Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 18.08.2012, 13:08   #1
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Hallo Ihr,

ich habe ein Problem. Mein PC wurde mit Trojan.Generic befallen. Der SpywareDoctor hatte Ihn gefunden und gelöscht bzw. in Quarantäne gesetzt. Bin immernoch panisch, da viele schreiben, dass es nicht ausreicht Ihn so zu entfernen. Mein PC hatte gestern einfach von selbst angefangen irgendwelche Sachen zu schreiben...

Der Befall war in den Java Ordnern. Ich habe nun ein OTL Scan gemacht und folgendes Log bekommen.

Wie sollte ich mich nun Eurer Meinung verhalten? Sollte ich den PC komplett neu formatieren?

Gruss!
Andreas

Alt 18.08.2012, 13:27   #2
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Spyware Doctor Analyse:

Allgemeine Informationen
Speicherdatei in Quarantäne verlegen: 6D2414AD-7706-41EE-9B17-DAC4D6D96D03.sfs
Quarantäne erstellt am: 18.08.2012 - 10:15:29
Größe der Datei: 167936 bytes
Nummer der Objekte: 8

Trojan.Generic - Niedrig
C:\Users\user\Appdata\Locallow\Sun\Java\Deployment\cache\6.0\52\31bba1f4-60bbb2e9
C:\Users\user\Appdata\Locallow\Sun\Java\Deployment\cache\6.0\44\5473416c-4ec3abeb
C:\Users\user\Appdata\Locallow\Sun\Java\Deployment\cache\6.0\43\556445eb-5bf40d22
C:\Users\user\Appdata\Locallow\Sun\Java\Deployment\cache\6.0\4\5541aec4-479e4b17
C:\Users\user\Appdata\Locallow\Sun\Java\Deployment\cache\6.0\33\30feb821-7bb339b8
C:\Users\user\Appdata\Locallow\Sun\Java\Deployment\cache\6.0\10\78d6980a-119d6a06
C:\Users\user\Appdata\Local\Temp\jar_cache3875126157932507360.tmp
C:\Users\user\Appdata\Local\Temp\jar_cache2632320134432183809.tmp

Code:
ATTFilter
OTL Extras logfile created on: 18.08.2012 13:50:03 - Run 1
OTL by OldTimer - Version 3.2.57.0     Folder = C:\Users\user\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,49 Gb Total Physical Memory | 1,99 Gb Available Physical Memory | 56,88% Memory free
7,18 Gb Paging File | 5,58 Gb Available in Paging File | 77,70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146,48 Gb Total Space | 32,90 Gb Free Space | 22,46% Space Free | Partition Type: NTFS
Drive D: | 785,03 Gb Total Space | 752,62 Gb Free Space | 95,87% Space Free | Partition Type: NTFS
Drive F: | 963,73 Mb Total Space | 500,55 Mb Free Space | 51,94% Space Free | Partition Type: FAT
 
Computer Name: VERKAUF3 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days
 
