Hallo Trojaner-Board, gestern wurde mir ein Link in ICQ geschickt welcher ein Bild sein sollte. Als ich diesen angeklickt habe wurde eine Installation-Datei runtergeladen(ich war misstrauisch) aber habe sie trotzdem installiert ![]() Jetzt habe ich meine Router-Firewall so eingestellt das Alles gemeldet wird was eine Verbindung zum Internet aufbauen möchte. Dabei sind mir die Programme Fz1.exe und Fz5.exe aufgefallen welche sich im Temp-Ordner befanden daraufhin habe ich diesen geleert(Darunter waren auch Dateien wie Fz2.exe Fz3.exe und Fz4.exe und diverse andere.)bis auf Fz1.exe und Fz5.exe ließen sich alle löschen. Diese beiden exes versuchen nun regelmäßig Verbindungen zu diversen Internetseiten aufzubauen. Außerdem wird regelmäßig der Internet-Explorer geöffnet jedoch ohne eine Seite anzuzeigen. Das ist der Stand der Dinge. Ich hoffe ihr könnt mir helfen. Vielen Dank schonmal mfg Tamad
Hallo und bitte nen Vollscan mit Malwarebytes machen und Log posten. Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________![]() bitte nen Vollscan mit Malwarebytes machen und Log posten. Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Hey.
| ![]() Fz1.exe Fz5.exe über ICQ-Link eingefangen Hallo, Maleware hat etwas länger gedauert. Mein PC ist wohl ziemlich voll. Maleware hat 32 infizierte Dateien/Registry gefunden davon konnten jedoch nicht alle gelöscht werden stand da. Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Datenbank Version: 4003 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18904 18.04.2010 21:07:32 mbam-log-2010-04-18 (21-07-32).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) Durchsuchte Objekte: 337215 Laufzeit: 1 Stunde(n), 2 Minute(n), 20 Sekunde(n) Infizierte Speicherprozesse: 1 Infizierte Speichermodule: 1 Infizierte Registrierungsschlüssel: 18 Infizierte Registrierungswerte: 3 Infizierte Dateiobjekte der Registrierung: 1 Infizierte Verzeichnisse: 0 Infizierte Dateien: 10 Infizierte Speicherprozesse: C:\Users\Public\winsvcn.exe (VirTool.DelfInject) -> Unloaded process successfully. Infizierte Speichermodule: C:\Users\Thomas\AppData\Local\Temp\sshnas21.dll (Trojan.Downloader) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows system guard (VirTool.DelfInject) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yvibbbha8c (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\canaveral (Trojan.Downloader) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Users\Public\winsvcn.exe (VirTool.DelfInject) -> Quarantined and deleted successfully. C:\Program Files (x86)\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files (x86)\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Users\Thomas\AppData\Local\Mozilla\Firefox\Profiles\xcek0a9t.default\Cache\4FC4ECE7d01 (Trojan.Buzus) -> Quarantined and deleted successfully. C:\Users\Thomas\AppData\Local\Mozilla\Firefox\Profiles\xcek0a9t.default\Cache\D2506F16d01 (Trojan.Buzus) -> Quarantined and deleted successfully. F:\User\Users\_Daten_\Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\Thomas\AppData\Local\Temp\Fz1.exe (Trojan.FakeAlert) -> Delete on reboot. C:\Users\Thomas\AppData\Local\Temp\sshnas21.dll (Trojan.Downloader) -> Delete on reboot. C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. Hier ist OTL OTL Extras logfile created on: 18.04.2010 21:39:19 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Thomas\Desktop 64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18904) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 76,00% Memory free 12,00 Gb Paging File | 11,00 Gb Available in Paging File | 86,00% Paging File free Paging file location(s): ?:\pagefile.sys %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 116,44 Gb Total Space | 39,55 Gb Free Space | 33,96% Space Free | Partition Type: NTFS Drive D: | 116,44 Gb Total Space | 103,13 Gb Free Space | 88,57% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 596,17 Gb Total Space | 518,83 Gb Free Space | 