Alt 10.06.2010, 17:43   #1
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

ich hab mir den Icq-virus eingefangen & ich weiß nicht wie ich ihn wieder losbekomme. kann mir jemand helfen?

mfg julia

Alt 10.06.2010, 21:20   #2
/// Winkelfunktion
/// TB-Süch-Tiger™
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

Hallo und

bitte nen Vollscan mit Malwarebytes machen und Log posten. Danach OTL:

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.


Alt 11.06.2010, 14:43   #3
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

OTL Extras logfile created on: 11.06.2010 15:30:35 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Julia\Downloads
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,77 Gb Total Space | 5,62 Gb Free Space | 8,05% Space Free | Partition Type: NTFS
Drive D: | 69,52 Gb Total Space | 51,12 Gb Free Space | 73,54% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JULIA-HOME
Current User Name: Julia
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0 -- ()
"InternetSettingsDisableNotify" = 0 -- ()
"AutoUpdateDisableNotify" = 0 -- ()
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0 -- ()
"AntiSpywareOverride" = 0 -- ()
"FirewallOverride" = 0 -- ()
"DisableNotifications" = 0 -- ()
"EnableFirewall" = 1
"DisableNotifications" = 0 -- ()
"EnableFirewall" = 1
"DisableNotifications" = 0 -- ()
"EnableFirewall" = 1
========== Authorized Applications List ==========
"C:\Program Files\fotobuch.de AG\Designer 2.0\Designer.exe" = C:\Program Files\fotobuch.de AG\Designer 2.0\Designer.exe:*:Designer.exe -- File not found
========== Vista Active Open Ports Exception List ==========
"{0602F28C-F203-4194-8BFB-C1AE0A8B4D44}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{07D93EF9-FA1D-48F3-A662-D0C551EC01E2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{0BC3D5C4-80B3-47D3-B8E6-13A1B29BBEB2}" = rport=139 | protocol=6 | dir=out | app=system | 
"{176354AC-0591-4F4F-AE39-315E7A038287}" = lport=138 | protocol=17 | dir=in | app=system | 
"{289B1FEB-9E48-41D0-B740-DD5F8247A4D7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{2A636677-52A0-4F90-8FA2-6E1832520A4A}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{2F63B287-54A0-4B31-BC13-D488F91D804B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{36B1BBBC-3FA4-4C8E-B453-6B5B0493CE4E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{4B4BB51D-A51A-4DEB-9FF4-CAABCE8BCA6B}" = lport=137 | protocol=17 | dir=in | app=system | 
"{4EA19635-5532-4776-A66D-59C38DA86AAF}" = rport=445 | protocol=6 | dir=out | app=system | 
"{6E780EA6-DC3D-4A8D-B7BE-16C2121BDAA8}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{70A53153-0644-485C-AA75-3DB0CBC16EB2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{7ACFF061-624A-4D99-9065-AB536965329D}" = lport=445 | protocol=6 | dir=in | app=system | 
"{839F8DB1-DBB9-4EEB-90AC-B0590CF13463}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{887BA9DF-E115-4E8F-9C6F-ADB255415AE2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{8F37165A-369E-45D8-8320-0389766D896B}" = lport=139 | protocol=6 | dir=in | app=system | 
"{926B7149-BDC8-4192-A8F6-6C38903CE067}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{A2AB894F-2AE3-42A2-B88C-B206764CF702}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{BF83B286-97E6-417F-BC63-79763941FEEC}" = rport=137 | protocol=17 | dir=out | app=system | 
"{C1C03671-8749-4691-9636-0DB1D245670F}" = rport=138 | protocol=17 | dir=out | app=system | 
"{D4A9BEC3-E7E0-464F-9817-3C10272DA5A1}" = lport=10243 | protocol=6 | dir=in | app=system | 
========== Vista Active Application Exception List ==========
"{00CF1D9C-62C9-4272-97A8-B22D7B90EC7F}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{01A91341-1583-4993-999E-AA187F019139}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{0E7404BC-82D3-44BA-97D0-C2C4F802073E}" = protocol=17 | dir=in | app=c:\program files\icq7.0\aolload.exe | 
"{1886FEA2-D083-4853-B24A-BDFEDC4551BB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{20A87C19-4C7D-45EC-AA1D-A4BCACAFCBC5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{260B5341-1830-4B87-9ACD-4B40D6A75231}" = protocol=6 | dir=out | app=system | 
"{26122130-B5C0-440D-A7C7-F064D0C3FDAB}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe | 
"{2BBBBA9E-A6EA-4028-8CDC-D8149F617319}" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe | 
"{2CF660F9-043D-4D44-AAA9-CC8BFFA73B08}" = dir=in | app=c:\program files\acer arcade deluxe\play movie\playmovie.exe | 
"{2FE687CD-69B4-4000-9C49-A375970046B5}" = dir=in | app=c:\program files\acer arcade deluxe\dvdivine\dvdivine.exe | 
