![]() |
|
Log-Analyse und Auswertung: rechner gesperrt ,bundesamt-trojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() rechner gesperrt ,bundesamt-trojaner hiho allerseits, ich habe mir vermutlich den bundesamt-trojaner eingefangen. weisser bildschirm mit der meldung, ich solle 100€ in form einer paysafe-card zahlen. :-/ nun hab ich mich hier im forum durchgewühlt und gesehen, dass man scheinbar immer diese logfile braucht. hab die gleich mal gemacht und mit gepostet. vielleicht kann mir jemand helfen damit ich den rechner wieder alleine fit bekomme. vielen dank vorab in hoffnungsvoller erwartung ;-) frank Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-05-2013 Ran by SYSTEM on 10-05-2013 10:50:34 Running from N:\ Windows 7 Ultimate (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log. ==================== Registry (Whitelisted) ================== HKU\pepi\...\Winlogon: [Shell] explorer.exe,C:\Users\pepi\AppData\Roaming\skype.dat <==== ATTENTION ========================== Services (Whitelisted) ================= S3 npggsvc; C:\Windows\system32\GameMon.des [3979632 2010-12-07] (INCA Internet Co., Ltd.) S4 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2795048 2013-04-24] (Iminent) S2 SystemStoreService; C:\Program Files\SoftwareUpdater\SystemStore.exe [296448 2013-04-30] () S2 AviraUpgradeService; "C:\Windows\TEMP\AVSETUP_517cd530\avupgsvc.exe" /TEMPSTART:""C:\Windows\TEMP\AVSETUP_517cd530\setup.exe" /NOTEMPCLEANUP /CROSSUPGRADE" [x] ==================== Drivers (Whitelisted) ==================== S3 ALCXWDM; C:\Windows\System32\drivers\ALCXWDM.SYS [2319680 2005-05-18] (Realtek Semiconductor Corp.) S3 BazisVirtualCD; C:\Windows\System32\DRIVERS\BazisVirtualCD.sys [61080 2009-07-01] (Bazis) S3 BazisVirtualCDBus; C:\Windows\System32\DRIVERS\BazisVirtualCDBus.sys [135320 2009-12-06] (SysProgs.org) S3 EL90Xbc; C:\Windows\System32\DRIVERS\el90Xbc5.SYS [74338 2002-08-13] (3Com Corporation) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [8456 2011-07-29] () S3 NPPTNT2; C:\Windows\system32\npptNT2.sys [4682 2005-01-03] (INCA Internet Co., Ltd.) S0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-02-05] (Duplex Secure Ltd.) S2 TBPanel; C:\Windows\System32\Drivers\TBPanel.sys [12256 2007-03-16] (Windows (R) 2000 DDK provider) S3 VirtDiskBus; C:\Windows\System32\DRIVERS\VirtDiskBus.sys [63640 2009-07-01] (Bazis) S3 dump_wmimmc; \??\F:\gPotato.eu\Dragonica\Release\GameGuard\dump_wmimmc.sys [x] S0 St320hg; system32\DRIVERS\st320hg.sys [x] S3 StarOpen; No ImagePath S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 XDva401; \??\C:\Windows\system32\XDva401.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-05-10 10:50 - 2013-05-10 10:50 - 00000000 ____D C:\FRST 2013-05-10 08:40 - 2013-05-10 09:37 - 00000004 ____A C:\Users\pepi\AppData\Roaming\skype.ini 2013-04-30 15:58 - 2013-05-10 09:22 - 00001008 ____A C:\Windows\setupact.log 2013-04-30 15:58 - 2013-04-30 15:58 - 00000790 ____A C:\Windows\PFRO.log 2013-04-28 09:43 - 2013-04-28 09:43 - 00000000 ____D C:\Users\pepi\AppData\Local\Techlogix 2013-04-28 09:00 - 2013-04-28 09:00 - 00000000 ____D C:\Users\pepi\AppData\Local\Freemium 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Users\pepi\AppData\Roaming\SimplyTech 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Users\pepi\AppData\Roaming\HomeTab 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Program Files\Protected Search 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Program Files\HomeTab 2013-04-28 08:59 - 2013-03-19 05:41 - 00016896 ____A C:\Windows\Launcher.exe 2013-04-28 08:58 - 2013-04-28 08:58 - 00000611 ____A C:\Windows\System32\InstallUtil.InstallLog 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Users\pepi\AppData\Roaming\Iminent 