========== Extra Registry (All) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.js [@ = jsfile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2542251369-281570442-2065618434-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{106461D0-6BBA-4DFE-B687-D6F92982117E}" = lport=139 | protocol=6 | dir=in | app=system | 
"{152CAC7B-4DFD-43F2-AFDD-1411EB888E35}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.5 | 
"{15FF7EB0-24E9-4981-9759-61F4AC3FF715}" = rport=139 | protocol=6 | dir=out | app=system | 
"{1B2F0EFC-CE15-4FD4-80D9-4A185EB24939}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{2EC248EC-F9AA-4680-B03F-1359E5248F54}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{4104984F-D508-404C-ACB2-DE857CE07EF3}" = rport=138 | protocol=17 | dir=out | app=system | 
"{54AEDCBF-C7A7-4F3A-8CC0-4E48B3724F46}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{56496BF1-1B32-483A-B7AF-64732B7C65AA}" = lport=137 | protocol=17 | dir=in | app=system | 
"{5DF81481-0184-4D42-A262-6D4A74B48E70}" = rport=445 | protocol=6 | dir=out | app=system | 
"{6549D05D-9B0A-4E3C-B398-C1D91F9CCA05}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{6C129ACC-6934-4104-A12D-28FDAA8A7A52}" = lport=138 | protocol=17 | dir=in | app=system | 
"{71965693-8A08-498C-8838-FF742772A689}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{82289108-5C1D-4076-97A0-60CB0D171A6D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | 
"{AD0CF77B-CF27-40CA-A5DE-CCA3BBDB9888}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{AE51759C-F80F-45D4-8CA4-BB0C55837651}" = lport=6112 | protocol=6 | dir=in | name=blizzard downloader | 
"{B18DA4DA-1453-432A-A675-8D8AC1D8CB13}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{C2C9A5F3-ACF5-45AF-9874-1361E2C7A9B4}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{C709E561-FB01-4324-A9D5-380874AC582B}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{CC3982B1-F1DF-4EE2-9AEA-E92BA7EA48C0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{D157EE68-E0FE-4871-9A10-9E00D03E04DE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{E02931A7-E122-4998-A59E-B292069A141B}" = lport=3946 | protocol=6 | dir=in | name=ventrilo | 
"{E90840F1-2821-4F05-8E06-ACABCE4565DA}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 | 
"{E92747D7-AE1F-4BB1-B729-71E5F1D82296}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{EB1B6184-E001-42BE-A52D-3D4290A712C5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{FDEC1BB1-C692-4C02-87C2-625E1F3F87B7}" = lport=445 | protocol=6 | dir=in | app=system | 
"{FF5C7D39-E19E-4F57-A896-651153A724C9}" = rport=137 | protocol=17 | dir=out | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00C7932C-D61F-473F-91EE-D17F7307345F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{01C988F2-5B73-4353-BE64-6C539B39C376}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{04851D07-7670-4DC3-BC23-68783961652C}" = protocol=6 | dir=out | app=system | 
"{06A323D9-CA5F-4969-B3D5-4B4310B86F31}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{07D607FC-40E2-4204-96D9-90DA313785E2}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-engb-downloader.exe | 
"{0FC77A14-87E4-4363-AAB4-9765B9F47C88}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{0FD7A0BD-2E7E-46C5-84A1-46B4273BC6B0}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{1009A282-735A-4061-99BD-92E676BE977E}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{10180036-9287-426A-84CE-6F0A3E6F6962}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{1055F073-D518-4CEB-ABAE-E90B290C4B45}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{11519837-ABAD-44C8-B681-16407E9363DD}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{1AE64408-6B33-4C54-AB2E-BC4812A70F06}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{1BAB34CA-3EA8-436E-92E9-5BCD24611A4F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{1CA1F947-10D7-429B-B90F-D86AC79BA0E3}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{1D733F30-F72C-4E96-A611-19A522EA6638}" = protocol=17 | dir=in | app=c:\users\user\appdata\local\apps\2.0\15jg11zj.472\lzhmavt2.gpv\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\curseclient.exe | 
"{1ED5A009-E271-4752-A4C7-7A78A34041EA}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.0.1-to-3.0.2-dede-win-update-downloader.exe | 
"{1FAFDD25-96EF-41F9-B850-6C9E7792F197}" = protocol=6 | dir=in | app=d:\spiele\starcraft ii\starcraft ii.exe | 
