|
Log-Analyse und Auswertung: Windows7 64 bit - Weißer Bildschirm - Bitte umHilfeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.12.2012, 18:41 | #1 |
| Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Mein acer Aspire Notebook (Windows 7 64 bit) zeigt mir nur noch einen weißen Bildschirm nach dem Bootvorgang. Ich kann sonst nichts mehr machen, außer den PC ausschalten und task manager aufrufen (alles endet wieder im weißen Bildschirm) Im abgesicherten Modus mit Netzwerktreibern erhalte ich übrigens den selben Effekt mit weißenmscreen. Im Anhang befindet sich das Logfiles otl.txt Ich würde mich freuen, wenn ihr mir helfen könntet. Bitte um Eure Hilfe |
12.12.2012, 19:13 | #2 | ||||
/// TB-Ausbilder | Windows7 64 bit - Weißer Bildschirm - Bitte umHilfeIch werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Gelesen und verstanden? Schritt 1: Fix mit OTLpe Fragen: Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen Schritt 3: Scan mit Combofix
__________________ |
12.12.2012, 20:27 | #3 |
| Hurra-gelöst: Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Danke für die wirklich extrem rasche und vor allem wirksame Hilfe! Kann man Dir eine kleine Zuwendung zukommen lassen - evtl via paypal? Ein virtuelles Bier steht sowieso!
__________________Ich hoffe, mein Rechner war nicht zu sehr infiziert - kannst du dazu evtl etwas näheres sagen, was da los war? Bin genau nach Anweisung vorgegangen - Schritt 1 - Ergebnis: Code:
ATTFilter ========= OTL ========== Registry value HKEY_USERS\Christa_ON_D\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\Christa\AppData\Roaming\skype.dat deleted successfully. File D:\Users\Christa\AppData\Roaming\skype.dat not found. Unable to delete ADS D:\ProgramData\Temp:5D7E5A8F . OTLPE by OldTimer - Version 3.1.48.0 log created on 12122012_193712 Danke dafür! Ok - danach weiter mit Schritt 2 - Ergebnis: Code:
ATTFilter # AdwCleaner v2.100 - Datei am 12/12/2012 um 19:43:53 erstellt # Aktualisiert am 09/12/2012 von Xplode # Betriebssystem : Windows 7 Home Premium (64 bits) # Benutzer : Christa - ACER-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Christa\Desktop\Cleaner-Soft\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Program Files (x86)\SweetIM Ordner Gelöscht : C:\ProgramData\boost_interprocess Ordner Gelöscht : C:\ProgramData\SweetIM Ordner Gelöscht : C:\Users\Christa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn Ordner Gelöscht : C:\Users\Christa\AppData\LocalLow\SweetIM ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\SweetIM Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\Software\SweetIM Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Sweetpacks Communicator] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16455 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v23.0.1271.95 Datei : C:\Users\Christa\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [4332 octets] - [12/12/2012 19:43:15] AdwCleaner[S1].txt - [4271 octets] - [12/12/2012 19:43:53] ########## EOF - C:\AdwCleaner[S1].txt - [4331 octets] ########## und last but not least - Combofix ergbnis: Code:
ATTFilter ComboFix 12-12-10.01 - Christa 12.12.2012 19:52:29.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.43.1031.18.3764.2431 [GMT 1:00] ausgeführt von:: c:\users\Christa\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\FullRemove.exe c:\users\Christa\4.0 c:\users\Christa\AppData\Roaming\skype.ini c:\users\Public\sdelevURL.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2012-11-12 bis 2012-12-12 )))))))))))))))))))))))))))))) . . 2012-12-12 23:11 . 2011-07-13 02:55 2237440 ----a-r- C:\OTLPE.exe 2012-12-12 23:10 . 2012-12-12 23:10 -------- d-----w- C:\_OTL 2012-12-12 18:58 . 2012-12-12 18:58 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-12-06 18:19 . 2012-12-06 18:19 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{77DED92B-57CA-4950-A3FA-8A8A186AA0BD}\offreg.dll 2012-12-06 16:57 . 2012-12-06 16:57 -------- d-----w- c:\users\Christa\AppData\Local\BouquetEditorSuite 2012-11-29 12:46 . 2012-11-29 13:12 -------- d-----w- c:\users\Christa\AppData\Roaming\FileZilla 2012-11-29 12:46 . 2012-11-29 12:46 -------- d-----w- c:\program files (x86)\FileZilla FTP Client 2012-11-23 13:11 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{77DED92B-57CA-4950-A3FA-8A8A186AA0BD}\mpengine.dll 2012-11-16 13:45 . 2012-10-18 18:18 3147264 ----a-w- c:\windows\system32\win32k.sys 2012-11-16 13:45 . 2012-09-25 22:39 95744 ----a-w- c:\windows\system32\synceng.dll 2012-11-16 13:45 . 2012-09-25 21:55 78336 ----a-w- c:\windows\SysWow64\synceng.dll 2012-11-14 19:12 . 2012-11-14 19:13 -------- d-----w- c:\users\Christa\AppData\Local\www.coolstream.to 2012-11-14 17:19 . 