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\ProgramData\Iminent 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Program Files\Iminent 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Program Files\Browser Updater 2013-04-28 08:54 - 2013-04-28 08:55 - 00000000 ____D C:\Program Files\SoftwareUpdater 2013-04-28 08:54 - 2013-04-28 08:54 - 00002551 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\Users\pepi\AppData\Roaming\Complitly 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\ProgramData\Package Cache 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\Program Files\Covus Freemium 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\Program Files\Complitly 2013-04-28 08:53 - 2013-04-28 08:53 - 00444408 ____A C:\Users\pepi\Downloads\DE_FreeSystemUtilities.exe 2013-04-28 08:53 - 2013-04-28 08:53 - 00000207 ____A C:\Users\pepi\Desktop\Amazon.url 2013-04-28 08:53 - 2013-04-28 08:53 - 00000000 ____D C:\Users\pepi\AppData\Local\DownloadGuide 2013-04-26 20:04 - 2013-04-26 20:04 - 00003214 ____A C:\Users\pepi\Desktop\bewerbungcsi.odt 2013-04-25 18:52 - 2013-04-25 18:53 - 00000000 ____D C:\Users\pepi\.tfo4 2013-04-25 18:52 - 2013-04-25 18:52 - 00000000 ____D C:\Users\pepi\4.0 2013-04-25 18:52 - 2013-04-25 18:52 - 00000000 ____D C:\ProgramData\Sun 2013-04-25 18:52 - 2013-04-25 18:52 - 00000000 ____D C:\Program Files\Common Files\Java 2013-04-25 18:51 - 2013-04-25 18:51 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll 2013-04-25 18:51 - 2013-04-25 18:51 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe 2013-04-25 18:51 - 2013-04-25 18:51 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe 2013-04-25 18:51 - 2013-04-25 18:51 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe 2013-04-25 18:51 - 2013-04-25 18:51 - 00000000 ____D C:\Program Files\Java 2013-04-24 14:08 - 2013-04-12 14:45 - 01211752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-04-14 08:44 - 2013-02-22 05:05 - 12324352 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-04-14 08:44 - 2013-02-22 04:47 - 09738752 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-04-14 08:44 - 2013-02-22 04:46 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-04-14 08:44 - 2013-02-22 04:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-04-14 08:44 - 2013-02-22 04:38 - 01104384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-04-14 08:44 - 2013-02-22 04:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-04-14 08:44 - 2013-02-22 04:36 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-04-14 08:44 - 2013-02-22 04:35 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-04-14 08:44 - 2013-02-22 04:34 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-04-14 08:44 - 2013-02-22 04:34 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-04-14 08:44 - 2013-02-22 04:34 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-04-14 08:44 - 2013-02-22 04:33 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-04-14 08:44 - 2013-02-22 04:32 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-04-14 08:44 - 2013-02-22 04:31 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-04-14 08:44 - 2013-02-22 04:31 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-04-14 08:44 - 2013-02-22 04:28 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-04-12 06:14 - 2013-03-19 06:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-04-12 06:14 - 2013-03-19 06:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-04-12 06:14 - 2013-03-19 05:48 - 00038912 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2013-04-12 06:14 - 2013-03-19 03:49 - 00069632 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe 2013-04-12 06:14 - 2013-03-01 04:09 - 02347008 