"{202FC4F5-244B-4D03-A3C8-4F19116DFC52}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-engb-downloader.exe | 
"{204D686E-EE36-4D3F-807B-001ED66E87B7}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{223F4BBC-0541-4591-8DC5-A02D31995554}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{224BCC9F-A6A6-4242-B650-2507AF26696E}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{2429818D-978E-442B-B5A5-21BCAF0026F0}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-engb-downloader.exe | 
"{24840FC6-F54C-4E6F-9C96-885ECBDB79BF}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{26C0B52A-DC99-4608-8DD6-499593FA371B}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{2CF89DB9-FCA7-405B-9911-D5087FDFED0D}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-engb-downloader.exe | 
"{2E2F2D7C-FF96-41B7-9AB8-E567767A720C}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{2F15B7FF-FD8A-49BA-A6C7-CD1AABDC76BC}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | 
"{2FF9FE12-0EEB-4170-B754-8FB19B6C19B8}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-engb-downloader.exe | 
"{371740EF-AF7E-4029-A344-5652613AFED1}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.0.1-to-3.0.2-dede-win-update-downloader.exe | 
"{39CB1172-8638-47C8-A1AA-DEBB035F3C64}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{3A51DBAF-5899-4FF4-BB48-E4401887A6CF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{3D18EC2F-3931-4D92-8A5E-8C33D2475A75}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{3FB0E919-D81E-4CC7-B825-701123F7E698}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{403D5678-FD52-4B52-8507-6DF8DFAE547A}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | 
"{4470F344-9AD8-4BCF-B1BB-8CBE195B48FA}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{46E2270F-47A6-4DF4-8A57-933D0D1FA7DE}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{4C5576E3-FFE2-4B64-8B7A-0AF5D5DA8BC4}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{4D93CD57-4448-4351-80CC-10AA64D81F16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{4E9EC35E-BF80-4DEF-8431-567A74E8F7BF}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{4F46A6B4-EA8B-4428-A4F1-BA2738A83C4C}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{54F377FB-B0E0-456B-ABAD-9D53625DF3A2}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{578C8070-0F17-47D8-BD40-D90005BBD6A2}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{5807F0C8-CDB1-451F-8702-3AFE34368EC6}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{5D36B659-60BF-46D7-889C-54D4EB580872}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{5DF1AAEE-267C-4304-81D7-7D60018C7FBC}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{6131B62F-CA12-4338-9A53-7DD65A2DF072}" = protocol=6 | dir=in | app=c:\program files\adobe\adobe flash builder 4.5\flashbuilder.exe | 
"{63D7BE6E-CC3B-4319-8773-85D5D836A125}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{64ABBD53-DF44-495B-8C37-5EA97E40EE6F}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{6695D531-7553-412C-8909-487EC70D28B5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{68D8B57A-DF3E-4601-80E2-15C8F27DF142}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{6971FDA8-2FDF-4860-B1B0-48806EE3F4B6}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{6D84733D-724A-4E63-AF46-ED3EB9081653}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{6F906D8E-3092-4AC5-BB97-11EE69A4E313}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-engb-downloader.exe | 
"{7073D57F-167F-404C-935C-880FD32BC87D}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{7107E952-DB97-4E16-8A6F-0C0F02304405}" = protocol=17 | dir=in | app=d:\spiele\civilization5\steam.exe | 
"{74860B75-578C-46DC-90DD-E40A824B4BA6}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{7751DD78-D8CB-488E-A894-73B0DD9CFDBA}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{77C661C4-3845-46C9-80BF-CA1460402C22}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{79950DA5-19FE-4775-8CCE-3EC4D236B18C}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{8031BCE7-60F9-4758-85EE-04629A0E0613}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{82F9F89E-FAC3-463E-85C1-E776904C60D8}" = protocol=17 | dir=in | app=d:\spiele\civilization5\steamapps\common\sid meier's civilization v\civilizationv.exe | 
