere Elements 9 Content 1 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\PRE 9 Content folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content\Adobe Premiere Elements 9 Content 1 folder moved successfully. C:\Users\media\AppData\Local\Temp\Adobe Premiere Elements 9 Content folder moved successfully. C:\Users\media\AppData\Local\Temp\AdobeARM.log moved successfully. C:\Users\media\AppData\Local\Temp\AllServicesInfoFiles folder moved successfully. C:\Users\media\AppData\Local\Temp\amt3.log moved successfully. C:\Users\media\AppData\Local\Temp\ArcUpdater folder moved successfully. C:\Users\media\AppData\Local\Temp\ArmUI.ini moved successfully. C:\Users\media\AppData\Local\Temp\AUCHECK_PARSER.txt moved successfully. C:\Users\media\AppData\Local\Temp\B135.tmp moved successfully. C:\Users\media\AppData\Local\Temp\boost_interprocess folder moved successfully. C:\Users\media\AppData\Local\Temp\CEF1.tmp moved successfully. C:\Users\media\AppData\Local\Temp\CFG1A91.tmp moved successfully. C:\Users\media\AppData\Local\Temp\CFG30B0.tmp moved successfully. C:\Users\media\AppData\Local\Temp\cfinstall.log moved successfully. C:\Users\media\AppData\Local\Temp\com.adobe.dynamiclinkmanagerCS5 moved successfully. C:\Users\media\AppData\Local\Temp\Commands.xml moved successfully. C:\Users\media\AppData\Local\Temp\config.xml moved successfully. C:\Users\media\AppData\Local\Temp\Cookies folder moved successfully. C:\Users\media\AppData\Local\Temp\F048.dir folder moved successfully. C:\Users\media\AppData\Local\Temp\F048.tmp moved successfully. File move failed. C:\Users\media\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot. C:\Users\media\AppData\Local\Temp\Gast.bmp moved successfully. C:\Users\media\AppData\Local\Temp\History\History.IE5 folder moved successfully. C:\Users\media\AppData\Local\Temp\History folder moved successfully. C:\Users\media\AppData\Local\Temp\hsperfdata_media folder moved successfully. C:\Users\media\AppData\Local\Temp\hs_err_pid1708.log moved successfully. C:\Users\media\AppData\Local\Temp\hs_err_pid5616.log moved successfully. C:\Users\media\AppData\Local\Temp\hs_err_pid5632.log moved successfully. C:\Users\media\AppData\Local\Temp\hs_err_pid5704.log moved successfully. C:\Users\media\AppData\Local\Temp\hs_err_pid7080.log moved successfully. C:\Users\media\AppData\Local\Temp\jar_cache6274958730539423160.tmp moved successfully. C:\Users\media\AppData\Local\Temp\JAUReg.log moved successfully. C:\Users\media\AppData\Local\Temp\java_install.log moved successfully. C:\Users\media\AppData\Local\Temp\java_install_reg.log moved successfully. C:\Users\media\AppData\Local\Temp\jusched.log moved successfully. C:\Users\media\AppData\Local\Temp\Low\hsperfdata_media folder moved successfully. C:\Users\media\AppData\Local\Temp\Low folder moved successfully. C:\Users\media\AppData\Local\Temp\mcaB4CE.tmp folder moved successfully. C:\Users\media\AppData\Local\Temp\McTemp folder moved successfully. C:\Users\media\AppData\Local\Temp\Media Go\PSNStoreUpdate folder moved successfully. C:\Users\media\AppData\Local\Temp\Media Go\Prepared folder moved successfully. C:\Users\media\AppData\Local\Temp\Media Go\Gracenote folder moved successfully. C:\Users\media\AppData\Local\Temp\Media Go\CFUpdate folder moved successfully. C:\Users\media\AppData\Local\Temp\Media Go folder moved successfully. C:\Users\media\AppData\Local\Temp\media.bmp moved successfully. C:\Users\media\AppData\Local\Temp\MGData-3812.tmp moved successfully. C:\Users\media\AppData\Local\Temp\MGData.MediaGo.9564.tmp moved successfully. C:\Users\media\AppData\Local\Temp\msdtadmin folder moved successfully. C:\Users\media\AppData\Local\Temp\MSI21fb0.LOG moved successfully. C:\Users\media\AppData\Local\Temp\MSI23e66.LOG moved successfully. C:\Users\media\AppData\Local\Temp\OOBE(201207091420291170).log moved successfully. C:\Users\media\AppData\Local\Temp\oobelib.log moved successfully. C:\Users\media\AppData\Local\Temp\PDApp.log moved successfully. C:\Users\media\AppData\Local\Temp\PRE901.log moved successfully. C:\Users\media\AppData\Local\Temp\PRE_Files folder moved successfully. C:\Users\media\AppData\Local\Temp\PSEPatcher903.log moved successfully. C:\Users\media\AppData\Local\Temp\QTInstallCode.log moved successfully. C:\Users\media\AppData\Local\Temp\qtplugin.log moved successfully. C:\Users\media\AppData\Local\Temp\RegCompactor folder moved successfully. C:\Users\media\AppData\Local\Temp\repair_config.xml moved successfully. C:\Users\media\AppData\Local\Temp\rss1093.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss11AC.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss11FA.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss141C.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss18BD.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss1C6.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss1D40.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss1D5F.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss2700.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss2A4A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss33AC.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss35AF.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss4BDF.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss4C4B.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss4DA2.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss5188.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss5437.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss5BA.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss5E55.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss6132.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss6891.