87,03% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: THOMAS-PC Current User Name: Thomas Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = 4F FB DE 5F C7 89 C8 01 [binary data] "VistaSp2" = 0F 45 E0 E0 AB DE C9 01 [binary data] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{12591BB9-25D9-4BBD-A47B-9684B93A6878}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{2A3F537C-B46B-4140-BAF2-6EA78BE23F35}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{2AE8DEEB-B9F6-407C-B341-4F71082FE8A2}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{35F9275F-9250-42F6-99DC-8CDC3F1BEEF6}" = lport=2869 | protocol=6 | dir=in | app=system | "{604FECF1-5142-4827-9205-830727AEB5AE}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{73CAC076-3B5B-49B4-9288-D352C7F27FD8}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{ADEDBA0F-AE66-4D39-B84F-25289EAD6CC3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B3758D33-749E-4703-946A-E2CD5DB78C22}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{C34FDBEC-516C-4D4C-A18E-0A42DCCC0383}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FF9D10AC-EB70-4773-9EF2-FD52DA3B456B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{063A17F0-9D3D-4C8B-B831-DF8565DAF340}" = protocol=17 | dir=in | app=d:\programme\burnout\burnoutlauncher.exe | "{0EEB48BD-B1E6-474D-A108-56B8C4D35896}" = protocol=17 | dir=in | app=d:\burnout\burnoutconfigtool.exe | "{10CA0480-3A9C-4745-BA0D-C7D14DC16DFC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{11663995-A4F6-456F-882E-9E2804FF15E5}" = protocol=17 | dir=in | app=d:\programme\burnout\burnoutparadise.exe | "{158670B7-D399-4EC9-B396-75F4D9D1789D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{15F3DDD5-316F-48F3-84E7-690A93B1368C}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | "{230C2EC3-C02F-4704-9327-4B857CA38BE3}" = protocol=6 | dir=in | app=d:\programme\burnout\burnoutparadise.exe | "{29F3EDF1-ECFE-410A-8ABD-099F9DAB2575}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe | "{2CE2970B-6D1C-4D58-BAFD-55A681AC63D9}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\logitech vid\vid.exe | "{30DFE133-4313-4AE5-AC64-1112207BF29D}" = protocol=6 | dir=in | app=d:\burnout\burnoutparadise.exe | "{38ECF3AB-EDBB-433D-A0BC-6F150E436D44}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{41B0E012-0F67-454C-9B4F-4944B253499A}" = protocol=17 | dir=in | app=d:\burnout\burnoutlauncher.exe | "{441DF7EF-DBEC-4DCE-9D90-8844AEBAD46A}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\fboxupd.exe | "{4934318B-74E2-475B-B2B6-9809D417B137}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\fboxupd.exe | "{4B7B6776-DABA-4532-B9F5-E54573C52A5C}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\webwaigd.exe | "{56377A8D-CEEC-4079-8273-48F859182EB3}" = protocol=6 | dir=in | app=c:\program files\fritz!dsl\igdctrl.exe | "{59761267-84C5-491C-B315-F88078D653B6}" = protocol=17 | dir=in | app=f:\bfbc2\limited edition\bfbc2updater.exe | "{5B0C67F9-5CDF-4BE3-8931-00CAAB941F98}" = protocol=6 | dir=in | app=d:\burnout\burnoutlauncher.exe | "{5DB48008-87D9-47F2-B593-C407022D7D55}" = protocol=6 | dir=in | app=d:\burnout\burnoutconfigtool.exe | "{5EE5A329-1E79-4206-AE06-AB2D3BB81F2A}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\icq.exe | "{6546E80C-C6F4-48DE-8CC1-E9633CE54DF8}" = protocol=6 | dir=in | app=f:\bfbc2\spiel\bfbc2betaupdater.exe | "{66225BF0-E912-4E9A-8995-BFE2563C46EF}" = protocol=6 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe | "{79A6EEE0-D558-4DC5-A88E-1336046A97D7}" = protocol=6 | dir=in | app=d:\programme\burnout\burnoutconfigtool.exe | "{7AD47396-5825-4779-8F87-FAFBF4B7C053}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe | "{80638A31-0DEA-43B1-8431-B68657166BF1}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{88472D84-6477-42C6-873E-FCFD91633F2B}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\webwaigd.exe | "{8C32458A-D1CB-444D-A86B-F10670627438}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{8E634411-9395-46E3-994D-D3638378FB7F}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\logitech vid\vid.exe | "{958F8326-EBA2-4A7A-ACA7-4DB76711F954}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{9E25CAAD-F5FB-483D-9BD9-99F3BB71A566}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{A372DDE4-9E2E-4644-98C2-60BF481368A7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{A426BA64-73FC-4029-9225-5E1399245F1C}" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\webwaigd.exe | "{A42D2B8B-4437-418B-A83D-141C77922FEC}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | "{A700CD85-1527-477A-BEC6-67D41D72AEE4}" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\fboxupd.exe | "{ABFD5022-7763-4909-8790-D3C922488C7A}" = protocol=17 | dir=in | app=d:\burnout\burnoutparadise.exe | "{BB676B27-5942-4B2A-BC19-DB266523314F}" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\webwaigd.exe | "{C3A1052B-8DE7-48D8-8FB1-E2793D6DF223}" = protocol=17 | dir=in | app=f:\bfbc2\spiel\bfbc2betaupdater.exe | "{C6737C74-D47C-455A-B833-5EFB84561146}" = protocol=6 | dir=in | app=d:\programme\burnout\burnoutlauncher.exe | "{C804F183-7C66-409A-99CC-97E71AEE9135}" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\fboxupd.exe | "{CC9974E4-6E2A-4E79-A708-BB39328E5D74}" = protocol=17 | dir=in | app=c:\program files (x86)\icq7.0\aolload.exe | "{D28B65C4-86A2-42CE-8FF3-86E3E308F918}" = protocol=17 | dir=in | app=d:\programme\burnout\burnoutconfigtool.exe | "{D477FF95-237B-4D54-AD67-43BEFF44BB17}" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\igdctrl.exe | "{E01B93AD-E9AC-444B-96E3-6FFEEDAABB89}" = protocol=6 | dir=in | app=f:\bfbc2\limited edition\bfbc2updater.exe | "{EBE4D24E-8E46-4700-A706-9F442F633AFB}" = protocol=17 | dir=in | app=c:\program files\fritz!dsl\igdctrl.exe | "{FA93FBFA-1FB5-40CC-9DE1-D142B1D602BC}" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\igdctrl.exe | "TCP Query User{05A2F318-18D5-4C6D-92F0-683953B379A1}C:\program files (x86)\ea games\battlefield 2\bf2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | "TCP Query User{1C3FEC39-B71A-4B34-8CFE-FECF3C048203}C:\program files (x86)\curse\curseclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "TCP Query User{62BA38B0-92CF-4E0C-8E13-3A08F5CBBA14}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "TCP Query User{8ADFC3AE-6E8D-40AB-A18F-FE2079A4D85E}C:\program files (x86)\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "TCP Query User{B1D210F6-D3F6-43ED-BB81-B4ABFD551D94}C:\program files (x86)\logitech\logitech vid\vid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\logitech vid\vid.exe | "TCP Query User{CF73CEC9-5366-4C21-BFC8-5BFFD1E3E6EF}F:\bfbc2\spiel\bfbc2game.exe" = protocol=6 | dir=in | app=f:\bfbc2\spiel\bfbc2game.exe | "TCP Query User{E624114E-E572-4C1D-B619-1CAF4FF80AEB}F:\bfbc2\limited edition\bfbc2game.exe" = protocol=6 | dir=in | app=f:\bfbc2\limited edition\bfbc2game.exe | "TCP Query User{E6A230B5-1EF8-4185-9D2E-41ECC8A63F62}C:\program files (x86)\steam\steamapps\common\wings of prey demo\acess.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wings of prey demo\acess.exe | "UDP Query User{1C9728BF-5A91-4A65-9715-D45D81FC33DD}C:\program files (x86)\steam\steamapps\common\wings of prey demo\acess.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wings of prey demo\acess.exe | "UDP Query User{1F4EEEBA-589B-422C-A30C-9996E301B39D}F:\bfbc2\spiel\bfbc2game.exe" = protocol=17 | dir=in | app=f:\bfbc2\spiel\bfbc2game.exe | "UDP Query User{54A22BE3-3CC7-4624-9EBD-82B98ECD3BB5}C:\program files (x86)\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "UDP Query User{54E25457-6023-48F0-9870-3C8AE414A576}C:\program files (x86)\curse\curseclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "UDP Query User{55A4AAB5-B734-44C5-A5F2-D553A4C7033B}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "UDP Query User{85E015CD-B529-49AB-A58F-EDA24C222252}C:\program