"{374A9A80-8424-4E97-BA38-80B8485E4FA0}" = protocol=6 | dir=in | app=c:\program files\icq7.0\aolload.exe | 
"{47B60C99-CD57-4D15-B032-32C2DEB185B2}" = dir=in | app=c:\program files\acer arcade deluxe\play movie\pmvservice.exe | 
"{4A063829-9864-4250-90FB-D03B196307D5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{56C75B83-630D-4A34-B229-C5A031B34093}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{6E48BCEF-0A7C-4EAC-8F9D-8FFC7B2E8C9A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{78738716-5FEE-4276-A892-53117EBE7A9F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{87BFA719-F2D7-43B6-BF2A-159AF1CF7283}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{8A8FFA2B-2378-4B33-B107-74CFCECECE02}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{8E7A26BC-4E72-453F-A543-9AAFEC11D844}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{95A42002-EC4B-4023-A653-D32B5A0831FF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{975AFC61-FE68-4CF6-A65A-564A9F5D9D35}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{9ABF3027-2CFA-4824-8121-28DDCF0AF8CB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{9F8F4367-ED82-4C10-8E18-329FFEA0EDBA}" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe | 
"{A0E0D9ED-FDDA-449E-87CA-C4864C343C4F}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{A81052FD-C9EE-4479-9457-4A27CF3C731F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{A9A89D73-24CF-459E-8FC6-A7DEABB9B5D5}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{AC1C30D1-9E32-418A-9020-946BEAE24E4B}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | 
"{C953C160-D1E1-40F6-9B5F-63F435EDF951}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{C9A6E4AE-1C25-469A-883C-F31DAAA87F27}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{D3B8284D-42DF-4B36-969D-54DF81218438}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{D974DD32-2CFE-4153-AB63-A79ECD2BCDAE}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"{E0E15590-6A38-461F-BA54-930C47CD9B0C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{E13DAC76-9080-488E-B14A-A09E8C7C96A0}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | 
"{E1CD9F7E-D5A5-4655-BB03-4FA1D04048A0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{E2061A89-8B2B-4C34-A0F5-85D6D996A2B4}" = dir=in | app=c:\program files\acer arcade deluxe\dv wizard\dv wizard.exe | 
"{E76074DF-3EC7-4C1A-B3F6-FA04A497620D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{F56A074B-A43B-4EAA-A4E1-28CD8197A223}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"{FB05615A-3F6C-48B2-912A-FECB096B4D62}" = dir=in | app=c:\program files\acer arcade deluxe\videomagician\videomagician.exe | 
"{FC35AC74-8D24-478F-A74F-18AFA8C771BB}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe | 
"TCP Query User{5E470293-36AE-4C98-9BA9-348E2942B63C}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"TCP Query User{93E2721A-B0D3-4B28-9E6B-81D56BE98BD2}C:\program files\icq7.0\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.0\icq.exe | 
"TCP Query User{A66E222B-C5CF-4B44-AB87-8573773D3E66}C:\program files\ares\ares.exe" = protocol=6 | dir=in | app=c:\program files\ares\ares.exe | 
"TCP Query User{AF8E29D3-A82F-4467-B046-05CD4A05E1EB}C:\program files\icq7.2\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"UDP Query User{93280175-E90C-41A0-A33B-EE3E1ED85C08}C:\program files\ares\ares.exe" = protocol=17 | dir=in | app=c:\program files\ares\ares.exe | 
"UDP Query User{A418CA4F-3206-4F66-8B08-A09545AF5CCE}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"UDP Query User{B6A2D2C2-B5B5-4519-B537-97E147B1BF70}C:\program files\icq7.2\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe | 
"UDP Query User{BD64CF19-2498-429B-B560-4B05D9ECFC48}C:\program files\icq7.0\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.0\icq.exe | 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{06EA4395-0EB6-4CEB-88D3-4AA320F8F6EA}" = Zlango Pic-Talk Setup
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08021248-88B6-E67B-CFD0-7B2C690CF37F}" = Catalyst Control Center Localization Russian
"{0ABBC013-7CF3-FEAE-8851-A4A290DC3D93}" = Catalyst Control Center Localization Norwegian
"{0E290898-A92A-682B-84BC-791E4B51D39E}" = Catalyst Control Center Localization Finnish
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{192A107E-C6B9-41B9-BDBF-38E3AA226054}" = OpenOffice.org 3.2
"{196654EB-009F-6E50-7BAB-CE60C89AE403}" = ccc-core-static
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{2758691A-2CDE-4942-A4AC-0E8F61FE2067}" = USB Video Device Driver