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss6A08.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss6D52.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss6F07.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss707D.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7203.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss737A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7500.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss753E.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss75DA.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7618.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7702.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7760.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss77FC.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss784A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss785A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7944.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss79EF.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7A3D.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7A5D.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7A5E.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7C7F.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7D69.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7D88.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7DD6.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7EC0.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7EDF.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7EFE.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7F4C.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss7F9A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss817E.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8229.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss82F4.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8381.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss84B9.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss84E7.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss87C5.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss87E4.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss87F3.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8832.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8851.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss88DD.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8B4D.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8BAB.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8C57.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8D50.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8DDD.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss8F15.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss95B9.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss973F.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss978D.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rss9D95.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssA7B.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssAFB0.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssB154.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssB5E6.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssBAA7.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssBBB0.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssBF77.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssC86C.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssD92E.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssD97C.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssD9AB.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssD9BB.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssDB31.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssDB70.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssDEAA.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssDF75.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssE291.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssE2DF.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssE60A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssE926.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssEE82.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssEFD.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssF1DC.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssF1DD.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssF23A.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssF3EF.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssF42D.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssF4F8.tmp moved successfully. C:\Users\media\AppData\Local\Temp\rssFCA6.tmp moved successfully. C:\Users\media\AppData\Local\Temp\Sen19F5.tmp moved successfully. C:\Users\media\AppData\Local\Temp\Sen45F7.tmp moved successfully. C:\Users\media\AppData\Local\Temp\Sen5256.tmp moved successfully. C:\Users\media\AppData\Local\Temp\Sen7A1E.tmp moved successfully. C:\Users\media\AppData\Local\Temp\Sen9F79.tmp moved successfully. C:\Users\media\AppData\Local\Temp\SenBF48.tmp moved successfully. C:\Users\media\AppData\Local\Temp\SetupAdmin1C0C.log moved successfully. C:\Users\media\AppData\Local\Temp\SetupAdmin2F3C.log moved successfully. C:\Users\media\AppData\Local\Temp\SetupAdminB70.log moved successfully. C:\Users\media\AppData\Local\Temp\SetupExe(20120709142106E98).log moved successfully. C:\Users\media\AppData\Local\Temp\SetupExe(201207091428351B50).log moved successfully. C:\Users\media\AppData\Local\Temp\SkypeSetup.exe moved successfully. C:\Users\media\AppData\Local\Temp\StructuredQuery.log