![]() |
Trojaner: Survey says... ! Hallo Trojaner Board-Community! Ich habe mir gestern "versehentlich" einen Trojaner gedownloadet, der mein Win 7-System total blockiert; d.h. der pc bildschirm ist komplett weiß und es öffnet sich ein Fenster mit dem Titel "Survey says...". Darin steht ich solle einen Survey ausfüllen, tue ich dies nicht wird mein System unnützlich gemacht. Es öffnet sich also der Browser, doch die Seite kann nicht zuende geladen werden, schließe ich den Trojaner ohne die richtige Nummer eingegeben zu haben zu bekomme ich eine Ermahnung, bei drei Ermahnungen wird ebenfalls win 7 unnützlich gemacht werden. Ich habe schon bei Neustart mit f8 eine Systemreparatur durchgeführt, doch der Trojaner öffnet sich erneut, jedoch erst nach ein paar Minuten, was mir ermöglicht win7 kurz zu benutzen und sogar pr ogramme zu öffnen. Alles im Bezug auf win7 wird vom trojaner geschlossen, programme bleiben geöffnet, so kann ich zum beispiel mein antivieren-programm (avg) öffnen, welches rund 350 fehler auf meinem pc erkennt und ich habe den kompletten download ordner inhqlt gelösxht. Ich weiß mir nun schon gar nicht mehr zu helfen! Bitte Helft mir, hab versucht so ausführlich wie möglich mein problem darzulegen! |
Hi, Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code: activex
|
Ok bin wieder da, kann aber etwas dauern, weil die Kopier-Funktion geblockt wird! Ich kann aber dieses (0/0) nicht schreiben, oder ist das %? Was soll ich nun machen? ...? |
Hi dann starte neu, drücke f8, wähle abgesicherter Modus mit Netzwerk, melde dich im betroffenen Konto an, und versuchs mit otl erneut |
ok mach ich! Is ja doch n % ! Welche Einstellungen sind richtig (OTL) ? Überall Safelist und Dateialter 7 tage? ...? |
was für ein % meinst du? wie die otl konfig zu machen ist, steht eig oben im link + mein Script |
Und wo findet man otl.txt und extra.txt ? |
Wird automatisch geöffnet |
OTL.txt:OTL Logfile: Code: OTL logfile created on: 27.12.2012 20:35:30 - Run 1 |
Extra.txt: OTL Extras logfile created on: 27.12.2012 20:35:30 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Tammo\Downloads 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,98 Gb Total Physical Memory | 4,81 Gb Available Physical Memory | 80,34% Memory free 11,96 Gb Paging File | 10,79 Gb Available in Paging File | 90,17% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 450,66 Gb Total Space | 170,48 Gb Free Space | 37,83% Space Free | Partition Type: NTFS Unable to calculate disk information. Computer Name: TAMMO-PC | User Name: Tammo | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [scan_with_SPYWAREfighter] -- C:\Program Files (x86)\Fighters\SPYWAREfighter\swproTray.exe /scan "%1" (SPAMfighter) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [scan_with_SPYWAREfighter] -- C:\Program Files (x86)\Fighters\SPYWAREfighter\swproTray.exe /scan "%1" (SPAMfighter) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{2D84C835-A2AB-4883-9F10-C0B3C30F0D35}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{32D88249-914C-49AC-8EAD-6B735A129A2E}" = lport=139 | protocol=6 | dir=in | app=system | "{37C2641F-C3D9-4434-A100-849365A2033E}" = rport=445 | protocol=6 | dir=out | app=system | "{42018894-0B1D-40E8-9DC6-C6AD3C5A37EF}" = lport=138 | protocol=17 | dir=in | app=system | "{5EBC3AE6-5B9E-41D8-A1B3-A9326B2A6D28}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{72512386-1CFD-4C6B-8DAD-3F248FAA6000}" = rport=137 | protocol=17 | dir=out | app=system | "{8DB0CC56-E83B-4705-819C-186AE8E842D7}" = lport=137 | protocol=17 | dir=in | app=system | "{9D49F672-1A6A-4EAD-B2A7-D23AF20F7FC5}" = lport=445 | protocol=6 | dir=in | app=system | "{A1161494-FA84-45E7-BA46-68511436AAE2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C71408F1-2760-4DBB-BEA5-93DF170D7356}" = rport=139 | protocol=6 | dir=out | app=system | "{C9A924D6-6B9D-46D4-8469-B6936004A5EB}" = rport=138 | protocol=17 | dir=out | app=system | "{E33A6C99-71B1-4470-BCAB-D13EA22550CB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{ED1AB8A4-5B20-47B9-ADF8-1A9C09899F83}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{F6D80069-A520-43C4-A04A-08AB96151108}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{000E7141-09F2-458E-8990-07E03D99AC0E}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\clear.fi.exe | "{0755E3A0-6953-43E6-96FA-7726D34AC20A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe | "{07FFF922-4585-498B-8CF7-F5FCADEFF1A4}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{08A8C6F3-59F8-4194-9B94-974A5FF8B72C}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{0D2A6E85-EC85-43B9-8FF5-AFC0DADEF95D}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\.