"{853A4342-A870-431B-96BE-D2EE367C387D}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{8699229A-E2B7-4DAF-92A6-E7CA06B99F32}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{869C63DA-332C-4F9D-9578-FA48D197FE42}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{890FD895-0F32-4CDD-81A3-96C009D6A3A6}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{8B7377B7-2799-4336-80F4-E462DABC07AB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{8B9BC2BD-F3C6-49ED-BBEC-C5F8F136D37C}" = protocol=17 | dir=in | app=c:\users\user\appdata\local\apps\2.0\15jg11zj.472\lzhmavt2.gpv\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\curseclient.exe | 
"{8DBD26E0-72CF-4F06-9B20-B9E0E961EFE0}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.1.0-engb-downloader.exe | 
"{8EABDECD-0A6D-430D-BFA9-66528CE52A8B}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{8FDEC2AA-B532-40E9-A2A6-CDA129C1E3A2}" = protocol=6 | dir=in | app=d:\spiele\civilization5\steamapps\common\sid meier's civilization v\civilizationv.exe | 
"{9053152C-C84D-4B2A-97E6-76BEA8566E7F}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{92C40CAD-FA80-419E-AE7A-0FBEBC381006}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{93737319-6F5F-4FE9-804C-D18720E76786}" = protocol=17 | dir=in | app=d:\spiele\starcraft ii\versions\base15405\sc2.exe | 
"{9A50A317-33CB-4914-8FAF-549D8618E941}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-engb-downloader.exe | 
"{9B653C86-037D-437B-A616-45FEEEB8BE2F}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{9CB30BAD-D3F6-4AD7-B9C6-FDE3A4049E90}" = protocol=17 | dir=in | app=d:\spiele\starcraft ii\starcraft ii.exe | 
"{9D92FB31-963A-46DB-ADA8-48F821AC24AA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | 
"{9E702875-6F73-4E50-AD48-5C4B47C8655B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{9EB64010-0EBC-418C-823F-1CA40B42DB9D}" = protocol=17 | dir=in | app=d:\spiele\civilization5\steamapps\common\sid meier's civilization v\launcher.exe | 
"{A2360ADD-C592-40BE-A3CD-DAD2456EF05C}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-engb-downloader.exe | 
"{A323C349-FA27-40DB-A3BE-F1289D2E1F7C}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{A3C42A01-4C3C-42F5-B219-37DB80615482}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{A9AEF3EA-438C-440C-B4D6-904A48D5B31D}" = protocol=6 | dir=in | app=c:\users\user\appdata\local\apps\2.0\15jg11zj.472\lzhmavt2.gpv\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\curseclient.exe | 
"{AA837C89-824D-4F31-9397-D1A2ADB49056}" = protocol=17 | dir=in | app=c:\program files\adobe\adobe flash builder 4.5\flashbuilder.exe | 
"{AC39D349-DC9B-479C-8B8E-13E96B0BA9A9}" = protocol=6 | dir=in | app=c:\program files\curse\curseclient.exe | 
"{AC8FFFF3-2B05-4F02-A782-0108A7B2E659}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{AD3B08C5-6F5D-4E3B-A3D7-24CA8347D933}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{AE6AEC7E-531A-4513-9748-DFE1B2D1B247}" = protocol=6 | dir=in | app=d:\spiele\civilization5\steam.exe | 
"{B291D7CF-D55B-4286-8BD1-2DFB829179E0}" = protocol=6 | dir=in | app=d:\spiele\starcraft ii\versions\base15405\sc2.exe | 
"{B31F9B23-652E-4C51-AA26-C41E3AA1E64A}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{B360DBA4-DE6B-4330-B978-DE0497495E60}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-0.1.0-engb-downloader.exe | 
"{B607A4D8-BF09-47CF-A32B-FB5396047656}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{B614B3DC-072E-4E40-8ECB-7B566678599B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BCE228AA-DBF2-4937-8A07-2A80AA6118FB}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{BEF8FE62-BB50-4141-AE0C-A80D876EEAC0}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{C10D3225-E052-4F23-806B-43EE028FC01D}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{C2E8EC15-BA8F-48B9-BC97-159AC04DB392}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{C30B95E6-0C57-471E-9E79-4D6C342F266D}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{C9AD8628-E93B-48A0-ABD9-23D6CBA778A5}" = protocol=6 | dir=in | app=d:\spiele\civilization5\steamapps\common\sid meier's civilization v\launcher.exe | 
"{CD12C06D-F20A-4569-9D41-3984D4194F69}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{D6AC4AA9-11B5-4EE4-B38E-746C05BBFD5E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{DC9F32F6-4E6B-4406-A2A9-349CED530757}" = protocol=17 | dir=in | app=c:\program files\curse\curseclient.exe | 
