![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: einige trojaner agenten, viele backdoors und einen spyagentWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | einige trojaner agenten, viele backdoors und einen spyagent Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL
PRC - [2011.08.23 21:20:18 | 000,887,976 | ---- | M] (Ask) -- C:\Programme\Ask.com\Updater\Updater.exe
SRV - File not found [Auto | Stopped] -- -- (ClipInc001)
SRV - File not found [Auto | Stopped] -- -- (AntiVirService)
SRV - File not found [Auto | Stopped] -- -- (AntiVirSchedulerService)
SRV - File not found [On_Demand | Stopped] -- -- (ACDaemon)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.puls4.com/home
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://start.facemoods.com"
FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com:1.0.4
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.13.1.18107
FF - prefs.js..keyword.URL: "http://start.facemoods.com/results.php?f=5&a=fbpage&q="
[2011.09.28 11:19:45 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.10.20 13:08:22 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com
[2011.10.25 16:56:32 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-1.xml
[2011.10.04 11:59:26 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-2.xml
[2011.10.11 13:12:35 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-3.xml
[2011.10.27 18:04:12 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-4.xml
[2011.10.28 10:50:55 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-5.xml
[2011.09.12 16:53:26 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin.xml
[2010.07.05 10:03:37 | 000,000,000 | ---D | M] (FaceMod Dislike Button) -- C:\Programme\Mozilla Firefox\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
[2010.05.15 13:32:26 | 000,000,000 | ---D | M] (Facemoods) -- C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.3.61.8\facemoodsTlbr.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Programme\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min File not found
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKCU..\Run: [Facebook Update] C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk = File not found
O9 - Extra Button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Programme\Get Styles\ct.htm File not found
O9 - Extra 'Tools' menuitem : GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Programme\Get Styles\ct.htm File not found
O9 - Extra Button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - z:\Programme\PartyGaming\PartyCasino\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - z:\Programme\PartyGaming\PartyCasino\RunApp.exe File not found
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - z:\Programme\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - z:\Programme\PartyGaming\PartyPoker\RunApp.exe File not found
O18 - Protocol\Filter\text/html {574940E0-1B7A-4881-8FA3-1E809714B156} - C:\Dokumente und Einstellungen\Tobias\AppData\LocalLow\Microñoft\redir.dll File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.22 15:48:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
MsConfig - StartUpReg: 8DDYX0ZBPZ - hkey= - key= - File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AlcoholAutomount - hkey= - key= - File not found
MsConfig - StartUpReg: ClipIncSrvTray - hkey= - key= - File not found
MsConfig - StartUpReg: D-Link AirPlus G - hkey= - key= - File not found
MsConfig - StartUpReg: DAEMON Tools - hkey= - key= - File not found
MsConfig - StartUpReg: ICQ - hkey= - key= - File not found
MsConfig - StartUpReg: KYQ8ZBOAXR - hkey= - key= - File not found
MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - File not found
MsConfig - StartUpReg: SearchSettings - hkey= - key= - File not found
MsConfig - StartUpReg: SweetIM - hkey= - key= - File not found
MsConfig - StartUpReg: Tobias - hkey= - key= - C:\Dokumente und Einstellungen\Tobias\Tobias.exe ()
MsConfig - StartUpReg: {8A166BDA-4591-7E9D-6201-0BB7707305E8} - hkey= - key= - File not found
MsConfig - StartUpReg: {9AD77469-89CC-3354-3A72-25F37B434BAE} - hkey= - key= - File not found
[2011.10.27 14:29:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\ufa
[2011.10.27 14:29:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\phoenix
[2011.10.27 14:18:08 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.7.1
[2011.10.27 14:17:24 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.5.0
[2011.10.27 14:08:01 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.8.1
[2011.10.27 14:01:09 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.2
[2011.10.27 13:56:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\av_ico
[2011.10.27 13:54:01 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.1
[2011.10.27 13:53:46 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-9-0-lnk
[2011.10.27 13:53:46 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-9-0
[2011.10.27 13:53:45 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-8-0-lnk
[2011.10.27 13:53:45 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-8-0
[2011.10.24 09:43:11 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook
[2011.10.20 13:00:18 | 000,000,000 | ---D | C] -- C:\Programme\Ask.com
[2011.10.20 13:00:15 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\AskToolbar
[2011.10.20 13:00:04 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\ManyCam
[2011.10.20 13:00:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam
[2011.10.20 12:59:55 | 000,000,000 | ---D | C] -- C:\Programme\ManyCam
[2011.10.20 12:59:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ask
[2011.10.28 09:46:25 | 000,202,984 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011.10.28 09:46:25 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hîsts