files (x86)\logitech\logitech vid\vid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\logitech vid\vid.exe | "UDP Query User{CC03EB54-7E2F-4864-A299-B4DEBE3E12F2}F:\bfbc2\limited edition\bfbc2game.exe" = protocol=17 | dir=in | app=f:\bfbc2\limited edition\bfbc2game.exe | "UDP Query User{CF677E9A-0C17-485A-B9EE-A23A24592ACF}C:\program files (x86)\ea games\battlefield 2\bf2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer "{2D5D9603-22CF-4B99-83F6-0CD20330F62E}" = FRITZ!DSL64 "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{37A62E96-D157-487E-9954-84E8557DE9ED}" = ATI Catalyst Install Manager "{5FCF5515-4CC4-4812-8C9A-755336AB85F8}" = Logitech Motion Detector Gadget "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software "{9D42F24B-6BFC-42F4-AD90-A25680063754}" = eDocPrintPro v3.13.4 "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D285FC5F-3021-32E9-9C59-24CA325BDC5C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "{F250A44A-10C6-CF88-275C-899C259B1321}" = ccc-utility64 "{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper "81AE60DDD229A248055515E311406D86F7E4012A" = Windows Driver Package - Infineon Technologies (FlashUSB) USB (04/16/2009 "lvdrivers_12.10" = Logitech Webcam Software-Treiberpaket "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "TeamSpeak 3 Client" = TeamSpeak 3 Client "UltSounds" = Windows-Soundschemas "UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2(TM) "{065D5505-3821-4C2E-BB6C-FE66A7E7CB4F}" = USB Flash Port Driver "{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth "{0AFC55D4-9CDF-B140-2E4F-0B818B9B8C0E}" = CCC Help Italian "{0DE39AB6-D1BF-535C-F342-2F9986801936}" = CCC Help Japanese "{192A107E-C6B9-41B9-BDBF-38E3AA226054}" = OpenOffice.org 3.2 "{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Ethernet Utility "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{226EA3C9-0EAF-9546-46C4-F2FF55F7A6F1}" = CCC Help Dutch "{22980C46-EBB6-C22C-016A-E0CFAC15118B}" = CCC Help Czech "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{250755EE-312C-3B38-1BAF-501A71A3851D}" = CCC Help Turkish "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18 "{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime "{30D71FC9-E909-330C-57F9-C649C8837AA5}" = CCC Help Greek "{3154CFC9-2E4F-B839-2944-2A27200B4D64}" = CCC Help Swedish "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{361D8754-326D-B7CC-8DC7-95966DD01ED4}" = Catalyst Control Center Graphics Previews Common "{36E89A40-DD04-239B-A69E-532A27547089}" = CCC Help English "{37EC24B2-2E75-0AEB-F8A1-12A0C7EB5EED}" = Catalyst Control Center InstallProxy "{37FD8D84-7B88-6B5A-376A-34E2B7C28816}" = ccc-core-static "{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2 "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{4807FDA4-7AF3-66CA-C167-779A333D6FFC}" = Catalyst Control Center Localization All "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid "{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{5A154586-7AEB-4305-3B12-D73F0886B839}" = Catalyst Control Center HydraVision Full "{5DF79887-598B-DE65-9755-4B7D8C3D87BE}" = CCC Help Chinese Standard "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{61A0F92B-89A0-F7AD-4CA2-97991862EB10}" = CCC Help Hungarian "{687E8557-CBF3-A7FF-33EC-00BE6266BFAA}" = CCC Help Russian "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6A44A28A-5D79-8100-7BDF-FB637E62715B}" = CCC Help Polish "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7 "{6E19F210-3813-4002-B561-94D66AA182B6}" = Attansic L1 Gigabit Ethernet Driver "{72FA4B28-3A99-1533-0E7C-94E6D20CD1A8}" = CCC Help Chinese Traditional "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7CA26B08-BEFD-D4D2-52E1-24E730284594}" = Catalyst Control Center Graphics Light "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent "{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8E5CDC9B-CB0A-6E78-5BBE-C3D3F67B50E3}" = CCC Help