\kernel\clml\clmlsvc.exe | "{161E5E66-8BB1-489F-8282-C1A4C88DA407}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{1B7E8426-E36F-4CF2-892C-4C298C66F33B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{1D7666A2-D752-45B2-85FE-43D9383539FF}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\.\kernel\dmr\dmrengine.exe | "{26A8694E-C024-4D20-9BD6-A605CCC2AD94}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{2C740C30-7A92-4512-9043-05E8635D27AC}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{382EECC6-39DB-4361-9786-1F035588445D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{39E79FBF-2DA0-4EB2-B2C3-DA2628AD44E0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{3DBC3AA2-FB69-4D8C-994F-E555A31F49F5}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra\fearcombat\fearmp.exe | "{421FEABC-CA88-4FF6-A5E5-A55622F8DB3E}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 2050 j510 series\bin\usbsetup.exe | "{4EEFDA9C-B22F-448C-9329-E9607E5A8C70}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{50797324-45E9-4969-90B0-1DC72106D42B}" = protocol=6 | dir=in | app=c:\users\administrator\games\call.of.duty.4.germanpostmortem\mss32.dll\facemoods.exe | "{50E33445-B4A2-4FC6-96A9-43B8387D6B66}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe | "{54C65662-3E65-49D6-870F-EF649BDA5753}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{578ADE26-39E6-4EA5-BE18-542119D7C61E}" = protocol=17 | dir=in | app=c:\program files\mobileforces\system\mobileforces.exe | "{5A168311-BF82-4A16-A8F7-8C0D80A0C1F9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5CAF965F-A7FD-4CEA-B3C2-5A8B61256536}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{5E059189-1251-4DAC-9E85-CF5026892EF9}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\launcher.exe | "{60A01ACB-EE4E-442A-8D3C-7A9997DD52F5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{69B0D7A2-A716-4166-807D-45B9EC81C31D}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{74A35FD2-AD46-4F58-83EE-8EFEBFC3D101}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{7947207F-AA84-4D29-AEE3-80A0DADFF72A}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{7E5AD7F4-3383-49BF-AF5A-53F3A0988343}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra\fearcombat\fearmp.exe | "{7F2C49F5-01C6-440F-AD17-CA3FC68ACFED}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{8109C4FD-42AF-4F62-8E2A-F4122ADA3318}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{856D030D-7BD0-4024-84E3-7962475EDE58}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\.\kernel\dmr\dmrengine.exe | "{85E8C5D3-C77B-470F-99D3-64D9C58AC22B}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{862F796C-B12D-402B-B4DD-F3EF4A4BE4AD}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{8C9F2D0E-0FC1-4FBB-B07F-DC545100C468}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe | "{8DE6A392-DA19-4A75-AA72-02E4837B2E4B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{8FF2BF77-F7F5-4B51-A169-CE066549152F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{901C4076-A28A-436A-B2F2-326A00815A06}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{906A5F06-A28D-4C74-90D1-63245C1F54E5}" = dir=in | app=c:\program files (x86)\acer\clear.fi\movie\touchmovieservice.exe | "{916664B1-9ED0-438B-B692-03E98FE443DD}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{92D44510-B199-4F2D-B304-C299AF217101}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{94DBF2A0-EF2E-40ED-B25B-4B323836043A}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{986AE10A-35A8-4303-8448-C85479F29326}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{99CF0385-993B-429F-A217-9303A2CDB256}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{A5DBE75C-DE66-4C6E-A091-85D2F0C69C38}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A9024E1F-3446-4678-AE79-E360C58A620A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{A9294077-DD0A-4ED8-AF5B-7C7D0D45738A}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\clear.fiagent.exe | "{B2399E40-4A39-418F-8071-C43BBD5CFD93}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B79371FF-48AB-47CF-A890-3A847FC7CE11}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{B883265B-EA30-4148-B784-3B13006AF76D}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{B9C5DE62-B337-4C0D-ABAE-6502508D062B}" = protocol=17 | dir=in | app=c:\users\tammo\appdata\local\microsoft\windows\temporary internet files\content.ie5\8gs47nk5\sweetimsetup[1].exe | "{BAFF04A9-B40E-44D7-8FE1-0CE3FA11018F}" = protocol=6 | dir=in | app=c:\users\tammo\appdata\local\microsoft\windows\temporary internet files\content.ie5\8gs47nk5\sweetimsetup[1].exe | "{C61EB9DF-2F9B-4584-BE5E-7D60F6306365}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe | "{C625F38F-7F94-495E-BB7A-859CB4092ADD}" = protocol=17 | dir=in | app=c:\users\administrator\games\call.of.duty.4.germanpostmortem\mss32.dll\facemoods.exe | "{C843E56A-90A4-4812-A090-E76C706F74F5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{CA09A281-A5DF-4EE1-8895-517A345578AE}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{CBB0384A-3654-41E1-A49E-03C4DBC2B9EF}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{CE6B9528-FE43-4856-A8EF-8AD4F08E8DE3}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\.