[2011.10.27 22:15:58 | 000,000,224 | ---- | M] () -- C:\WINDOWS\info1
[2011.10.27 21:41:47 | 000,000,000 | ---- | M] () -- C:\WINDOWS\loader2.exe_ok
[2011.10.20 12:59:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ask
[2009.08.20 17:54:43 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{39850DC2-6343-4AE6-BC4C-63494A9C369F}
[2009.08.20 18:01:39 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{4843418D-E3A6-4662-842A-857DF0C650FB}
[2011.08.12 20:57:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Azno
[2010.06.06 22:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\facemoods.com
[2011.09.14 18:21:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\FinalTorrent
[2011.08.15 11:37:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Maadci
[2011.10.20 13:00:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam
[2011.08.15 11:37:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Oksuzu
[2011.08.13 13:43:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\pdfforge
[2011.08.13 13:43:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Search Settings
[2011.08.15 09:42:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Xuukhe
:Files
C:\Programme\Ask.com
C:\Dokumente und Einstellungen\Tobias\AppData\LocalLow\Micro*
C:\Windows\tasks\*.job
C:\WINDOWS\*.rar
C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\*.sys
:Commands
[emptytemp]
[resethosts]
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #2 |
![]() | einige trojaner agenten, viele backdoors und einen spyagent All processes killed
__________________========== OTL ========== No active process named Updater.exe was found! Service ClipInc001 stopped successfully! Service ClipInc001 deleted successfully! Service AntiVirService stopped successfully! Service AntiVirService deleted successfully! Service AntiVirSchedulerService stopped successfully! Service AntiVirSchedulerService deleted successfully! Service ACDaemon stopped successfully! Service ACDaemon deleted successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully. C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "ICQ Search" removed from browser.search.defaultenginename Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q=" removed from browser.search.defaulturl Prefs.js: "Google" removed from browser.search.selectedEngine Prefs.js: "hxxp://start.facemoods.com" removed from browser.startup.homepage Prefs.js: ffxtlbr@Facemoods.com:1.0.4 removed from extensions.enabledItems Prefs.js: toolbar@ask.com:3.13.1.18107 removed from extensions.enabledItems Prefs.js: "hxxp://start.facemoods.com/results.php?f=5&a=fbpage&q=" removed from keyword.URL C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\searchplugins folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\logs folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\defaults\preferences folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\defaults folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\datastore folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Thu-20-Oct-2011-11-17-26-GMT folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\chrome\temp folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\chrome\skin folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\chrome\content folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com\chrome folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\extensions\toolbar@ask.com folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-1.xml moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-2.xml moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-3.xml moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-4.xml moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin-5.xml moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Mozilla\Firefox\Profiles\ojb1r1rf.default\searchplugins\icqplugin.xml moved successfully. C:\Programme\Mozilla Firefox\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}\defaults\preferences folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}\defaults folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}\content folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7} folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\defaults\preferences folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\defaults folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\preferences folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content\images folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\content folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\components folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com\chrome folder moved successfully. C:\Programme\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully. C:\Programme\Ask.com\GenericAskToolbar.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found. File C:\Programme\ICQ6Toolbar\ICQToolBar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Programme\Ask.com\Updater\Updater.