2012-11-14 17:27 -------- d-----w- c:\users\Christa\AppData\Roaming\Notepad++ 2012-11-14 17:19 . 2012-11-14 17:19 -------- d-----w- c:\program files (x86)\Notepad++ . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-12 12:48 . 2012-08-15 06:27 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 12:48 . 2012-03-09 10:53 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-11-16 13:47 . 2012-03-01 21:42 66395536 ----a-w- c:\windows\system32\MRT.exe 2012-10-30 22:51 . 2012-05-16 17:15 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-30 22:51 . 2012-05-16 17:16 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-30 22:51 . 2012-05-16 17:15 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-30 22:51 . 2012-05-16 17:15 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-30 22:51 . 2012-05-16 17:16 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-30 22:51 . 2012-05-16 17:15 41224 ----a-w- c:\windows\avastSS.scr 2012-10-30 22:50 . 2012-05-16 17:15 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe 2012-10-30 22:50 . 2012-05-16 17:15 285328 ----a-w- c:\windows\system32\aswBoot.exe 2012-10-15 16:59 . 2012-05-16 17:15 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-09-14 19:23 . 2012-10-19 08:47 2048 ----a-w- c:\windows\system32\tzres.dll 2012-09-14 18:30 . 2012-10-19 08:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{17166733-40EA-4432-A85C-AE672FF0E236}] 2011-05-11 15:36 163936 ----a-w- c:\programdata\1und1InternetExplorerAddon\BHOXML.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 02:40 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-21 98304] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952] "MDS_Menu"="c:\program files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "ArcadeMovieService"="c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [2011-02-17 124136] "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2010-03-10 300400] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files (x86)\Acer\Acer VCM\AcerVCM.exe [2010-9-21 704032] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 CLKMSVC10_039CBDDF;CyberLink Product - 2012/05/22 17:40;c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\NavFilter\kmsvc.exe [2011-01-28 241648] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-04-17 50432] R3 nuvotoncir;Nuvoton IR Transceiver;c:\windows\system32\DRIVERS\nuvotoncir.sys [2009-08-31 48128] R3 nuvotonir;Nuvoton CIR Transceiver;c:\windows\system32\DRIVERS\nuvotonir.sys [2009-08-31 68096] R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-02 1255736] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2009-10-05 87600] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464] S2 {6E090BD5-4EF5-4bf0-A968-74049E88E935};Power Control [2012/02/22 22:50];c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\000.fcl [2010-05-19 11:33 146928] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-04-20 202752] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2010-06-15 822304] S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\Drivers\FPSensor.sys [2012-02-22 35888] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-04-17 144640] S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-07-01 2533400] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344] S3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\DRIVERS\hidshim.sys [2009-08-31 6656] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2010-04-20 10322848] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-06-25 76912] S3 nuvotonhidcir;Nuvoton HID CIR Receiver;c:\windows\system32\DRIVERS\nuvotonhidcir.sys [2009-08-31 26624] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdgx64.sys [2010-03-05 75624] S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdgx64.sys [2010-01-11 50976] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL *Deregistered* - CLKMDRV10_039CBDDF . Inhalt des "geplante Tasks" Ordners . 2012-12-12 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 12:48] . 2012-12-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-16 17:16] . 2012-12-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-16 17:16] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 02:42 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-19 10134560] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-20 166424] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-20 391192] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-20 413720] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-09 206208] "Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2010-06-15 496160] . ------- Zusätzlicher Suchlauf ------- . uStart Page = https://www.google.at/ uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://acer.msn.com mStart Page = hxxp://acer.