\kernel\dmr\dmrengine.exe | "{D19FC2C7-DFB9-4940-BC02-C3900B0ED7A7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe | "{D585D739-A57D-423C-9EB3-FA92DBB7F7E1}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\launcher.exe | "{DAC55044-82D2-4198-9DFB-1237C9649877}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{DBB2BCBA-0FC0-4484-ADA8-81F33D8794CE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{E13BEBC2-FDA6-44D2-993C-67DA7B62F182}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{E2B33EFB-C4E0-400E-93FB-493F7A67CA2F}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{E42981C3-34DB-4854-9DB1-5B1F8C348C41}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 2050 j510 series\bin\usbsetup.exe | "{E76C0969-B327-47E4-9CC3-F1893FD2DAB5}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{E90F7F81-5D6F-4DD2-8556-5C25BEAD28EF}" = dir=in | app=c:\program files (x86)\acer\clear.fi\movie\touchmovie.exe | "{EC0DE1B4-E42C-40DA-822C-95C3FB631707}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{EC6B9F61-DC96-48DC-BA6F-1EAFEACB2E11}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe | "{ECA24702-7419-487C-8A8F-A315BA8F02B2}" = protocol=6 | dir=in | app=c:\program files\mobileforces\system\mobileforces.exe | "{EF0902CD-928B-4227-AB75-5B66027939AA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{FA2A2F98-CB8C-4215-B591-FF3721F9346D}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{FF9E48C1-925A-4421-8D96-3B16A1EC462C}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "TCP Query User{0C275EBB-9CCB-4224-8564-D70C147ACCC9}C:\program files (x86)\far cry 2\bin\farcry2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\far cry 2\bin\farcry2.exe | "TCP Query User{136BD057-4E5D-4636-9B96-51817A805EBF}C:\program files (x86)\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\counter-strike source\hl2.exe | "TCP Query User{154A986C-40C6-4BF9-9A05-A7756605049A}C:\program files (x86)\call of duty black ops\blackopsmp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty black ops\blackopsmp.exe | "TCP Query User{1D5E23F9-786A-47CE-AAA5-6AFAE364D9F5}C:\users\tammo\desktop\diablo-iii-8370-engb-installer-downloader.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\diablo-iii-8370-engb-installer-downloader.exe | "TCP Query User{20C423A3-72A1-49D4-98EC-C3CC2E7AA2E6}C:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe | "TCP Query User{2628F7D3-DC77-400A-8181-3135CCD878B7}C:\users\tammo\desktop\crysis wars\bin64\crysis.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\crysis wars\bin64\crysis.exe | "TCP Query User{32912821-3E8F-4317-8B65-A973D19ED80E}C:\program files (x86)\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=c:\program files (x86)\battlefield 1942\bf1942.exe | "TCP Query User{44956FDB-DA65-4476-8C47-6842A1F3F16C}F:\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=f:\left 4 dead 2\left4dead2.exe | "TCP Query User{4C7FE93B-FA4B-4905-BF1B-D8F4DC03FB45}C:\users\tammo\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\tammo\appdata\roaming\spotify\spotify.exe | "TCP Query User{525BFB4C-C2B7-4C11-8329-AAECAE923CF6}C:\program files (x86)\starcraft ii\versions\base19679\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe | "TCP Query User{5367F42C-CC21-4B2F-93A5-49AD7427D322}C:\users\tammo\desktop\call of duty black ops\blackops.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\call of duty black ops\blackops.exe | "TCP Query User{5CCFC590-870F-4727-9F21-41A656DB1EF7}C:\program files (x86)\starcraft ii\versions\base19679\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe | "TCP Query User{63F32406-EB42-4A72-9F4F-231530C5778C}C:\program files (x86)\call of duty black ops\blackops.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty black ops\blackops.exe | "TCP Query User{68A6DE14-1CE1-49D0-83D9-3D5DAF3B64DD}C:\program files (x86)\starcraft ii\test\versions\base19595\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\test\versions\base19595\sc2.exe | "TCP Query User{6A9FA5F3-8F0F-4C40-83BA-80101C49E005}C:\users\tammo\desktop\teamspeak3-server_win32-3.0.0\teamspeak3-server_win32\ts3server_win32.