Norwegian "{8F2F35B0-4019-4291-BBF5-121F51637FC7}" = VC80MFCRedist - 8.0.50727.4053 "{96A8FABC-AADB-F299-0826-AF2246CE012F}" = CCC Help Danish "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout(TM) Paradise The Ultimate Box "{9D98630B-BD50-3C44-58D2-1571AEA889D3}" = CCC Help Portuguese "{9E4EFA2A-4344-4C56-F927-7F7C53845BE2}" = CCC Help German "{A1C962E2-2426-49C6-A38B-9A07E40D607C}" = Microsoft Games for Windows - LIVE "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A37CA3F0-B0C6-8256-02BA-B06CEE1E5BEB}" = CCC Help Korean "{A724AEC6-494E-6BD5-C12A-9F51AF6C1123}" = Skins "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{ABD7DBE3-E344-4BCA-B8AD-4360494DD1D9}" = LG MC USB U330 driver "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{AC7EE5F1-0DE4-4256-8E43-92B73C8E6019}" = LG Bluetooth Drivers "{AC814121-74BA-A025-358E-B706354ED7F5}" = Catalyst Control Center Graphics Full New "{AF145F8997B44EE9B106D018EF1DB58B}" = DivX Converter Mobile "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5 "{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX "{CC2B3907-3DEA-6E0E-E5A5-C6FCF876ECD5}" = CCC Help French "{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1 "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D1F9CD55-A15A-846F-B2B1-D73F37C65B3E}" = CCC Help Spanish "{D3F80A98-05AB-4D8C-9272-766CCFA6A48D}" = DIE SIEDLER - Aufstieg eines Königreichs "{D94BA408-F110-488B-A65E-3AE7945F79E6}_is1" = LG PC Suite III deinstallieren "{D9D93D74-107D-4BD3-87D0-AABCF7C98BD5}" = Catalyst Control Center - Branding "{DEAC1EEB-48FD-36A6-B87B-58E365C92EFB}" = Catalyst Control Center Graphics Previews Vista "{E1640DA5-89B4-4F52-B15D-5DA3D14F29D4}" = LG USB Modem Drivers "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 "{E74A7FE1-1324-23D1-A050-187B2A6B1DE1}" = Catalyst Control Center InstallProxy "{E9E871B9-4E1D-38D7-7ECF-4DFD3708CC67}" = Catalyst Control Center Core Implementation "{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager "{EF7F8782-0E8D-A566-195F-8FF2360CA6C8}" = CCC Help Thai "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F15DDD54-CA1A-6764-2CF4-1C601725E96C}" = Catalyst Control Center Graphics Full Existing "{F1A14CB2-A048-45A6-AFDA-3571296E1D76}" = Creative Media Toolbox 6 "{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 "{F57A7C3E-AA0D-4F1A-B7EC-F7583571A517}" = DW6 Demo "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{F9A4662C-775D-32CF-4B6B-DEC701FDD516}" = CCC Help Finnish "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "ALchemy" = Creative ALchemy "ASIO4ALL" = ASIO4ALL "Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.10 (Unicode) "Audacity_is1" = Audacity 1.2.6 "AudioCS" = Creative Audio-Systemsteuerung "Avira AntiVir Desktop" = Avira Premium Security Suite "Console Launcher" = Creative Konsole Starter "Creative Software AutoUpdate" = Creative Software AutoUpdate "Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition "Diagnostics 4_5" = Creative-Diagnose "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v4.20 "FL Studio 9" = FL Studio 9 "Free YouTube to Mp3 Converter_is1" = Free YouTube to Mp3 Converter version 3.1 "GeoGebra" = GeoGebra "Host OpenAL" = Host OpenAL "Infineon USB driver_is1" = Infineon USB driver "InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch "InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch "InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch "InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3) "Mozilla Thunderbird (3.0.4)" = Mozilla Thunderbird (3.0.4) "Mp3tag" = Mp3tag v2.44 "PunkBusterSvc" = PunkBuster Services "RealPlayer 12.0" = RealPlayer "Space Synthesizer_is1" = Space Synthesizer 2.0 "Steam App 15680" = Warhammer 40,000: Dawn of War II - Single-player Demo "Steam App 16062" = Samantha Swift and the Golden Touch Demo "Steam App 8180" = Battlestations: Pacific - Demo "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "Trillian" = Trillian "Uninstaller_B4736000_Creative Media Toolbox 6" = Creative Media Toolbox 6 (Shared Components) "VLC media player" = VLC media player 1.0.3 "Warcraft III" = Warcraft III "WaveStudio 7" = Creative WaveStudio 7 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "WMV9_VCM" = Microsoft Windows Media Video 9 VCM ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "InstallShield_{F57A7C3E-AA0D-4F1A-B7EC-F7583571A517}" = DYNASTY WARRIORS 6 Playable Demo "Warcraft III" = Warcraft III: All Products ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 22.04.2009 08:08:28 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:28 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:28 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:28 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:28 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:28 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:29 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:29 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:29 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = Error - 22.04.2009 08:08:29 | Computer Name = Thomas-PC | Source = Audiorecorder | ID = 65535 Description = [ System Events ] Error - 18.04.2010 03:48:32 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7000 Description = Error - 18.04.2010 04:40:12 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7000 Description = Error - 18.04.2010 04:40:12 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7001 Description = Error - 18.04.2010 05:02:21 | Computer Name = Thomas-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am 18.04.2010 um 10:49:39 unerwartet heruntergefahren. Error - 18.04.2010 05:03:52 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7000 Description = Error - 18.04.2010 05:03:52 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7001 Description = Error - 18.04.2010 07:55:41 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7000 Description = Error - 18.04.2010 07:55:41 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7001 Description = Error - 18.04.2010 15:12:49 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7000 Description = Error - 18.04.2010 15:36:34 | Computer Name = Thomas-PC | Source = Service Control Manager | ID = 7001 Description = < End of report > |
![]() | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Fz1.exe Fz5.exe über ICQ-Link eingefangenZitat:
![]() ![]() Die (Be)nutzung von Cracks, Serials und Keygens ist illegal, somit gibt es im Trojaner-Board keinen weiteren Support mehr. Für Dich geht es hier weiter => Neuaufsetzen des Systems Bitte auch alle Passwörter abändern (für E-Mail-Konten, StudiVZ, Ebay...einfach alles!) da nicht selten in dieser dubiosen Software auch Keylogger und Backdoorfunktionen stecken. Danach nie wieder sowas anrühren!
Logfiles bitte immer in CODE-Tags posten
Hallo, Vielen Dank für die Hilfe! Das diese Datei auf meinem PC ist war mir nicht bewußt. In diesem _Daten_-Ordner befinden sich Dateien die sich auf meinem alten PC befanden. Aus dem ich einfach alle Dateien in diesen Ordner verschoben habe. Ich versichere das ich diese Datei nie benutzt habe. Und auf einer Lanparty nehme ich an auf meinen PC geschickt wurde man weiß ja nie was Kumpels so mit ihrer Moral vereinbaren können wenn sie sich an meinen PC setzen. Wenn mein PC nun sauber ist. Ist es nötig ihn neuaufzusetzen? Die Datensicherung von E-Mail programmen und persönlichen einstellung in Programmen empfinde ich als sehr aufwendig. Diese dann auch wieder an den richtigen Platz zu kopieren noch mehr. Die Bilder/Musik mal eben auf en USB ziehen wäre zwar kein Problem aber ich besitze leider kein solch großes Speichermedium. Und auch keinen Brenner. Sind mit alle Passwörter auch die gemeint die ich nicht benutzt habe seitdem diese "ICQ-Datei" meinen PC befallen hat. (ich speichere grundsätzlich keine Passwörte automatisch) Ich habe meine Lektion gelernt ![]() mfg Tamad