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2A5050FE-B629-D35A-38F3-89B353477674}" = Catalyst Control Center Localization Spanish
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java(TM) 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32D4851C-399A-4C02-A961-6A56178004B9}" = Hama Webcam Suite
"{34ED728D-ECE5-4A0D-9963-B54B318D0932}" = ccc-Branding
"{3838E2BF-91E8-730A-9C1C-4D73A9A08A91}" = Catalyst Control Center Graphics Light
"{3DB8A7B1-2EEB-56AF-A877-5742D2B18BEC}" = Catalyst Control Center Localization Dutch
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{429CEC54-6DE7-C63D-EB89-518AAB6F0E35}" = Catalyst Control Center Localization Korean
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D4C8490-9048-4E2C-AF1B-3866D6BC9EC8}" = WEB.DE Firefox Paket
"{4E55CE14-FC19-0D1F-E603-9CB92DBD9E7E}" = Catalyst Control Center Localization Italian
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works
"{5204EE13-A206-ED46-8AD6-5102491DE3B6}" = Catalyst Control Center Localization Portuguese
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{54ADF8E0-E14A-6C4E-9D60-51637D6576BE}" = Catalyst Control Center Localization Czech
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57265292-228A-41FA-9AEC-4620CBCC2739}" = Acer eAudio Management
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5D95AD35-368F-47D5-B63A-A082DDF00116}" = Microsoft Foto 2006 Standard Edition Editor
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{62355C0D-A1AC-0C50-582A-83F08692D1A4}" = Catalyst Control Center Localization Danish
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67ADE9AF-5CD9-4089-8825-55DE4B366799}" = NTI Backup NOW! 4.7
"{691F4068-81BF-49E3-B32E-FE3E16400112}" = Microsoft Foto 2006 Standard Edition Bibliothek
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A904BEA-D1B5-3077-E82D-239262DCE266}" = Catalyst Control Center Localization Thai
"{6CF2361C-E085-E644-9503-D2755C98D1B7}" = Catalyst Control Center Localization German
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7A2E65F0-FCD3-50F7-CD3A-D17E01D9B22D}" = Catalyst Control Center Localization Japanese
"{7CD88B0E-CC14-20C4-AAD7-310883457848}" = ccc-utility
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{7EE873AF-46BB-4B5D-BA6F-CFE4B0566E22}" = TuneUp Utilities Language Pack (de-DE)
"{802E72D3-BAD8-44A6-B51C-7E911144A870}" = Hama WEBCAM E110
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111473353}" = Dynasty
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent
"{86D6A20D-3910-4441-A3E5-EB6977251C86}" = Samsung USB Driver
"{8C13BEE4-E7CE-4E46-BD13-8F41DAD00FEF}" = SweetIM Toolbar for Internet Explorer 3.4
"{8DAE66B9-3D2C-870A-AC1F-D98D56B2E48D}" = Catalyst Control Center Localization Chinese Standard
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
"{90F1DDBF-0C56-44B0-A920-72CC90C51565}" = Microsoft Works Suite-Add-Ins für Microsoft Word
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{911B0407-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{94389919-B0AA-4882-9BE8-9F0B004ECA35}" = Acer Tour
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B850277-4198-1D44-B7BD-CA8D4DCEE620}" = Catalyst Control Center Localization Polish
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{9FDBB8DB-753F-6482-DB5E-2B7DA5577053}" = Catalyst Control Center Localization Chinese Traditional
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6B90148-02C5-4fd3-8D7A-EF2386835CB9}" = F4100_Help
"{A6C265BE-E2C1-483e-843D-6B4C1E912AE0}" = F4100
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AEA296D6-0F45-5B8E-FA16-6D553D5E6149}" = Catalyst Control Center Core Implementation
"{AEEAE013-92F1-4515-B278-139F1A692A36}" = Acer eDataSecurity Management
"{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B4509BCE-7BAD-4a8c-B1AE-4D0CE7467C42}" = F4100_doccd
"{B4F35A00-24FD-4fb3-BF5E-413D5423434D}" = DJ_AIO_Software_min
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
"{BFC7B8B9-37A3-F118-8929-8D6C0E52E9B2}" = Catalyst Control Center Localization Hungarian
"{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
"{C28512D7-66A1-2EF6-94F3-6A458BD76419}" = Catalyst Control Center Localization Greek
"{C99B5FE7-A85C-77A6-64BD-644358B01A45}" = Catalyst Control Center Localization Turkish
"{CA50045C-5119-48e7-9BA7-6B317379857A}" = DJ_AIO_Software
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE28E6F5-4A03-4DED-B954-D0779B47FFBF}" = Works Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe
"{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management
"{CE992AB2-28A0-4A92-01B8-970606F7B2A4}" = Catalyst Control Center Localization French