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-04-12 06:14 - 2013-02-15 05:37 - 03217408 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2013-04-12 06:14 - 2013-02-15 05:34 - 00131584 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll 2013-04-12 06:14 - 2013-02-15 04:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2013-04-12 06:14 - 2013-01-24 05:47 - 00196328 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys ==================== One Month Modified Files and Folders ======== 2013-05-10 10:50 - 2013-05-10 10:50 - 00000000 ____D C:\FRST 2013-05-10 09:37 - 2013-05-10 08:40 - 00000004 ____A C:\Users\pepi\AppData\Roaming\skype.ini 2013-05-10 09:37 - 2011-01-29 22:30 - 00000000 ____D C:\Users\pepi\AppData\Local\TSVNCache 2013-05-10 09:37 - 2009-11-02 19:32 - 01655524 ____A C:\Windows\WindowsUpdate.log 2013-05-10 09:33 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\tracing 2013-05-10 09:27 - 2009-07-14 05:34 - 00017264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-05-10 09:27 - 2009-07-14 05:34 - 00017264 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-05-10 09:22 - 2013-04-30 15:58 - 00001008 ____A C:\Windows\setupact.log 2013-05-10 09:22 - 2012-10-24 14:12 - 00000000 ____D C:\ProgramData\NVIDIA 2013-05-10 09:22 - 2010-09-04 20:59 - 00001090 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-05-10 09:22 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-05-10 09:14 - 2010-09-04 20:59 - 00001094 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-05-08 11:09 - 2010-08-19 11:16 - 00000000 ___HD C:\Users\pepi\Documents\Runes of Magic 2013-05-03 17:09 - 2009-07-14 05:33 - 00268272 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-02 13:51 - 2009-11-09 18:11 - 00058016 ____A C:\Users\pepi\AppData\Local\GDIPFONTCACHEV1.DAT 2013-05-02 13:29 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-05-02 13:28 - 2013-03-26 16:42 - 00000000 ____D C:\Program Files\Microsoft Office 2013-05-02 13:26 - 2013-03-26 16:41 - 00000000 ____D C:\Program Files\MSECache 2013-05-02 13:12 - 2009-11-02 19:39 - 01527740 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-02 01:06 - 2009-10-14 03:21 - 00238872 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2013-04-30 15:58 - 2013-04-30 15:58 - 00000790 ____A C:\Windows\PFRO.log 2013-04-28 09:43 - 2013-04-28 09:43 - 00000000 ____D C:\Users\pepi\AppData\Local\Techlogix 2013-04-28 09:33 - 2012-12-26 15:10 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2013-04-28 09:33 - 2012-06-30 15:05 - 00000000 ____D C:\Program Files\TortoiseSVN 2013-04-28 09:33 - 2011-11-19 12:45 - 00000000 ____D C:\Users\pepi\AppData\Local\Turbine 2013-04-28 09:33 - 2010-03-27 13:39 - 00000000 ____D C:\Users\pepi\AppData\Roaming\inFlow Inventory 2013-04-28 09:33 - 2009-11-02 19:35 - 00000000 ____D C:\Users\pepi\AppData\Local\VirtualStore 2013-04-28 09:33 - 2009-10-14 04:07 - 00000000 ____D C:\Windows\Panther 2013-04-28 09:33 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\Msdtc 2013-04-28 09:00 - 2013-04-28 09:00 - 00000000 ____D C:\Users\pepi\AppData\Local\Freemium 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Users\pepi\AppData\Roaming\SimplyTech 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Users\pepi\AppData\Roaming\HomeTab 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Program Files\Protected Search 2013-04-28 08:59 - 2013-04-28 08:59 - 00000000 ____D C:\Program Files\HomeTab 2013-04-28 08:58 - 2013-04-28 08:58 - 00000611 ____A C:\Windows\System32\InstallUtil.InstallLog 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Users\pepi\AppData\Roaming\Iminent 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\ProgramData\Iminent 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Program