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avgnt deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico2 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico3 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico4 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update deleted successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\FacebookUpdate.exe moved successfully. C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{14CD42DD-ABCD-3586-DCAB-40E3693E3737}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14CD42DD-ABCD-3586-DCAB-40E3693E3737}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{14CD42DD-ABCD-3586-DCAB-40E3693E3737}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14CD42DD-ABCD-3586-DCAB-40E3693E3737}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{574940E0-1B7A-4881-8FA3-1E809714B156}\ deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\AUTOEXEC.BAT moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\8DDYX0ZBPZ\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\Adobe Reader Speed Launcher\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\AlcoholAutomount\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\ClipIncSrvTray\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\D-Link AirPlus G\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\DAEMON Tools\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\ICQ\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\KYQ8ZBOAXR\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\NeroFilterCheck\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\QuickTime Task\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SearchSettings\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SweetIM\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\Tobias\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\{8A166BDA-4591-7E9D-6201-0BB7707305E8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A166BDA-4591-7E9D-6201-0BB7707305E8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\{9AD77469-89CC-3354-3A72-25F37B434BAE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9AD77469-89CC-3354-3A72-25F37B434BAE}\ not found. C:\WINDOWS\ufa folder moved successfully. C:\WINDOWS\phoenix\kernels\poclbm folder moved successfully. C:\WINDOWS\phoenix\kernels\phatk folder moved successfully. C:\WINDOWS\phoenix\kernels folder moved successfully. C:\WINDOWS\phoenix folder moved successfully. C:\WINDOWS\update.7.1 folder moved successfully. C:\WINDOWS\update.5.0 folder moved successfully. C:\WINDOWS\update.8.1 folder moved successfully. C:\WINDOWS\update.2 folder moved successfully. C:\WINDOWS\av_ico folder moved successfully. C:\WINDOWS\update.1 folder moved successfully. C:\WINDOWS\update.tray-9-0-lnk folder moved successfully. C:\WINDOWS\update.tray-9-0 folder moved successfully. C:\WINDOWS\update.tray-8-0-lnk folder moved successfully. C:\WINDOWS\update.tray-8-0 folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Skype folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Common\fb#3aac6odczc2jcfewm5mhzqjysblg7yvjmbmophwtu6ymxgs3bxudnqldx6xz7n3lh9nly folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Video\Common folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Video folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\Manifest\Initial folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\Manifest folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\Download folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update\1.2.203.0 folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\Update folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook\CrashReports folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\Facebook folder moved successfully. C:\Programme\Ask.com\Updater folder moved successfully. C:\Programme\Ask.com\assets\oobe folder moved successfully. C:\Programme\Ask.com\assets folder moved successfully. C:\Programme\Ask.com folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\AskToolbar folder moved successfully. Folder move failed. C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\ManyCam scheduled to be moved on reboot. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Settings\Layer0\PlaylistSnapshots.pst_files folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Settings\Layer0\PlaylistMovies.pst_files folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Settings\Layer0\PlaylistImages.pst_files folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Settings\Layer0\Playlist.pst_files folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Settings\Layer0 folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Settings folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Objects\Holidays folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Objects\Fun folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Objects\Flags folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Objects\Avatars folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Objects folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Face accessories\Hats folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Face accessories\Hair folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Face accessories\Face folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Face accessories\Eyeglasses folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Face accessories\Eyebrow folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Face accessories folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Backgrounds\Static folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Backgrounds\Dynamic folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects\Backgrounds folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\Effects folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam folder moved successfully. C:\Programme\ManyCam\Help folder moved successfully. C:\Programme\ManyCam\Data\images\VideoSrc folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_stop folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_snapshot folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_shuffle folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_save folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_prev folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_playlist folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_play folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_openStillImage folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_openRecent folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_open folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_next folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_mute folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource\btn_loop folder moved successfully. C:\Programme\ManyCam\Data\images\videoSource folder moved successfully. C:\Programme\ManyCam\Data\images\VideoDriver folder moved successfully. C:\Programme\ManyCam\Data\images\tree folder moved successfully. C:\Programme\ManyCam\Data\images\trayMenu folder moved successfully. C:\Programme\ManyCam\Data\images\trackBar folder moved successfully. C:\Programme\ManyCam\Data\images\textEffectDlg\btn_font folder moved successfully. C:\Programme\ManyCam\Data\images\textEffectDlg\btn_clear folder moved successfully. C:\Programme\ManyCam\Data\images\textEffectDlg\btn_background folder moved successfully. C:\Programme\ManyCam\Data\images\textEffectDlg folder moved successfully. C:\Programme\ManyCam\Data\images\tab_sources folder moved successfully. C:\Programme\ManyCam\Data\images\tab_effects folder moved successfully. C:\Programme\ManyCam\Data\images\snapshotDlg\btn_snapshot folder moved successfully. C:\Programme\ManyCam\Data\images\snapshotDlg\background folder moved successfully. C:\Programme\ManyCam\Data\images\snapshotDlg folder moved successfully. C:\Programme\ManyCam\Data\images\selectedEffects\btn_clear_background folder moved successfully. C:\Programme\ManyCam\Data\images\selectedEffects\btn_clear folder moved successfully. C:\Programme\ManyCam\Data\images\selectedEffects folder moved successfully. C:\Programme\ManyCam\Data\images\pnpDlg\btn_single folder moved successfully. C:\Programme\ManyCam\Data\images\pnpDlg\btn_rec folder moved successfully. C:\Programme\ManyCam\Data\images\pnpDlg\btn_pnp folder moved successfully. C:\Programme\ManyCam\Data\images\pnpDlg\btn_pause folder moved successfully. C:\Programme\ManyCam\Data\images\pnpDlg\btn_background folder moved successfully. C:\Programme\ManyCam\Data\images\pnpDlg folder moved successfully. C:\Programme\ManyCam\Data\images\playList folder moved successfully. C:\Programme\ManyCam\Data\images\maindlg folder moved successfully. C:\Programme\ManyCam\Data\images\iconList folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg\btn_small folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg\btn_save folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg\btn_middle folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg\btn_large folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg\btn_clear folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg\btn_background folder moved successfully. C:\Programme\ManyCam\Data\images\drawEffectDlg folder moved successfully. C:\Programme\ManyCam\Data\images\DesktopDlg\btn_part_desktop folder moved successfully. C:\Programme\ManyCam\Data\images\DesktopDlg\btn_entire_desktop folder moved successfully. C:\Programme\ManyCam\Data\images\DesktopDlg\btn_castom_desktop folder moved successfully. C:\Programme\ManyCam\Data\images\DesktopDlg folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_yellow folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_white folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_violet folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_pink folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_orange folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_green folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_digital folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_blueBtn folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_blue folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_blackBtn folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_black folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg\btn_analog folder moved successfully. C:\Programme\ManyCam\Data\images\dateTimeDlg folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_saturation folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_red folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_green folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_grayButton folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_contrast folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_brightness folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls\btn_blue folder moved successfully. C:\Programme\ManyCam\Data\images\colorControls folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_zoomOut folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_zoomIn folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_up folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_right folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_properties folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_left folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_grayButton folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_down folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg\btn_center folder moved successfully. C:\Programme\ManyCam\Data\images\CameraDlg folder moved successfully. C:\Programme\ManyCam\Data\images\button folder moved successfully. C:\Programme\ManyCam\Data\images\btn_source_background folder moved successfully. C:\Programme\ManyCam\Data\images\btn_rotate_right folder moved successfully. C:\Programme\ManyCam\Data\images\btn_rotate_left folder moved successfully. C:\Programme\ManyCam\Data\images\btn_flipvert folder moved successfully. C:\Programme\ManyCam\Data\images\btn_fliphorz folder moved successfully. C:\Programme\ManyCam\Data\images\btn_addEffect folder moved successfully. C:\Programme\ManyCam\Data\images\backgroundControl\btn_snapshot