"{E63DEC23-8177-4CB8-A869-24F1ADA5A6EF}" = protocol=6 | dir=in | app=c:\users\user\appdata\local\apps\2.0\15jg11zj.472\lzhmavt2.gpv\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\curseclient.exe | 
"{EC4F540D-BC79-4490-BF3B-D10F556D90CF}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{F11D7020-D286-4568-A426-4CC4FB087146}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{F20F598C-F836-4778-8833-6E1EACA39854}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{F95765FD-6329-4165-BEDF-0B2EC555502D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{FA1EDECB-AE3A-4413-A69D-2818F00B4DD1}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{FA359DB9-3963-45D9-B614-E41306E55F25}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"TCP Query User{04102038-3DFE-46CB-963D-F1F577D3F8DF}C:\program files\ventsrv\ventrilo_srv.exe" = protocol=6 | dir=in | app=c:\program files\ventsrv\ventrilo_srv.exe | 
"TCP Query User{0D5CC775-0DCE-4280-BB2C-0AF00CF3C1C6}C:\program files\teamspeak 3 client\ts3server_win32.exe" = protocol=6 | dir=in | app=c:\program files\teamspeak 3 client\ts3server_win32.exe | 
"TCP Query User{0D77C922-52FF-4DE7-B7A2-BC331D3E83B6}C:\users\user\appdata\local\temp\blizzard launcher temporary - 7748e828\launcher.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\blizzard launcher temporary - 7748e828\launcher.exe | 
"TCP Query User{0E23F10F-F98B-45BD-9C7E-DF2F12054CA0}C:\program files\curse\curseclient.exe" = protocol=6 | dir=in | app=c:\program files\curse\curseclient.exe | 
"TCP Query User{31ABE77D-FA8F-499B-ABF9-DDBA81D97884}D:\spiele\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\spiele\world of warcraft\launcher.exe | 
"TCP Query User{3614FC40-1634-44D7-A975-FC0834E953D8}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | 
"TCP Query User{37711532-0722-480C-8015-826034F57618}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"TCP Query User{5C0B2A90-6E65-4F2F-B36A-07940CF0BDBB}D:\spiele\neverwinternights\nwmain.exe" = protocol=6 | dir=in | app=d:\spiele\neverwinternights\nwmain.exe | 
"TCP Query User{97734394-E96A-4B6B-919E-120F4828D844}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | 
"TCP Query User{A28F0D42-BD81-4BA9-8FBC-F480CA93B2ED}C:\users\user\appdata\local\temp\blizzard launcher temporary - 9f196ab0\launcher.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\blizzard launcher temporary - 9f196ab0\launcher.exe | 
"TCP Query User{A678FFD5-F05C-40AF-8F65-6194B7B465F7}D:\spiele\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=d:\spiele\world of warcraft\backgrounddownloader.exe | 
"TCP Query User{C5C56EC1-B07D-4E08-B8AB-8CAE6AFCF942}D:\spiele\world of warcraft public test\launcher.exe" = protocol=6 | dir=in | app=d:\spiele\world of warcraft public test\launcher.exe | 
"TCP Query User{DBE9D6D8-7EA6-4739-A71D-3CE3847271BB}C:\dcm\acu\bin\wrun32.exe" = protocol=6 | dir=in | app=c:\dcm\acu\bin\wrun32.exe | 
"TCP Query User{EF1B3011-9C12-4CBD-8A80-6DBE8D696CDA}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"UDP Query User{0BF04250-4882-402A-98B2-9CF1951C057F}C:\users\user\appdata\local\temp\blizzard launcher temporary - 9f196ab0\launcher.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\blizzard launcher temporary - 9f196ab0\launcher.exe | 
"UDP Query User{3AC1437F-BFE2-477E-BB24-B933312F7D8B}C:\users\user\appdata\local\temp\blizzard launcher temporary - 7748e828\launcher.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\blizzard launcher temporary - 7748e828\launcher.exe | 
"UDP Query User{699FC08C-BD80-4212-9C6A-3F298004019E}D:\spiele\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=d:\spiele\world of warcraft\backgrounddownloader.exe | 
"UDP Query User{7400748A-FEE2-4D0F-80E8-21066828175F}D:\spiele\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\spiele\world of warcraft\launcher.exe | 
"UDP Query User{7B91352F-66E7-46C8-AE30-D5E0A6B1A6CD}C:\program files\teamspeak 3 client\ts3server_win32.exe" = protocol=17 | dir=in | app=c:\program files\teamspeak 3 client\ts3server_win32.exe | 
"UDP Query User{87CE1005-2F6F-4718-B3A7-B6B06DDD24C1}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | 
"UDP Query User{8CD92487-E8D4-4B41-A076-19FD9E5874BD}C:\program files\curse\curseclient.exe" = protocol=17 | dir=in | app=c:\program files\curse\curseclient.exe | 