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> TCP: DhcpNameServer = 10.0.0.138 TCP: Interfaces\{E863604E-CE18-4B25-B5C7-C8520A339FF8}: NameServer = 192.168.0.1 Handler: gmx - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - c:\program files (x86)\GMX Toolbar\IE\uitb.dll . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\{6E090BD5-4EF5-4bf0-A968-74049E88E935}] "ImagePath"="\??\c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\000.fcl" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Z8ebm›] "0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "MRUListEx"=hex:08,00,00,00,07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03, 00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff "1"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "2"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "3"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "4"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "5"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "6"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "7"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ "8"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Zxiå:)þ] "0"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,31, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "MRUListEx"=hex:07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,00,00,02, 00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff "1"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,32, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "2"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,33, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "3"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,34, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "4"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,35, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "5"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,36, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "6"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,37, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ "7"=hex:72,00,36,00,00,00,00,00,00,00,00,00,80,00,43,00,57,00,6b,00,73,00,38, 00,2e,00,6a,70,67,00,be,5a,78,69,e5,3a,29,fe,10,01,00,00,48,00,08,00,04,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^ÂdiY1³] "0"=hex:50,00,31,00,00,00,00,00,30,41,0d,5b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,0d,5b,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff "1"=hex:50,00,31,00,00,00,00,00,35,41,73,9a,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,35,41,73,9a,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^fDÞ] "0"=hex:50,00,31,00,00,00,00,00,47,41,10,60,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,47,41,10,60,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,00,00,02, 00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff "1"=hex:50,00,31,00,00,00,00,00,4d,41,93,4d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,93,4d,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,4d,41,c3,4d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,c3,4d,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,4d,41,ef,4d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,ef,4d,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,4d,41,10,4e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,10,4e,2a,00,00,00,30,d8,00,00,00,00,\ "5"=hex:50,00,31,00,00,00,00,00,4d,41,3b,4e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,3b,4e,2a,00,00,00,30,d8,00,00,00,00,\ "6"=hex:50,00,31,00,00,00,00,00,4d,41,90,4e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,90,4e,2a,00,00,00,30,d8,00,00,00,00,\ "7"=hex:50,00,31,00,00,00,00,00,4d,41,d5,4e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,4d,41,d5,4e,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^fsŽ,] "0"=hex:50,00,31,00,00,00,00,00,2f,41,90,86,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,2f,41,90,86,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:0e,00,00,00,0d,00,00,00,0c,00,00,00,0b,00,00,00,0a,00,00,00,09, 00,00,00,08,00,00,00,07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,\ "1"=hex:50,00,31,00,00,00,00,00,30,41,8d,54,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,8d,54,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,30,41,ec,54,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,ec,54,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,30,41,1d,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,1d,55,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,30,41,31,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,31,55,2a,00,00,00,30,d8,00,00,00,00,\ "5"=hex:50,00,31,00,00,00,00,00,30,41,63,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,63,55,2a,00,00,00,30,d8,00,00,00,00,\ "6"=hex:50,00,31,00,00,00,00,00,30,41,8a,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,8a,55,2a,00,00,00,30,d8,00,00,00,00,\ "7"=hex:50,00,31,00,00,00,00,00,30,41,ad,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,ad,55,2a,00,00,00,30,d8,00,00,00,00,\ "8"=hex:50,00,31,00,00,00,00,00,30,41,d0,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,d0,55,2a,00,00,00,30,d8,00,00,00,00,\ "9"=hex:50,00,31,00,00,00,00,00,30,41,10,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,10,56,2a,00,00,00,30,d8,00,00,00,00,\ "10"=hex:50,00,31,00,00,00,00,00,30,41,50,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,50,56,2a,00,00,00,30,d8,00,00,00,00,\ "11"=hex:50,00,31,00,00,00,00,00,30,41,7d,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,7d,56,2a,00,00,00,30,d8,00,00,00,00,\ "12"=hex:50,00,31,00,00,00,00,00,30,41,a9,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,a9,56,2a,00,00,00,30,d8,00,00,00,00,\ "13"=hex:50,00,31,00,00,00,00,00,30,41,eb,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,eb,56,2a,00,00,00,30,d8,00,00,00,00,\ "14"=hex:50,00,31,00,00,00,00,00,30,41,12,57,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,30,41,12,57,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^ÑfõîOÖ] "0"=hex:50,00,31,00,00,00,00,00,5b,41,00,6d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,5b,41,00,6d,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:05,00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00, 00,00,00,ff,ff,ff,ff "1"=hex:50,00,31,00,00,00,00,00,5b,41,b4,6d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,5b,41,b4,6d,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,5b,41,c0,6d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,5b,41,c0,6d,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,5b,41,f4,6d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,5b,41,f4,6d,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,5b,41,39,6e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,5b,41,39,6e,2a,00,00,00,30,d8,00,00,00,00,\ "5"=hex:50,00,31,00,00,00,00,00,5b,41,69,6e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,5b,41,69,6e,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^Vg«xŒ] "0"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,9f,ae,90,a9,3b,a0,80,4e,94,bc,99,12,d7,50,\ "MRUListEx"=hex:05,00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00, 00,00,00,ff,ff,ff,ff "1"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,9f,ae,90,a9,3b,a0,80,4e,94,bc,99,12,d7,50,\ "2"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,9f,ae,90,a9,3b,a0,80,4e,94,bc,99,12,d7,50,\ "3"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,9f,ae,90,a9,3b,a0,80,4e,94,bc,99,12,d7,50,\ "4"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,9f,ae,90,a9,3b,a0,80,4e,94,bc,99,12,d7,50,\ "5"=hex:14,00,1f,42,25,48,1e,03,94,7b,c3,4d,b1,31,e9,46,b4,4c,8d,d5,74,00,00, 00,1a,00,ee,bb,fe,23,00,00,10,00,9f,ae,90,a9,3b,a0,80,4e,94,bc,99,12,d7,50,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg `^Ÿg !] "0"=hex:50,00,31,00,00,00,00,00,45,41,8f,6d,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,45,41,8f,6d,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:0a,00,00,00,09,00,00,00,08,00,00,00,07,00,00,00,06,00,00,00,05, 00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,\ "1"=hex:50,00,31,00,00,00,00,00,46,41,43,6b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,43,6b,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,46,41,61,6b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,61,6b,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,46,41,90,6b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,90,6b,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,46,41,b2,6b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,b2,6b,2a,00,00,00,30,d8,00,00,00,00,\ "5"=hex:50,00,31,00,00,00,00,00,46,41,ca,6b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,ca,6b,2a,00,00,00,30,d8,00,00,00,00,\ "6"=hex:50,00,31,00,00,00,00,00,46,41,fa,6b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,fa,6b,2a,00,00,00,30,d8,00,00,00,00,\ "7"=hex:50,00,31,00,00,00,00,00,46,41,18,6c,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,18,6c,2a,00,00,00,30,d8,00,00,00,00,\ "8"=hex:50,00,31,00,00,00,00,00,46,41,47,6c,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,47,6c,2a,00,00,00,30,d8,00,00,00,00,\ "9"=hex:50,00,31,00,00,00,00,00,46,41,75,6c,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,75,6c,2a,00,00,00,30,d8,00,00,00,00,\ "10"=hex:50,00,31,00,00,00,00,00,46,41,88,6c,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,88,6c,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^hÚYÌ[] "0"=hex:82,00,36,00,00,00,00,00,00,00,00,00,80,00,48,00,6f,00,63,00,68,00,62, 00,65,00,65,00,74,00,31,00,2e,00,6a,70,67,00,60,5e,16,68,da,59,cc,5b,10,01,\ "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff "1"=hex:82,00,36,00,00,00,00,00,00,00,00,00,80,00,48,00,6f,00,63,00,68,00,62, 00,65,00,65,00,74,00,32,00,2e,00,6a,70,67,00,60,5e,16,68,da,59,cc,5b,10,01,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*`^i€ŒTž] "0"=hex:50,00,31,00,00,00,00,00,46,41,e0,7e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,46,41,e0,7e,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff, ff,ff,ff "1"=hex:50,00,31,00,00,00,00,00,47,41,3b,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,47,41,3b,55,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,47,41,b7,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,47,41,b7,55,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,47,41,c1,55,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,47,41,c1,55,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,47,41,b8,59,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,47,41,b8,59,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*E¥u`^¦gô®+”—D*”ºD*] "0"=hex:50,00,31,00,00,00,00,00,36,41,3c,7b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,36,41,3c,7b,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*E¥uE¥u`^Nd”Kó3] "0"=hex:50,00,31,00,00,00,00,00,36,41,a9,7e,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,36,41,a9,7e,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:06,00,00,00,05,00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,01, 00,00,00,00,00,00,00,ff,ff,ff,ff "1"=hex:50,00,31,00,00,00,00,00,37,41,95,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,37,41,95,56,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,37,41,bd,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,37,41,bd,56,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,37,41,e6,56,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,37,41,e6,56,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,37,41,14,57,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,37,41,14,57,2a,00,00,00,30,d8,00,00,00,00,\ "5"=hex:50,00,31,00,00,00,00,00,37,41,38,57,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,37,41,38,57,2a,00,00,00,30,d8,00,00,00,00,\ "6"=hex:50,00,31,00,00,00,00,00,37,41,03,58,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,37,41,03,58,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-2091909744-1167858060-1918691837-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*E¥uE¥u`^¦g*¯+] "0"=hex:50,00,31,00,00,00,00,00,35,41,91,9a,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,35,41,91,9a,2a,00,00,00,30,d8,00,00,00,00,\ "MRUListEx"=hex:04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff, ff,ff,ff "1"=hex:50,00,31,00,00,00,00,00,36,41,c0,7a,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,36,41,c0,7a,2a,00,00,00,30,d8,00,00,00,00,\ "2"=hex:50,00,31,00,00,00,00,00,36,41,03,7b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,36,41,03,7b,2a,00,00,00,30,d8,00,00,00,00,\ "3"=hex:50,00,31,00,00,00,00,00,36,41,65,7b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,36,41,65,7b,2a,00,00,00,30,d8,00,00,00,00,\ "4"=hex:50,00,31,00,00,00,00,00,36,41,ed,7b,10,00,50,72,69,76,61,74,00,00,3a, 00,08,00,04,00,ef,be,28,41,a3,90,36,41,ed,7b,2a,00,00,00,30,d8,00,00,00,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\windows\system32\DRIVERS\o2flash.exe c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Launch Manager\LMworker.exe c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\Google\Update\Install\{9F284874-F494-4D41-A9A1-CDB91DCA9874}\23.0.1271.97_23.0.1271.95_chrome_updater.exe c:\windows\TEMP\CR_5D0A0.tmp\setup.exe . ************************************************************************** . Zeit der Fertigstellung: 2012-12-12 20:05:53 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2012-12-12 19:05 . Vor Suchlauf: 12 Verzeichnis(se), 429.838.733.312 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 431.989.194.752 Bytes frei . - - End Of File - - 56760CBF5AC94007750644A4B2144E3A |
12.12.2012, 20:41 | #4 | ||
/// TB-Ausbilder | Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Lach ... danke, aber eine Spende kannst du ganz am Ende loswerden, wenn du magst Schritt 1: Windows-Defender abschalten Da du einen anderen Virenscanner benutzt solltest du dringend den windowseigenen Scanner abschalten:
Quick-Scan mit Malwarebytes Schritt 3: ESET Online Scanner Zitat:
Schritt 4: ESET Online Scanner Zitat:
Schritt 5: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck: LINK1 LINK2
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
12.12.2012, 22:00 | #5 |
| [Alarm] Eset Online schlägt an - Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Hui - da gehts zur Sache! Nun denn - let's start! Schritt 1: Windows-Defender abschalten - DONE Schritt 2: Quick-Scan mit Malwarebytes - DONE Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.65.1.1000 www.malwarebytes.org Datenbank Version: v2012.12.12.11 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Christa :: ACER-PC [Administrator] Schutz: Aktiviert 12.12.2012 20:53:49 mbam-log-2012-12-12 (20-53-49).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 210064 Laufzeit: 2 Minute(n), 7 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Schritt 3 & 4: ESET Online Scanner - Oh Oh - ALARM! Wahat to do? Code:
ATTFilter C:\Users\Christa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\42JGM3ZN\49773516[1].htm HTML/Iframe.B.Gen virus C:\Users\Christa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Y3W9N1K6\banners[1].htm HTML/Iframe.B.Gen virus C:\_OTL\MovedFiles\12122012_193424\D_Users\Christa\AppData\Roaming\skype.dat Win32/TrojanDownloader.Vespula.AY trojan Code:
ATTFilter Results of screen317's Security Check version 0.99.56 Windows 7 x64 (UAC is enabled) Out of date service pack!! Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.65.1.1000 Adobe Reader 9 Adobe Reader out of Date! Google Chrome 21.0.1180.83 Google Chrome 21.0.1180.89 Google Chrome 22.0.1229.79 Google Chrome 22.0.1229.92 Google Chrome 22.0.1229.94 Google Chrome 23.0.1271.64 Google Chrome 23.0.1271.91 Google Chrome 23.0.1271.95 Google Chrome 23.0.1271.97 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe ESET ESET Online Scanner OnlineCmdLineScanner.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
12.12.2012, 22:06 | #6 |
/// TB-Ausbilder | Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Immer mit der Ruhe... Schritt 1: Temporäre Dateien löschen mit TFC
Schritt 2: Windows 7 Service Pack 1 installieren
Schritt 3: Update: Adobe Reader
Probiere einen alternativen Viewer für pdf-Dokumente aus. Diese sind meist schlanker, schneller und schleusen sehr viel seltener Schädlinge ein. Mein Vorschlag:
Schritt 4: Scan mit SecurityCheck Downloade Dir bitte SecurityCheck: LINK1 LINK2
__________________ --> Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe |
13.12.2012, 00:22 | #7 |
| Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Hui - was für eine nachhaltige Bekämpfung - also zuerst mal Vorbereitungen: Bierdoserl geöffnet & gelüpft! dann: Schritt 1: ausgeführt Schritt 2: Win7 SP1 runtergezogen und installiert Schritt 3: Acrobat reader deinstalliert & Foxit-Reader wie beschrieben installiert! Schritt 4: Done - hier das Ergebnis: Code:
ATTFilter Results of screen317's Security Check version 0.99.56 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.65.1.1000 Google Chrome 21.0.1180.83 Google Chrome 21.0.1180.89 Google Chrome 22.0.1229.79 Google Chrome 22.0.1229.92 Google Chrome 22.0.1229.94 Google Chrome 23.0.1271.64 Google Chrome 23.0.1271.91 Google Chrome 23.0.1271.95 Google Chrome 23.0.1271.97 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
13.12.2012, 11:18 | #8 | ||||
/// TB-Ausbilder | Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe PROST! Prima! Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: Tools deinstallieren
Schritt 2: ESET deinstallieren (Optional)
Abschließend noch Tipps zu folgenden Themen:
Damit wünsche ich dir noch viel Spaß beim Surfen im Internet ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
14.12.2012, 13:19 | #9 | ||
| [GELÖST] Windows7 64 bit - Weißer Bildschirm - Bitte umHilfeZitat:
Wird gemacht! Zitat:
Cu Kurt |
14.12.2012, 16:44 | #10 |
/// TB-Ausbilder | Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe Schön, dass wir helfen konnten Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen Falls du noch Lob oder Kritik loswerden möchtest, dann gibt es diesen Bereich hier: http://www.trojaner-board.de/lob-kritik-wuensche/
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
Themen zu Windows7 64 bit - Weißer Bildschirm - Bitte umHilfe |
abgesicherte, abgesicherten, acer, acer aspire, anhang, aspire, aufrufe, aufrufen, ausschalten, befindet, bildschirm, erhalte, freue, logfiles, manager, modus, netzwerk, netzwerktreiber, nichts, notebook, task manager, weiße, weißer, windows, windows 7, würde |