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D8FC2439-A2CA-6EEC-523D-8470C7967533}" = Catalyst Control Center Localization Swedish
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E2E7A0E8-77C4-495F-8FA3-63DAEDAA2DB3}" = F-Secure PSC Prerequisites
"{E548726E-F4E8-459f-BAB8-45551BC071E9}" = DJ_AIO_ProductContext
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{E848C9C0-E6FF-4A3F-9D67-AE53AC3628FE}" = SweetIM for Messenger 2.7
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Deluxe
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1249136-F629-460E-FC20-F5D4E3F7C180}" = ATI Catalyst Install Manager
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}" = HP Deskjet All-In-One Software 9.0
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ashampoo ClipFinder HD_is1" = Ashampoo ClipFinder HD 2.03
"ATI Uninstaller" = ATI Uninstaller
"Auto Movie Creator_is1" = Auto Movie Creator 3.2
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"cFosSpeed" = cFosSpeed v5.00
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.3
"Google Updater" = Google Updater
"GridVista" = Acer GridVista
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"ICQToolbar" = ICQ Toolbar
"ICQ-Tools_is1" = mehr ICQ Statussymbole
"Image Analyzer" = Image Analyzer
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"LManager" = Launch Manager
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mobile Partner" = Mobile Partner
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"PictureItPrem_v11" = Microsoft Foto 2006 Standard Edition
"PROR" = Microsoft Office Professional 2007-Testversion
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"TuneUp Utilities" = TuneUp Utilities
"Uninstall_is1" = Uninstall
"WEB.DE Firefox Browser Update" = WEB.DE Firefox Browser Update
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"Works2006Setup" = Setup-Start von Microsoft Works Suite 2006
========== HKEY_CURRENT_USER Uninstall List ==========
"Zylom Games Player Plugin" = Zylom Games Player Plugin
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10.06.2010 13:07:13 | Computer Name = Julia-Home | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description = 
Error - 10.06.2010 13:07:14 | Computer Name = Julia-Home | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description = 
Error - 10.06.2010 13:50:05 | Computer Name = Julia-Home | Source = FSecure-FSecure-F-Secure Anti-Virus | ID = 103
Description = 
Error - 10.06.2010 14:03:37 | Computer Name = Julia-Home | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description = 
Error - 10.06.2010 14:12:35 | Computer Name = Julia-Home | Source = Avira AntiVir | ID = 4122
Description = Die Datei AVPREF.DLL konnte nicht geladen werden.  Fehlercode: 0x45a
Error - 10.06.2010 14:21:30 | Computer Name = Julia-Home | Source = Web.de Update Service (AdminSVC) | ID = 100
Description = SetServiceStatus() failed error: '13'   Modul: adminsvcff     For more information,
 see Help and Support Service at hxxp://www.web.de    
Error - 10.06.2010 15:13:22 | Computer Name = Julia-Home | Source = Web.de Update Service (AdminSVC) | ID = 100
Description = SetServiceStatus() failed error: '13'   Modul: adminsvcff     For more information,
 see Help and Support Service at hxxp://www.web.de    
Error - 11.06.2010 03:23:54 | Computer Name = Julia-Home | Source = Avira AntiVir | ID = 4122
Description = Die Datei AVPREF.DLL konnte nicht geladen werden.  Fehlercode: 0x45a
Error - 11.06.2010 06:07:42 | Computer Name = Julia-Home | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description = 
Error - 11.06.2010 06:07:43 | Computer Name = Julia-Home | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description = 
[ Media Center Events ]
Error - 18.04.2008 13:01:28 | Computer Name = Julia-Home | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
[ System Events ]
Error - 10.06.2010 14:11:58 | Computer Name = JULIA-HOME | Source = WinDefend | ID = 2004
Description = Beim Laden der Signaturen wurde von %%827 ein Fehler festgestellt.
 Es wird versucht, einen als gültig bekannten Signatursatz wiederherzustellen.     Versuchte
 Signaturen: %%824     Fehlercode: 0x8050a001     Fehlerbeschreibung: Das Programm kann keine
 Definitionsdateien finden, die dazu dienen, unerwünschte Software zu erkennen. 
Überprüfen Sie, ob aktualisierte Definitionsdateien vorhanden sind, und versuchen
 Sie es dann erneut. Weitere Informationen zum Installieren von Updates finden Sie
 unter "Hilfe und Support".      Ladende Signaturen: %%825     Ladene Signaturversion: 1.83.1268.0