folder moved successfully. C:\Programme\ManyCam\Data\images\backgroundControl\background folder moved successfully. C:\Programme\ManyCam\Data\images\backgroundControl folder moved successfully. C:\Programme\ManyCam\Data\images\addEffectDlg folder moved successfully. C:\Programme\ManyCam\Data\images folder moved successfully. C:\Programme\ManyCam\Data\effect_data\logo folder moved successfully. C:\Programme\ManyCam\Data\effect_data\lines folder moved successfully. C:\Programme\ManyCam\Data\effect_data\ILdata\images folder moved successfully. C:\Programme\ManyCam\Data\effect_data\ILdata folder moved successfully. C:\Programme\ManyCam\Data\effect_data\dynamic folder moved successfully. C:\Programme\ManyCam\Data\effect_data\dateTime folder moved successfully. C:\Programme\ManyCam\Data\effect_data\color folder moved successfully. C:\Programme\ManyCam\Data\effect_data\3dmasks\images folder moved successfully. C:\Programme\ManyCam\Data\effect_data\3dmasks folder moved successfully. C:\Programme\ManyCam\Data\effect_data folder moved successfully. C:\Programme\ManyCam\Data folder moved successfully. C:\Programme\ManyCam\Bin\x64 folder moved successfully. Folder move failed. C:\Programme\ManyCam\Bin scheduled to be moved on reboot. Folder move failed. C:\Programme\ManyCam scheduled to be moved on reboot. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ask\APN-Stub folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ask folder moved successfully. C:\WINDOWS\system32\drivers\etc\hosts moved successfully. C:\WINDOWS\system32\drivers\etc\hîsts moved successfully. C:\WINDOWS\info1 moved successfully. C:\WINDOWS\loader2.exe_ok moved successfully. Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ask\ not found. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{39850DC2-6343-4AE6-BC4C-63494A9C369F} folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{4843418D-E3A6-4662-842A-857DF0C650FB}\offline\F349FA91\7E151C73 folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{4843418D-E3A6-4662-842A-857DF0C650FB}\offline\F349FA91 folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{4843418D-E3A6-4662-842A-857DF0C650FB}\offline folder moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{4843418D-E3A6-4662-842A-857DF0C650FB} folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Azno folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\facemoods.com\facemoods folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\facemoods.com folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\FinalTorrent folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Maadci folder moved successfully. Folder C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\ManyCam\ not found. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Oksuzu folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\pdfforge\temp folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\pdfforge\res folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\pdfforge folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Search Settings\temp folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Search Settings\res folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Search Settings folder moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\Xuukhe folder moved successfully. ========== FILES ========== File\Folder C:\Programme\Ask.com not found. C:\Dokumente und Einstellungen\Tobias\AppData\LocalLow\Microñoft folder moved successfully. C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-343818398-1417001333-682003330-1003Core.job moved successfully. C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-343818398-1417001333-682003330-1003UA.job moved successfully. C:\Windows\tasks\FinalTorrent Update Checker.job moved successfully. C:\Windows\tasks\Scheduled Update for Ask Toolbar.job moved successfully. C:\WINDOWS\geoiplist.rar moved successfully. C:\WINDOWS\phoenix.rar moved successfully. C:\WINDOWS\rpcminer.rar moved successfully. C:\WINDOWS\ufa.rar moved successfully. C:\Dokumente und Einstellungen\Tobias\Anwendungsdaten\lakerda1967.sys moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Gast ->Temp folder emptied: 643 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: LocalService ->Temp folder emptied: 809 bytes ->Temporary Internet Files folder emptied: 9996853 bytes ->Flash cache emptied: 405 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33237 bytes User: Tobias ->Temp folder emptied: 30599168 bytes ->Temporary Internet Files folder emptied: 10537040 bytes ->Java cache emptied: 38076835 bytes ->FireFox cache emptied: 10421567 bytes ->Google Chrome cache emptied: 8751299 bytes ->Flash cache emptied: 611 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2114764 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2725 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 105,00 mb HOSTS file reset successfully OTL by OldTimer - Version 3.2.31.0 log created on 10282011_153820 Files\Folders moved on Reboot... C:\Dokumente und Einstellungen\Tobias\Lokale Einstellungen\Anwendungsdaten\ManyCam folder moved successfully. C:\Programme\ManyCam\Bin folder moved successfully. C:\Programme\ManyCam folder moved successfully. Registry entries deleted on Reboot... |
![]() |
| Themen zu einige trojaner agenten, viele backdoors und einen spyagent |
| backdoor.agent, bereit, bildschirm, blockiert, center, dateien, einstellungen, explorer, funktioniert, malewarbytes, microsoft, probleme, schwarzer bildschirm, security, seite, services, software, spyware.agent, svchost.exe, systemwiederherstellung, temp, trojan.agent, trojan.agent.ge, trojan.downloader.gen, trojan.spyeyes.gen, trojaner, version, video, viren, virus, youtube, zugriff, zugriff blockiert |