"UDP Query User{A2E712FF-C93A-4A94-8926-2EA8354C83F7}C:\dcm\acu\bin\wrun32.exe" = protocol=17 | dir=in | app=c:\dcm\acu\bin\wrun32.exe | 
"UDP Query User{A37457B3-38BD-48BB-8884-F39DD4D30538}D:\spiele\world of warcraft public test\launcher.exe" = protocol=17 | dir=in | app=d:\spiele\world of warcraft public test\launcher.exe | 
"UDP Query User{AA6A5777-65EE-4137-A8E3-249187CB4651}D:\spiele\neverwinternights\nwmain.exe" = protocol=17 | dir=in | app=d:\spiele\neverwinternights\nwmain.exe | 
"UDP Query User{BB73537F-9DB1-405C-8B69-553F1F367EA9}C:\program files\ventsrv\ventrilo_srv.exe" = protocol=17 | dir=in | app=c:\program files\ventsrv\ventrilo_srv.exe | 
"UDP Query User{F792A451-4DD4-4D79-9E91-963FD7B6F56E}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"UDP Query User{FCBB0E39-0536-4EB6-8608-971FA0D6FB4E}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | 
"UDP Query User{FEA36E13-192B-4657-8F1C-FE18787C9FC9}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007F778D-F15C-4EAB-AE92-071D21FAF632}" = Adobe Photoshop Elements 9
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{06139D80-022B-4A0B-AD5F-E643E0294640}" = Magic-Office Erweiterung für Freie Händler
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{176B3593-72F1-459C-829C-5E9671E2CB35}" = GameSpy Comrade
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{405743AF-ED24-47BB-82BA-546FB5B524AA}" = Magic-Office Client Setup
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58AA0670-2352-424B-BE5F-CF59EDD07EA0}" = Razer Anansi
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6CC95B76-D380-46B2-9022-9353938E48BA}" = Logitech GamePanel Software 3.03.133
"{7AD94184-E6AF-443C-8F53-049E0265D4E4}" = UltraEdit
"{7C503E58-B2BC-11D5-978A-0050BA84F5F7}" = Neverwinter Nights
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A00B2A53-60D9-4477-ADA3-60490770C5E0}" = Daum ActiveX ÄÁÆ®·Ñ - ??? ?????
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E5C983-1B44-405D-9725-CD92C49863B3}" = UltraCompare v7.20
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{AD88355B-A4E0-4DA1-BAC3-EA4FEA930691}" = Ipswitch WS_FTP 12
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B0382C7F-846F-4036-9EAA-EDB505D51A8B}" = Magic-Office
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BCE46757-7674-4416-BEDB-68205A60409E}" = CanoScan Toolbox Ver4.1
"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D8D2B468-8342-411A-8760-BCC362C3408F}" = Adobe Creative Suite 5.5 Master Collection
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}" = Elements STI Installer
"{E64404F1-98DC-4CC8-A1A7-EF36E4E21031}" = Nero 8 Essentials
"{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop Elements 9" = Adobe Photoshop Elements 9
"ArcSoft PhotoBase" = ArcSoft PhotoBase
"ArcSoft PhotoStudio 2000" = ArcSoft PhotoStudio 2000
"Browser Defender_is1" = Browser Defender 2.0.6.15
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon RAW Codec" = Canon RAW Codec
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.dmp.contentviewer" = Adobe Content Viewer
"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
"FinalMediaPlayer_is1" = Final Media Player 2010
"GameSpy Arcade" = GameSpy Arcade
"Google Chrome" = Google Chrome
"InstallShield_{06139D80-022B-4A0B-AD5F-E643E0294640}" = Magic-Office Erweiterung für Freie Händler
"InstallShield_{405743AF-ED24-47BB-82BA-546FB5B524AA}" = Magic-Office Client Setup
"InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"InstallShield_{B0382C7F-846F-4036-9EAA-EDB505D51A8B}" = Magic-Office (Applikation)
"InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"IrfanView" = IrfanView (remove only)
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.18
"KONICA MINOLTA magicolor 4750 Installer" = KONICA MINOLTA magicolor 4750
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyCamera" = Canon Utilities MyCamera
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"PremElem90" = Adobe Premiere Elements 9
"PrintKey2000" = PrintKey2000
"ProTeria.NET_is1" = Deinstallation ProTeria.NET
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"SeaMonkey (2.11)" = SeaMonkey (2.11)
"Spyware Doctor" = Spyware Doctor 7.0
"SystemRequirementsLab" = System Requirements Lab
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 26.03.2012 09:50:31 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0x8004FC13
 