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32-3.0.0\teamspeak3-server_win32\ts3server_win32.exe | "TCP Query User{6CB5A676-2FD1-4809-B698-2CB33EF2969C}C:\users\administrator\games\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\administrator\games\left 4 dead 2\left4dead2.exe | "TCP Query User{7052732F-CC03-481D-BDBE-7AC252FEC54C}C:\program files (x86)\call of duty black ops\blackops.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty black ops\blackops.exe | "TCP Query User{79B5D642-5932-44DE-A17F-CD180A6CA457}C:\users\tammo\appdata\local\temp\temp1_teamspeak3-server_win64-3.0.0-rc1.zip\teamspeak3-server_win64\tsdns\tsdnsserver_win64.exe" = protocol=6 | dir=in | app=c:\users\tammo\appdata\local\temp\temp1_teamspeak3-server_win64-3.0.0-rc1.zip\teamspeak3-server_win64\tsdns\tsdnsserver_win64.exe | "TCP Query User{7BD3ECE4-24E5-4F56-AB1D-F032A142C039}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | "TCP Query User{7C89B9CB-3958-4E97-A169-35B9542CD286}C:\program files (x86)\starcraft ii\starcraft ii public test.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | "TCP Query User{7D60FDE9-1419-4660-AD45-2BE3085E90DB}C:\users\tammo\desktop\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe | "TCP Query User{8A29EB77-9D49-42EB-B0FC-03272ABC0095}C:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe | "TCP Query User{8F7ABE84-40EB-4100-A746-86F2C2764CE7}C:\users\tammo\desktop\diablo-iii-8370-dede-installer-downloader.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\diablo-iii-8370-dede-installer-downloader.exe | "TCP Query User{922196B7-309A-422C-BC19-2C54E8462470}C:\program files (x86)\call of duty 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty 4\iw3mp.exe | "TCP Query User{9A76ED16-E6CA-4108-8A5C-3BD2B458005B}C:\program files (x86)\fifa 12\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fifa 12\game\fifa.exe | "TCP Query User{9B8B12D3-4815-4491-BD3F-EA18A30E44C4}C:\users\tammo\desktop\far cry 2\bin\farcry2.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\far cry 2\bin\farcry2.exe | "TCP Query User{9EFDD7C9-0891-4158-9BD3-317C2BFA0997}C:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\ts3server_win32.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\ts3server_win32.exe | "TCP Query User{A0E99DBD-5721-4B30-9500-09272DAC81E5}C:\users\tammo\downloads\starcraft_2_tw_zh-tw.exe" = protocol=6 | dir=in | app=c:\users\tammo\downloads\starcraft_2_tw_zh-tw.exe | "TCP Query User{A52B70F0-B76A-4583-85D2-27D9D37225DA}C:\program files (x86)\call of duty 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\call of duty 4\iw3mp.exe | "TCP Query User{A5B5050C-DCAA-437D-A82B-F52F39B38874}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "TCP Query User{AC795863-1B38-43DB-A573-235AA0E9AF8B}C:\users\tammo\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\tammo\appdata\roaming\spotify\spotify.exe | "TCP Query User{B65F880C-E6D3-4EFB-BE53-5F25A5B7737A}C:\program files\mobileforces\system\mobileforces.exe" = protocol=6 | dir=in | app=c:\program files\mobileforces\system\mobileforces.exe | "TCP Query User{B6892C62-1817-4B9D-8FAA-13F9BFB358BE}C:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe | "TCP Query User{BCA1E471-36FC-4D87-9478-B5B2C14CD56A}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "TCP Query User{BE9FD94F-1FA9-4FCF-BB58-841175BD7126}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "TCP Query User{C1896F2F-1D56-4B09-8CCC-19DBBB71C2BA}C:\program files (x86)\crysis wars\bin64\crysis.exe" = protocol=6 | dir=in | app=c:\program files (x86)\crysis wars\bin64\crysis.exe | "TCP Query User{C2B4EBCC-3F96-4994-B6EE-207D0447381F}C:\program files (x86)\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\counter-strike source\hl2.exe | "TCP Query User{CA428072-B4E3-4AD5-AC5C-2C93039A40D9}C:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe | "TCP Query User{CB1E1890-90C0-4561-A8E8-40D3C0218C23}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | "TCP Query User{D4CAD170-DEA6-4810-A1E1-85B0472BE3A1}F:\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=f:\borderlands\binaries\borderlands.exe | "TCP Query User{D5A0FB3F-361A-424C-9498-B22395B420B5}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | "TCP Query User{D61DC21B-DBD9-4C5F-8E4E-7EDB5AE76EFE}C:\users\administrator\games\call.of.duty.4.germanpostmortem\call of duty 4 - modern warfare\setup\data\iw3mp.exe" = protocol=6 | dir=in | app=c:\users\administrator\games\call.of.duty.4.germanpostmortem\call of duty 4 - modern warfare\setup\data\iw3mp.exe | "TCP Query User{D83BAC7D-5235-499E-A13D-240AD340DEE3}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{DE439C82-65F6-468D-A0E0-DFC15330BE56}C:\program files (x86)\brink\brink.exe" = protocol=6 | dir=in | app=c:\program files (x86)\brink\brink.exe | "TCP Query User{E6A3A712-E573-4E35-82D8-56A815C2FB8F}C:\users\tammo\desktop\call of duty 