moved successfully. C:\Users\media\AppData\Local\Temp\sudo.tmp.vbs moved successfully. C:\Users\media\AppData\Local\Temp\swtag.log moved successfully. C:\Users\media\AppData\Local\Temp\swtlib-32 folder moved successfully. C:\Users\media\AppData\Local\Temp\Temporary Internet Files\Content.IE5\TXCJPCKE folder moved successfully. C:\Users\media\AppData\Local\Temp\Temporary Internet Files\Content.IE5\HI7I7ORR folder moved successfully. C:\Users\media\AppData\Local\Temp\Temporary Internet Files\Content.IE5\CG5GA9IU folder moved successfully. C:\Users\media\AppData\Local\Temp\Temporary Internet Files\Content.IE5\8DSGSTLL folder moved successfully. C:\Users\media\AppData\Local\Temp\Temporary Internet Files\Content.IE5 folder moved successfully. C:\Users\media\AppData\Local\Temp\Temporary Internet Files folder moved successfully. C:\Users\media\AppData\Local\Temp\Theme1HD.log moved successfully. C:\Users\media\AppData\Local\Temp\Theme1SD.log moved successfully. C:\Users\media\AppData\Local\Temp\Theme2HD.log moved successfully. C:\Users\media\AppData\Local\Temp\Theme2SD.log moved successfully. C:\Users\media\AppData\Local\Temp\Theme3HD.log moved successfully. C:\Users\media\AppData\Local\Temp\Theme3SD.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1184-20120619-090731.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1240-20120524-090200.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1308-20120509-085759.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1444-20120523-095558.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1676-20120709-135834.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1704-20120628-134551.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1720-20120531-085345.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1896-20120620-112145.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1912-20120515-084507.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-1964-20120709-145026.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-2060-20120507-090441.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-2236-20120504-092912.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-2656-20120626-085616.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-2988-20120623-085546.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3016-20120612-085716.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3024-20120627-085546.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3172-20120518-085458.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3212-20120511-091544.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3288-20120706-085015.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3328-20120510-085834.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3352-20120507-095205.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3356-20120704-085910.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3416-20120604-085759.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3496-20120702-085426.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3588-20120629-085823.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3596-20120703-084640.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3600-20120512-085546.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3600-20120601-085915.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3604-20120630-090055.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3616-20120705-085950.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3628-20120615-085018.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3680-20120621-085906.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3684-20120526-085902.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3728-20120605-085622.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3732-20120529-090023.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3752-20120628-134919.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3780-20120519-085723.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3812-20120504-114131.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3812-20120707-084849.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3840-20120622-085717.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3852-20120508-092430.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3876-20120618-085812.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3924-20120521-085756.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-3964-20120514-085551.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4064-20120608-085748.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4064-20120709-085700.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-408-20120516-085437.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4236-20120609-085839.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4312-20120613-085828.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4328-20120525-090423.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4332-20120628-113634.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4376-20120602-085928.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4420-20120626-142104.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4456-20120611-090200.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4548-20120530-085956.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4724-20120522-090144.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4768-20120628-085751.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-4952-20120505-085723.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-5000-20120606-085747.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-5048-20120611-121208.