Error - 26.03.2012 09:50:31 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0x8004FC13
 
Error - 26.03.2012 10:00:29 | Computer Name = Verkauf3 | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung NMIndexStoreSvr.exe, Version 3.3.3.0, Zeitstempel
 0x47c6bd1b, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x0c0c0c0c,  Prozess-ID 0xba4, Anwendungsstartzeit
 01cd0b58bdc786d5.
 
Error - 26.03.2012 10:01:24 | Computer Name = Verkauf3 | Source = WinMgmt | ID = 10
Description = 
 
Error - 27.03.2012 05:45:02 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0xC004C008
 
Error - 27.03.2012 05:45:02 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 1014
Description = Fehler beim Erwerb der Endbenutzerlizenz. hr=0xC004C008  SKU-ID=f3acdd3c-119a-4932-a3d7-0b6f33a1dca9
 
Error - 27.03.2012 10:00:06 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0xC004C008
 
Error - 27.03.2012 10:00:06 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 1014
Description = Fehler beim Erwerb der Endbenutzerlizenz. hr=0xC004C008  SKU-ID=f3acdd3c-119a-4932-a3d7-0b6f33a1dca9
 
Error - 27.03.2012 14:15:05 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 8200
Description = Lizenzerwerb-Fehlerdetails.   hr=0xC004C008
 
Error - 27.03.2012 14:15:05 | Computer Name = Verkauf3 | Source = Software Licensing Service | ID = 1014
Description = Fehler beim Erwerb der Endbenutzerlizenz. hr=0xC004C008  SKU-ID=f3acdd3c-119a-4932-a3d7-0b6f33a1dca9
 
[ System Events ]
Error - 17.08.2012 08:56:54 | Computer Name = Verkauf3 | Source = WMPNetworkSvc | ID = 866312
Description = 
 
Error - 17.08.2012 08:57:14 | Computer Name = Verkauf3 | Source = Service Control Manager | ID = 7026
Description = 
 
Error - 18.08.2012 04:21:12 | Computer Name = Verkauf3 | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
 
Error - 18.08.2012 04:21:13 | Computer Name = Verkauf3 | Source = disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
 
Error - 18.08.2012 07:39:03 | Computer Name = Verkauf3 | Source = Service Control Manager | ID = 7011
Description = 
 
Error - 18.08.2012 07:39:33 | Computer Name = Verkauf3 | Source = Service Control Manager | ID = 7043
Description = 
 
Error - 18.08.2012 07:40:03 | Computer Name = Verkauf3 | Source = Service Control Manager | ID = 7043
Description = 
 
Error - 18.08.2012 07:42:12 | Computer Name = Verkauf3 | Source = Service Control Manager | ID = 7026
Description = 
 
Error - 18.08.2012 07:42:15 | Computer Name = Verkauf3 | Source = WMPNetworkSvc | ID = 866312
Description = 
 
Error - 18.08.2012 07:42:15 | Computer Name = Verkauf3 | Source = WMPNetworkSvc | ID = 866312
Description = 
 
 
< End of report >
         
__________________


Alt 20.08.2012, 09:54   #3
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Code:
ATTFilter
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.18.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
user :: VERKAUF3 [Administrator]

18.08.2012 15:27:38
mbam-log-2012-08-18 (15-27-38).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 551510
Laufzeit: 1 Stunde(n), 23 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations|bak_Application (Hijacker.Application) -> Daten: hxxp://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations|Application (Hijacker.Application) -> Bösartig: (hxxp://www.helpmeopen.com/?n=app&ext=%s) Gut: (hxxp://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
Nachzureichen war noch der Scan mit Malwarebytes Anti-Malware 1.62.0.1300, welcher nochmals fündig geworden ist.
Wie würdet Ihr nun vorgehen.

Vielen Dank für Eure Zeit im vorraus.

Feht Euch noch was? Wie kann ich die "Extras" Datei erstellen?
__________________

Geändert von loppy (20.08.2012 um 10:03 Uhr) Grund: Bemerkung vergessen.