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\users\tammo\desktop\call of duty 4\iw3mp.exe | "TCP Query User{E8BE338A-F227-4C1D-84EA-E01461D19201}C:\program files (x86)\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "TCP Query User{E9207A04-FFDB-41D2-8B4A-EA0A0826D3AD}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe | "TCP Query User{EBA819F6-AEC0-41CF-AC34-A97ED5F4772C}C:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\nfs11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\nfs11.exe | "UDP Query User{08A458F1-65F6-4EF7-AA5B-EC25F76C2BBF}C:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\nfs11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\nfs11.exe | "UDP Query User{0DCEB031-8E8F-4E5B-BACA-1AC731CE7DDB}C:\users\administrator\games\call.of.duty.4.germanpostmortem\call of duty 4 - modern warfare\setup\data\iw3mp.exe" = protocol=17 | dir=in | app=c:\users\administrator\games\call.of.duty.4.germanpostmortem\call of duty 4 - modern warfare\setup\data\iw3mp.exe | "UDP Query User{0E91E613-012F-4F9D-8093-BCF6E3DA2F33}C:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\ts3server_win32.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\ts3server_win32.exe | "UDP Query User{173EDB4E-A725-4B90-B4AB-FCD8D1BF2583}C:\users\tammo\desktop\call of duty black ops\blackops.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\call of duty black ops\blackops.exe | "UDP Query User{1F9FFE3C-4FF9-4B65-B707-11DFCF40215A}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe | "UDP Query User{21B28240-94E8-4132-926A-247FB549179C}F:\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=f:\left 4 dead 2\left4dead2.exe | "UDP Query User{29DC1AFA-C9DC-4E78-B883-C4291251C717}C:\program files\mobileforces\system\mobileforces.exe" = protocol=17 | dir=in | app=c:\program files\mobileforces\system\mobileforces.exe | "UDP Query User{2CA2AF80-6A7A-4048-A74E-8DADFFE34D60}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "UDP Query User{3F600BE5-92E0-4FEF-85A6-75CAABFDD3BA}C:\users\tammo\desktop\far cry 2\bin\farcry2.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\far cry 2\bin\farcry2.exe | "UDP Query User{40B26DE0-D906-42F2-B620-E524F7D5AADC}C:\program files (x86)\starcraft ii\test\versions\base19595\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\test\versions\base19595\sc2.exe | "UDP Query User{480B3696-773E-4F39-A98F-60CE68438D3A}C:\program files (x86)\starcraft ii\versions\base19679\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe | "UDP Query User{4B915591-24A1-4DBC-8235-668531544020}C:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32-3.0.0-rc1\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe | "UDP Query User{54F14540-751A-4889-B370-536F8BE61015}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | "UDP Query User{551AE502-1C64-4F80-B4E2-5B94C9479CF9}C:\users\tammo\desktop\crysis wars\bin64\crysis.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\crysis wars\bin64\crysis.exe | "UDP Query User{564BEB50-78E4-49D2-B0A7-23ECCBE4830B}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{5D9849D9-03F9-4EBB-BCB2-76360954CF8A}C:\program files (x86)\starcraft ii\starcraft ii public test.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | "UDP Query User{5EB21886-6C14-4C55-8F72-4971D812AFB5}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | "UDP Query User{5F965106-DEFD-4A7D-8CEF-7FB4C1DFD853}C:\users\tammo\desktop\diablo-iii-8370-dede-installer-downloader.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\diablo-iii-8370-dede-installer-downloader.exe | "UDP Query User{607E50F7-9DF2-4473-AC21-6CC5D2CB0C07}C:\program files (x86)\call of duty black ops\blackopsmp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty black ops\blackopsmp.exe | "UDP Query User{67B14427-822C-4036-89CE-B14F2B8CE13D}C:\program files (x86)\fifa 12\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fifa 12\game\fifa.exe | "UDP Query User{67BABE44-FD3A-47D0-8A40-9E81FC3688EB}C:\program files (x86)\call of duty black ops\blackops.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty black ops\blackops.exe | "UDP Query User{7F8B0AAC-E83D-48B0-BD66-CBA7F7056BBE}C:\program files (x86)\call of duty 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty 4\iw3mp.exe | "UDP Query User{81447F9C-1412-4930-914E-A8DFF1F684F8}C:\program files (x86)\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\counter-strike source\hl2.exe | "UDP Query User{8527B837-16CE-4175-B229-34AE296BC133}C:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe | "UDP Query User{878749DD-2BBB-4305-8544-DF36CC76830B}C:\users\tammo\desktop\teamspeak3-server_win32-3.0.0\teamspeak3-server_win32\ts3server_win32.