Files\Iminent 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2013-04-28 08:58 - 2013-04-28 08:58 - 00000000 ____D C:\Program Files\Browser Updater 2013-04-28 08:55 - 2013-04-28 08:54 - 00000000 ____D C:\Program Files\SoftwareUpdater 2013-04-28 08:54 - 2013-04-28 08:54 - 00002551 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\Users\pepi\AppData\Roaming\Complitly 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\ProgramData\Package Cache 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\Program Files\Covus Freemium 2013-04-28 08:54 - 2013-04-28 08:54 - 00000000 ____D C:\Program Files\Complitly 2013-04-28 08:53 - 2013-04-28 08:53 - 00444408 ____A C:\Users\pepi\Downloads\DE_FreeSystemUtilities.exe 2013-04-28 08:53 - 2013-04-28 08:53 - 00000207 ____A C:\Users\pepi\Desktop\Amazon.url 2013-04-28 08:53 - 2013-04-28 08:53 - 00000000 ____D C:\Users\pepi\AppData\Local\DownloadGuide 2013-04-26 20:04 - 2013-04-26 20:04 - 00003214 ____A C:\Users\pepi\Desktop\bewerbungcsi.odt 2013-04-25 18:53 - 2013-04-25 18:52 - 00000000 ____D C:\Users\pepi\.tfo4 2013-04-25 18:52 - 2013-04-25 18:52 - 00000000 ____D C:\Users\pepi\4.0 2013-04-25 18:52 - 2013-04-25 18:52 - 00000000 ____D C:\ProgramData\Sun 2013-04-25 18:52 - 2013-04-25 18:52 - 00000000 ____D C:\Program Files\Common Files\Java 2013-04-25 18:52 - 2009-11-02 19:34 - 00000000 ____D C:\users\pepi 2013-04-25 18:51 - 2013-04-25 18:51 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll 2013-04-25 18:51 - 2013-04-25 18:51 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe 2013-04-25 18:51 - 2013-04-25 18:51 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe 2013-04-25 18:51 - 2013-04-25 18:51 - 00145184 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe 2013-04-25 18:51 - 2013-04-25 18:51 - 00000000 ____D C:\Program Files\Java 2013-04-14 13:11 - 2012-10-24 14:11 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-04-14 13:09 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore 2013-04-12 14:45 - 2013-04-24 14:08 - 01211752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-04-12 11:56 - 2009-10-14 03:21 - 70490256 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe Other Malware: =========== C:\Users\pepi\AppData\Roaming\skype.dat C:\Users\pepi\AppData\Roaming\skype.ini C:\ProgramData\ezsidmv.dat ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-05-10 07:12:04 ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 4095.24 MB Available physical RAM: 3607.54 MB Total Pagefile: 4093.52 MB Available Pagefile: 3612.68 MB Total Virtual: 2047.88 MB Available Virtual: 1962.3 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:38.96 GB) (Free:4.43 GB) NTFS Drive d: (PRIVAT) (Fixed) (Total:19.52 GB) (Free:9.96 GB) FAT32 Drive e: (MISC) (Fixed) (Total:19.52 GB) (Free:5.02 GB) FAT32 Drive f: (MUSIK) (Fixed) (Total:108.15 GB) (Free:71.31 GB) FAT32 Drive n: (USB DISK) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 186 GB) (Disk ID: 0F530F53) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=39 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=147 GB) - (Type=OF Extended) ======================================================== Disk: 6 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=4 GB) - (Type=0C) Last Boot: 2013-04-26 18:57 ==================== End Of Log ============================ |
Themen zu rechner gesperrt ,bundesamt-trojaner |
association, bildschirm, browser, bundesamt, check, desktop, explorer, explorer.exe, farbar, farbar recovery scan tool, forum, frst.txt, gesperrt, home, log datei, logfile, malware, microsoft, musik, realtek, registry, secure, services.exe, softwareupdater, sprotection, svchost.exe, system, system32, teamspeak, temp, windows xp, winlogon, winlogon.exe |