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-5072-20120614-090136.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-5108-20120620-090226.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-5264-20120504-112513.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-5276-20120511-085120.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-6940-20120616-085759.log moved successfully. C:\Users\media\AppData\Local\Temp\trayicon-744-20120625-085748.log moved successfully. C:\Users\media\AppData\Local\Temp\vso_dat_extract folder moved successfully. C:\Users\media\AppData\Local\Temp\wls1C59.tmp moved successfully. C:\Users\media\AppData\Local\Temp\wls1D25.tmp moved successfully. C:\Users\media\AppData\Local\Temp\wmplog00.sqm moved successfully. C:\Users\media\AppData\Local\Temp\wmplog01.sqm moved successfully. C:\Users\media\AppData\Local\Temp\wmplog02.sqm moved successfully. C:\Users\media\AppData\Local\Temp\wmsetup.log moved successfully. C:\Users\media\AppData\Local\Temp\WPDNSE folder moved successfully. C:\Users\media\AppData\Local\Temp\wrapper-4156-20120709-150102.log moved successfully. C:\Users\media\AppData\Local\Temp\{01601318-A865-4C92-BAA2-098B43BB8BF3}Exclude.txt moved successfully. C:\Users\media\AppData\Local\Temp\{11D799DE-CC5E-4F82-AEE6-AAA10B6EB89B} folder moved successfully. C:\Users\media\AppData\Local\Temp\{223FDFD1-D5BA-4561-B5E0-103EF6230B6A} folder moved successfully. C:\Users\media\AppData\Local\Temp\{2BD7DE53-9E63-4EDD-A4BE-C7432B3FFA9D} folder moved successfully. C:\Users\media\AppData\Local\Temp\{38BCFE37-B7CB-4090-88BD-9FECE3621C4E} folder moved successfully. C:\Users\media\AppData\Local\Temp\{38D6EEE8-6611-4090-9354-C11134CA501B} folder moved successfully. C:\Users\media\AppData\Local\Temp\{3CB9918D-9221-4E45-B711-357C1F11D761} folder moved successfully. C:\Users\media\AppData\Local\Temp\{3D00FF28-1D1E-4F84-8D12-8D5D3C9729FB} folder moved successfully. C:\Users\media\AppData\Local\Temp\{42170FE1-D060-4FE5-87A7-1EAEA0A7FBCE} folder moved successfully. C:\Users\media\AppData\Local\Temp\{49F685EE-24F7-4E6B-B776-2F4B4DAD2409} folder moved successfully. C:\Users\media\AppData\Local\Temp\{4E459652-AB6C-4CEE-A7D6-95B806B5F917} folder moved successfully. C:\Users\media\AppData\Local\Temp\{5F0C9201-A19B-43C3-BF9A-59AECDB6166B} folder moved successfully. C:\Users\media\AppData\Local\Temp\{87B97E6B-2344-4F27-A563-5126112E5FD9} folder moved successfully. C:\Users\media\AppData\Local\Temp\{8DDD241B-56BF-4F36-AA3A-D8643920C770} folder moved successfully. C:\Users\media\AppData\Local\Temp\{9F9D7867-0097-4DD9-9110-D92110E0D730} folder moved successfully. C:\Users\media\AppData\Local\Temp\{A6A4E492-7554-40BE-9417-82345985F07E} folder moved successfully. C:\Users\media\AppData\Local\Temp\{A7C46C2B-D746-4695-96C2-2B77420E1C04} folder moved successfully. C:\Users\media\AppData\Local\Temp\{A85F5CA4-D9A6-45F3-B415-27254616AF94}Exclude.txt moved successfully. C:\Users\media\AppData\Local\Temp\{B487BAED-5DBF-4BC9-9B8F-B1BB2B90AC51} folder moved successfully. C:\Users\media\AppData\Local\Temp\{B74BC9A8-3EA6-4921-9732-CA10FABC57AC} folder moved successfully. C:\Users\media\AppData\Local\Temp\{E71A50A6-EDD3-46AF-960E-911C82296C81} folder moved successfully. C:\Users\media\AppData\Local\Temp\~DF02477624CAF81D07.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0695B6406DFF8319.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF07AE7DF2291086DA.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0905637B409A843F.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0A63939EE182251E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0C33263D59B41B30.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0C54C98F0E82B61F.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0F8221ADD7B49F8C.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF0FDDF08C0FA78904.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF12BE78D28DA7A068.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF160BC985B0EC82E8.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF18DB35A30E5A42B0.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF193C99AA5B4165E6.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF19A871B635252A47.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF1A850BB8D1E965DB.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF1F613D24C8E040FA.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF22629CF98A71650C.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF237BCFBE7C6A7533.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF25AB83A03B5D2816.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF25F53A9E28DF35A3.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF2BA7096381FEA8B5.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF2C9AD7FC5A32FC0E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF2CD310199BE09998.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF33659BC4BAC9F046.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF340820E518194696.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF3D958FB401E7632A.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF3EBD78A2A4AF4BAB.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF3ED33522200A885E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF40E56D8283BE398A.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF45376234B64B98C9.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF46E7580C3061781A.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF49B442720C6CB71D.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF4AC0956A6E962F60.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF4D256036124AF85C.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF4DC60072F82A35D1.