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32-3.0.0\teamspeak3-server_win32\ts3server_win32.exe | "UDP Query User{8D364BAB-922A-4D47-AA1A-4C029DD2A49B}C:\program files (x86)\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\counter-strike source\hl2.exe | "UDP Query User{90269C55-A579-430A-8377-DC8C46595DD6}C:\program files (x86)\call of duty 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty 4\iw3mp.exe | "UDP Query User{9231C907-4CE9-4DC0-99F5-D486FDD41B27}C:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\thq\saints row the third\saintsrowthethird_dx11.exe | "UDP Query User{9F157550-CFBA-4CE8-9140-3A00133C43F2}C:\users\tammo\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\tammo\appdata\roaming\spotify\spotify.exe | "UDP Query User{A1B70AEC-8823-4C65-A4E0-F405183BAAC3}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | "UDP Query User{B1260B71-5E9E-4D6B-8AFA-28AFDBA6099B}C:\users\tammo\desktop\diablo-iii-8370-engb-installer-downloader.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\diablo-iii-8370-engb-installer-downloader.exe | "UDP Query User{B4383AD1-16F3-4752-A134-DA23EED79A7B}C:\program files (x86)\brink\brink.exe" = protocol=17 | dir=in | app=c:\program files (x86)\brink\brink.exe | "UDP Query User{BE54500D-3F14-4859-B4B1-4C6A87D06B4A}C:\users\tammo\appdata\local\temp\temp1_teamspeak3-server_win64-3.0.0-rc1.zip\teamspeak3-server_win64\tsdns\tsdnsserver_win64.exe" = protocol=17 | dir=in | app=c:\users\tammo\appdata\local\temp\temp1_teamspeak3-server_win64-3.0.0-rc1.zip\teamspeak3-server_win64\tsdns\tsdnsserver_win64.exe | "UDP Query User{BEEA5B01-733D-4B0A-8483-0A699F41D620}C:\program files (x86)\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "UDP Query User{C4BB5BEF-15C0-47BE-A614-E6F1EB57290C}C:\program files (x86)\crysis wars\bin64\crysis.exe" = protocol=17 | dir=in | app=c:\program files (x86)\crysis wars\bin64\crysis.exe | "UDP Query User{C4E7724F-8B78-4390-8FA0-DF95CB565AD6}C:\program files (x86)\call of duty black ops\blackops.exe" = protocol=17 | dir=in | app=c:\program files (x86)\call of duty black ops\blackops.exe | "UDP Query User{D02F80D0-0CCB-4812-9295-A74CCB164E2F}C:\program files (x86)\far cry 2\bin\farcry2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\far cry 2\bin\farcry2.exe | "UDP Query User{D29A8D58-B8C5-4310-8D60-F2EFB9286C63}C:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\tammo97\team fortress 2\hl2.exe | "UDP Query User{D53866A9-BB94-4C50-A3C1-A83E20F0469E}C:\program files (x86)\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=c:\program files (x86)\battlefield 1942\bf1942.exe | "UDP Query User{DC5B9174-8C3E-4E47-A887-8049D7A58CEC}C:\users\administrator\games\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\administrator\games\left 4 dead 2\left4dead2.exe | "UDP Query User{DDADA426-7689-4C52-8E13-659F693CE913}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | "UDP Query User{DDB348AE-016B-4E2B-A302-700F19CD957E}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "UDP Query User{E8768D36-1A03-439F-A97C-4547CBD14F55}C:\users\tammo\desktop\call of duty 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\call of duty 4\iw3mp.exe | "UDP Query User{EA778C98-C1C8-4BEF-A14C-13811D7AC2AA}C:\program files (x86)\starcraft ii\versions\base19679\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19679\sc2.exe | "UDP Query User{ED6811DB-2170-4751-8D6F-94DDD4D54E04}F:\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=f:\borderlands\binaries\borderlands.exe | "UDP Query User{EE28C7BF-F3CF-4310-A44C-1722D73219B4}C:\users\tammo\desktop\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe" = protocol=17 | dir=in | app=c:\users\tammo\desktop\teamspeak3-server_win32\tsdns\tsdnsserver_win32.exe | "UDP Query User{F787AAC2-7C72-4975-A7A5-9E3C320BF698}C:\users\tammo\downloads\starcraft_2_tw_zh-tw.exe" = protocol=17 | dir=in | app=c:\users\tammo\downloads\starcraft_2_tw_zh-tw.exe | "UDP Query User{FA3B3E28-8918-4601-8194-E940B7081C2F}C:\users\tammo\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\tammo\appdata\roaming\spotify\spotify.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{10940C91-59FD-48D4-BE53-1A30A0C3235B}" = AVG 2011 "{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder "{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.478 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8E308612-4678-40BC-99A5-C95E7E6135DA}" = AVG 2011 "{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{982C480E-5BE0-2714-E584-83E88F8A31C3}" = ccc-utility64 "{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}" = Microsoft Xbox 360 Accessories 1.2 "{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 "{C263ED32-78DB-40EB-8B12-2925C8213E28}" = HP Deskjet 2050 J510 series - Grundlegende Software für das Gerät "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E69F8CE0-7EA0-63A9-5A5B-D8FD9BDCC219}" = ATI Catalyst Install Manager "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "AVG" = AVG 2011 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-Bit) "WNLT" = Web Optimizer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{063541C9-B4CA-CD49-080C-AEDE45067CEB}" = CCC Help Portuguese "{07580AC7-1B74-92E7-F405-9AD4019CA577}" = CCC Help Thai "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3 "{10AD2C1F-9825-F220-7870-CD7B946D367E}" = CCC Help Spanish "{13F59927-CFBE-44D1-8417-7203AD4F1795}" = Gothic 3 "{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite "{1B192700-C368-49C1-BF81-D2F9BA065534}" = Catalyst Control Center - Branding "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{23E26695-3815-012F-1CAF-C6C3564DBCBF}" = ccc-core-static "{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{29A4502B-1FA5-72E0-92F1-AC8F2EF16D51}" = CCC Help Danish "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{320795BA-446B-C1F7-9560-CC171192DC21}" = CCC Help Turkish "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{334BEF1F-EE5B-295F-BED0-728F7F45328B}" = CCC Help Polish "{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4 "{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX "{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3 "{43AAE145-83CF-4C96-9A5E-756CEFCE879F}" = clear.fi Client "{47772E7F-6942-B7A3-1B31-74D30343064B}" = CCC Help Norwegian "{485E3D4A-35FB-CED2-3CF5-FAD4CCFE46BD}" = CCC Help Hungarian "{4968622A-4D3F-489E-9ACE-5FEC4CC0BDE3}" = MediaEspresso "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A6D25EA-5390-CEE6-305E-F28B192C806C}" = CCC Help Finnish "{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "{557018DC-309C-5BCC-0587-B2D86BA20613}" = CCC Help Greek "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{704ED517-BB7F-7654-2185-627ACCB20179}" = Catalyst Control Center Localization All "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71BCF416-AA53-4F70-B253-88DFDE19B84B}" = Snap.Do "{7451FD2D-1A23-4E67-92CD-8EDDD1846917}" = AVG PC TuneUp Language Pack (de-DE) "{75E607CF-7BAE-4B88-84B3-97F3DF44BA28}" = FEARCombat "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3 "{7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}" = HP Deskjet 2050 J510 series Hilfe "{7B0D3494-9AB1-43AE-80B0-FD00E9516E55}" = Fighters "{7B284AC2-4756-6779-9274-FE20EE9216B7}" = Catalyst Control Center InstallProxy "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management "{800BE8AA-C912-E42D-E97F-BA533A2C851F}" = CCC Help Korean "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home "{83429F57-1A80-EB5B-8E60-C215D025A18B}" = CCC Help Italian "{83A606F5-BF6F-42ED-9F33-B9F74297CDED}" = Need for Speed(TM) Hot Pursuit "{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3) "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B3119BF5-2502-B6A6-45AA-A1FE5D82FFD7}" = CCC Help Russian "{B4C7BC58-3914-9EF9-E2B9-52216DFE899D}" = Catalyst Control Center Graphics Previews Vista "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B722FA60-A6EF-A3F5-DD4B-C826CDA16114}" = CCC Help Japanese "{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}" = clear.fi "{BF6C70DB-7E1E-4A85-B668-F4E80C3CA349}" = Condemned - Criminal Origins Demo "{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update "{CC7BBA77-7C6F-115C-4B47-0E3EE2610C13}" = CCC Help German "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}" = AVG PC TuneUp "{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}" = Bing Bar "{DBCCC93B-F646-EB40-4AB1-55D4BE0E5D30}" = CCC Help Dutch "{DBD55196-4BE4-CAAC-1447-4AF6657EEAD6}" = CCC Help Czech "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E1161FE3-E090-512B-BE20-AA276C2766CA}" = CCC Help Swedish "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5B8B8A6-BBD9-0B5F-1AA1-A95161C16247}" = CCC Help Chinese Traditional "{E5F1F9B2-90C3-83E2-888F-2725AACA93BD}" = CCC Help French "{E87C0C8B-82D6-7C51-B1A3-01EAF3314F7F}" = CCC Help English "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2E90747-42A1-E42F-C104-48239458946A}" = CCC Help Chinese Standard "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "{FCDDB05A-1B35-453B-47B5-AD75809BBBF9}" = PX Profile Update "Acer Registration" = Acer Registration "Acer Screensaver" = Acer ScreenSaver "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "AVG PC TuneUp" = AVG PC TuneUp "AVG Secure Search" = AVG Security Toolbar "BasicScan" = BasicScan 1.0 build 114 "Battlelog Web Plugins" = Battlelog Web Plugins "ESN Sonar-0.70.4" = ESN Sonar "FL Studio 10" = FL Studio 10 "Freemake Video Downloader_is1" = Freemake Video Downloader version 1.1.15 "Identity Card" = Identity Card "IL Download Manager" = IL Download Manager "IL Shared Libraries" = IL Shared Libraries "incredibar" = Incredibar Toolbar on IE and Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam "InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Acer Backup Manager "InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite "InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9 "IspAssistant-Mp3Tube" = IspAssistant-Mp3Tube "Mafia II_is1" = Mafia II "Mozilla Thunderbird (3.1.17)" = Mozilla Thunderbird (3.1.17) "Origin" = Origin "Pixillion" = Pixillion Image Converter "PortraitProfessional10Trial_is1" = Portrait Professional 10.8 Test "PriceGong" = PriceGong 2.6.7 "PricePeep" = PricePeep for Internet Explorer "Saints Row The Third_is1" = Saints Row The Third "Softonic" = Softonic toolbar on IE "Spotydl_is1" = Spotydl 0.5.0 "SPYWAREfighter" = SPYWAREfighter "StarCraft II" = StarCraft II "Steam App 43110" = Metro 2033 "Steam App 440" = Team Fortress 2 "TeamSpeak 3 Client" = TeamSpeak 3 Client "Uninstall_is1" = Uninstall 1.0.0.1 "Warcraft III" = Warcraft III "WinGimp-2.0_is1" = GIMP 2.6.11 "WinLiveSuite" = Windows Live Essentials ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "Spotify" = Spotify "Usenetnl" = Usenet.nl "Warcraft III" = Warcraft III: All Products ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22.12.2012 11:56:09 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:10 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:20 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:21 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:21 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:21 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:32 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:32 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:33 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = Error - 22.12.2012 11:56:33 | Computer Name = Tammo-PC | Source = .NET Runtime Optimization Service | ID = 1101 Description = [ System Events ] Error - 27.12.2012 15:46:51 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 27.12.2012 15:47:49 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 27.12.2012 15:47:49 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 27.12.2012 15:47:49 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 27.12.2012 15:48:57 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 27.12.2012 15:48:57 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 27.12.2012 15:48:57 | Computer Name = Tammo-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 |
hi dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user. wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts. • Starte bitte die OTL.exe • Kopiere nun das Folgende in die Textbox. Code: :OTL • Schliesse bitte nun alle Programme. • Klicke nun bitte auf den Fix Button. • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen. • Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren. starte in den normalen modus. falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten! Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + E Taste.
|
All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Live deleted successfully. C:\Users\Tammo\AppData\Local\Temp\winini.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\svchost deleted successfully. C:\Users\Tammo\AppData\Roaming\svchost.exe moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator User: All Users User: Default User: Default User User: Public User: Tammo ->Flash cache emptied: 1536 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Tammo ->Temp folder emptied: 7320954551 bytes ->Temporary Internet Files folder emptied: 556543798 bytes ->Java cache emptied: 1 bytes ->Google Chrome cache emptied: 295812937 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 4032 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 384254825 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 3141310 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 8.164,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 12282012_191628 Files\Folders moved on Reboot... File move failed. C:\Users\Tammo\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot. PendingFileRenameOperations files... |
Hi, upload fehlt |
Ok habe die Datei hochgeladen! Vielen, vielen Dank, dass du mir geholfen hast. KRaYZieGaMeR |
Ich danke, schau sie mir mal an. download tdss killer: http://www.trojaner-board.de/82358-t...entfernen.html Klicke auf Change parameters • Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system • Klick auf OK und anschließend auf Start scan - bei funden erst mal immer skip wählen, log posten |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:59 Uhr. |
Copyright ©2000-2025, Trojaner-Board