Alt 21.08.2012, 13:23   #4
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Ist Hilfe hier möglich, oder bin ich es falsch angegangen? Hatte halt immer Spyware Doctor, wusste nicht, dass man den so leicht ausschalten kann

Geändert von loppy (21.08.2012 um 13:31 Uhr)

Alt 23.08.2012, 10:14   #5
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Erinnerung.

Bitte vergesst mich nicht


Alt 27.08.2012, 13:29   #6
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Bitte denkt an mich?

Alt 12.09.2012, 09:45   #7
loppy
 
Trojan.Generic Befall  Bitte um Hilfe nach OTL Log Auswertung! - Standard

Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!



Schade...

Antwort

Themen zu Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!
auswertung, befall, einfach, entferne, folge, folgendes, formatieren, gefangen, gelöscht, gestern, immernoch, java, komplett, log, meinung, neu, ordner, quarantäne, sache, sachen, scan, troja, trojan.generic, verhalten



Ähnliche Themen: Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!


  1. Trojan.GenericKD.2269178 (B) + Trojan.Generic.13051484 (B) + Trojan.Generic.12905642 (B)
    Log-Analyse und Auswertung - 10.04.2015 (12)
  2. Trj.CI.A befall, bitte um Hilfe bei der Auswertung ob ich etwas beim Löschen übersehen habe.
    Log-Analyse und Auswertung - 20.02.2015 (9)
  3. Hilfe! Trojaner Generic Befall
    Log-Analyse und Auswertung - 10.07.2013 (153)
  4. Trojan.Zaccess-Befall, bitte um Hilfe
    Log-Analyse und Auswertung - 06.09.2012 (14)
  5. Virenfund Trojan.Generic.7552386 und Trojan.Sirefef.FY nach GVU-Befall
    Log-Analyse und Auswertung - 03.08.2012 (15)
  6. Benötige OTL-Log Auswertung nach Exploit.Drop.2-Befall
    Log-Analyse und Auswertung - 09.04.2012 (23)
  7. Befall von Trojan.Generic.kdv.55894 und GEn:Variant.Kazy.2385.taskeng.exe
    Plagegeister aller Art und deren Bekämpfung - 28.10.2010 (1)
  8. Trojan.Win32.Generic!BT nach Internetbetrug gefunden
    Plagegeister aller Art und deren Bekämpfung - 25.07.2010 (8)
  9. Trojan.Generic.2861923 nach Neuinstallation
    Log-Analyse und Auswertung - 04.06.2010 (15)
  10. Auswertung von HJT nach Befall von fake Windows Security
    Log-Analyse und Auswertung - 08.01.2010 (2)
  11. Hilfe: Trojan.Generic.1624240
    Plagegeister aller Art und deren Bekämpfung - 12.05.2009 (21)
  12. Trojan.generic nach entzippen gefunden (Kspersky)
    Log-Analyse und Auswertung - 06.03.2009 (5)
  13. Trojan.Agent.AIVO sowie Backdoor.Bot4120 befall bei mir bitte Hilfe
    Plagegeister aller Art und deren Bekämpfung - 27.06.2008 (13)
  14. Viren Befall - Bitte um Hilfe bei EScan/HiJack Auswertung!
    Log-Analyse und Auswertung - 27.07.2007 (3)
  15. Möglicher Befall - Bitte um Auswertung
    Log-Analyse und Auswertung - 07.05.2007 (6)
  16. SinEspias-Befall Bitte um Hilfe bei der Log-File Auswertung
    Log-Analyse und Auswertung - 16.12.2005 (1)
  17. HILFE!!! Trojan horse Generic.GM
    Plagegeister aller Art und deren Bekämpfung - 29.09.2005 (1)

Zum Thema Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung! - Hallo Ihr, ich habe ein Problem. Mein PC wurde mit Trojan.Generic befallen. Der SpywareDoctor hatte Ihn gefunden und gelöscht bzw. in Quarantäne gesetzt. Bin immernoch panisch, da viele schreiben, dass - Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung!...
Archiv
Du betrachtest: Trojan.Generic Befall Bitte um Hilfe nach OTL Log Auswertung! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.