 Modulversion: 1.1.5802.0
Error - 10.06.2010 14:12:43 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7000
Description = 
Error - 10.06.2010 14:21:27 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7030
Description = 
Error - 10.06.2010 14:21:29 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7030
Description = 
Error - 10.06.2010 14:21:31 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7016
Description = 
Error - 10.06.2010 15:13:20 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7030
Description = 
Error - 10.06.2010 15:13:21 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7030
Description = 
Error - 10.06.2010 15:13:22 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7016
Description = 
Error - 10.06.2010 16:52:22 | Computer Name = Julia-Home | Source = DCOM | ID = 10010
Description = 
Error - 11.06.2010 03:24:02 | Computer Name = Julia-Home | Source = Service Control Manager | ID = 7000
Description = 
[ TuneUp Events ]
Error - 31.05.2010 03:31:25 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 01.06.2010 10:01:34 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 02.06.2010 10:19:29 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 08.06.2010 09:44:35 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 09.06.2010 14:07:54 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 09.06.2010 15:10:22 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 10.06.2010 03:55:48 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 10.06.2010 12:08:42 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 10.06.2010 12:47:40 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
Error - 10.06.2010 14:12:44 | Computer Name = Julia-Home | Source = TuneUp.UtilitiesSvc | ID = 300
Description = 
< End of report >
--- --- ---

Alt 11.06.2010, 14:52   #4
/// Winkelfunktion
/// TB-Süch-Tiger™
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

Was ist mit Malwarebytes?
Logfiles bitte immer in CODE-Tags posten

Alt 11.06.2010, 15:24   #5
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

was meinst du?'

Alt 11.06.2010, 15:25   #6
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

OTL Logfile:
Alt 13.06.2010, 13:18   #7
/// Winkelfunktion
/// TB-Süch-Tiger™
ich habe den ICQ-Virus - Standard

ich habe den ICQ-Virus

Was ist denn jetzt mit Malwarebytes? Nimm Dir doch einfach mal mehr Zeit zum Lesen der Postings und Anleitungen, das würde uns diese unnötige Nachfragerei ersparen!
Logfiles bitte immer in CODE-Tags posten