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF4EE50DF39DE26A72.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF535BD7C4C3C83E27.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF5667BE0C04784A4D.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF598C91890AFFDB95.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF5AC83DC4293F57F0.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF5CD42A65AA96D080.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF5E048BACFCEB99E5.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF605A7AF3EE1C98E5.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF61E6A0A1BCDD2C19.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF62D8DF60E60F2032.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF635BACAA190DEB1E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF6C0366971ACDFE09.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF6DF4C44B4B13054B.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF6EA5C50910D5C458.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF742E6AB7CEF801BF.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF75D61B4FF15DA04F.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF79D0F16C4BA9F18A.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF7AE8EB9101FD3EC6.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF7E4C06AF4EE79406.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF7EC2050AF72CD075.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF817884C9BFE9B60C.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF82C4C5C7EEC741E9.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF831BF6C4799C3CB8.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF8373A5BA27A68C7B.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF851770165AAFC75F.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF85D649E5089EEB35.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF8668D6CFA2806482.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF8796196CDBAE9E1D.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF882163C4964F44E0.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF88BC93AE45AA2541.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF88C8557903E324CF.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF89BEF47754A85FF6.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF8A47A64BBB61B45F.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF9019434EDE24521E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF96BC168A1A2B2492.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF980A025D24ED0050.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF9A0E1F741F681022.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF9AFFCBA6105D64E2.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF9D04E84EDAAF1518.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DF9EE09605398E32BA.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFA65B103A703ECE2B.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFA71961F2F58E45A3.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFAAA83F59D3411996.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFABD59F574CEEE487.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFACD927F1B6C8AE81.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFADD95413BE622C49.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFAE0AB2B0B8E5824A.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFB2B62AF0FE828597.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFB740A16039212D6D.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFBA98DE0C01BFA83F.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFC26B3FBFFD0567FE.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFC3B64CE35A6F6E99.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFC47CBE04AB51168E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFC669CF6DEA60E9EF.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFC76C0664FFFEB4A6.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFC9C9B23D51D6180E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFCD66ED4483403053.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFCDFC3A2CC0AD7891.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFD020380727C6F276.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFD2A603F4182228CC.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFD3BE3DAF831545B7.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFD55388A1B8F4FF1D.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFDA41D82A78AF4464.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFDBA89A0DF32CF71A.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFDD0F1F423CB2A630.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFDF06815D1E7ABD95.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFDF25CC2D00D53018.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFE2251504E4E27A73.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFE3B33BEBECAE96A6.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFE5F52ADC39501F0C.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFE689308835381971.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFE716038486F1C8FC.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFEBFE0CAB69EBFE04.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFF036114A45A41CDC.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFF2986017B806330E.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFFAFC3D67D721F6E1.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFFB4D7A9B5C0305A4.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFFDC1DE8482D3E9E0.TMP moved successfully. C:\Users\media\AppData\Local\Temp\~DFFF09E99EBBEBA3D3.TMP moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\media\Desktop\cmd.bat deleted successfully. C:\Users\media\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56468 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: media ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 181880723 bytes ->Java cache emptied: 0 bytes ->Apple Safari cache emptied: 3861504 bytes ->Flash cache emptied: 57391 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 328162491 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 162409 bytes RecycleBin emptied: 699541470 bytes Total Files Cleaned = 1.157,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: media ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.55.0 log created on 08022012_194243 Files\Folders moved on Reboot... c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll moved successfully. C:\Users\media\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... File c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll not found! File C:\Users\media\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! Registry entries deleted on Reboot... |
03.08.2012, 13:47 | #4 |
/// Helfer-Team | Polizeivirus Österreich Sehr gut! 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
06.08.2012, 07:40 | #5 |
| Polizeivirus Österreich Hallo t'John, ich bin deinen Anweisungen wieder gefolgt. 1. Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.06.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 media :: MEDIA-VAIO [Administrator] Schutz: Aktiviert 06.08.2012 07:09:35 mbam-log-2012-08-06 (07-09-35).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 352424 Laufzeit: 55 Minute(n), 36 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) 2. AdwCleaner: Code:
ATTFilter # AdwCleaner v1.800 - Logfile created 08/06/2012 at 08:32:30 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : media - MEDIA-VAIO # Running from : C:\Users\media\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. ************************* AdwCleaner[R1].txt - [614 octets] - [06/08/2012 08:32:30] ########## EOF - C:\AdwCleaner[R1].txt - [741 octets] ########## Gruß, Alex |
06.08.2012, 15:22 | #6 |
/// Helfer-Team | Polizeivirus Österreich Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ --> Polizeivirus Österreich |
07.08.2012, 16:38 | #7 |
| Polizeivirus Österreich Hallo t'John, ich bin deinen Anweisungen wieder gefolgt. 1. AdwCleaner (delete): Code:
ATTFilter # AdwCleaner v1.800 - Logfile created 08/07/2012 at 16:43:39 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : media - MEDIA-VAIO # Running from : C:\Users\media\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. ************************* AdwCleaner[R1].txt - [741 octets] - [06/08/2012 08:32:30] AdwCleaner[S1].txt - [675 octets] - [07/08/2012 16:43:39] ########## EOF - C:\AdwCleaner[S1].txt - [802 octets] ########## 2. Emsisoft Anti-Malware: Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 07.08.2012 16:58:19 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 07.08.2012 16:59:52 C:\_OTL\MovedFiles\08022012_194243\C_Users\media\AppData\Local\Temp\jar_cache6274958730539423160.tmp -> wvfef.class gefunden: Exploit.Java.CVE-2012-1723!E2 Gescannt 607662 Gefunden 1 Scan Ende: 07.08.2012 17:31:41 Scan Zeit: 0:31:49 Alex |
07.08.2012, 17:22 | #8 |
/// Helfer-Team | Polizeivirus Österreich Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
07.08.2012, 18:51 | #9 |
| Polizeivirus Österreich Hallo t'john, hab mich wieder an deine Vorgaben gehalten. Eset Online Scanner Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=78034b126cddd54098cfc45c2aa1df31 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-07 05:45:33 # local_time=2012-08-07 07:45:33 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5121 16777213 100 75 2519478 9583696 0 0 # compatibility_mode=5893 16776574 100 94 21255075 95988050 0 0 # compatibility_mode=8192 67108863 100 0 94 94 0 0 # scanned=188258 # found=0 # cleaned=0 # scan_time=3332 Alex |
07.08.2012, 19:22 | #10 |
/// Helfer-Team | Polizeivirus Österreich Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html |
07.08.2012, 20:27 | #11 |
| Polizeivirus Österreich Hallo t'john, habe Java aktualisiert und alle alten Versionen deinstalliert. Die jetzige Version ist 32-bit. Die neueste alte Version war 64-bit. Ist das ein Problem? Gruß, Alex |
07.08.2012, 23:59 | #12 |
/// Helfer-Team | Polizeivirus Österreich Kein Problem. Benutzt du ueberhaupt den 64Bit Browser? Sehr gut! damit bist Du sauber und entlassen! adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
13.08.2012, 16:20 | #13 |
| Polizeivirus Österreich Hallo t'john, ich bin deinen Anweisungen bzw. den Anleitungen gefolgt. Bzgl. CCleaner habe ich mich genau an die Anleitung gehalten und die Registry nicht bereinigt. Passt das so? Malwarebytes möchte ich behalten und habe die PRO Version aktiviert. (Ich hoffe, dass sich McAfee Total Protection und Malwarebytes verträgt...) Zu guter letzt möchte ich mich für die unkomplizierte und schnelle Hilfe bedanken. Ich bin froh, dass es euch gibt. Ganz nebenbei erwähnt hat es mir sogar Spaß gemacht, anhand meines blöden Anlassfalles dazuzulernen. Ich wünschte mir, ich wäre auch so gut drauf wie du (ihr). Schöne Grüße, Alex Ps.: hab das TB mit €50,00 unterstützt. Hoffe das hilft euch ein bissl... |
13.08.2012, 16:53 | #14 | ||||
/// Helfer-Team | Polizeivirus ÖsterreichZitat:
Ich verlinke die Anleitung, weil man es nicht aus Spass tun soll. Hier ist es aber geboten. Zitat:
Zitat:
Zitat:
|
Themen zu Polizeivirus Österreich |
aktuelle, alten, benötigt, drängt, entfernen, error, heute, infos, laptop, logfiles, nicht mehr, nichts, probleme, quarantäne, stelle, sämtliche, total, trojan.phex.thagen6, trojaner-board, version, virus, windows, windows 7, Österreich |