![]() |
|
Plagegeister aller Art und deren Bekämpfung: Banking Trojaner (40 TANs eingeben) los werdenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() Banking Trojaner (40 TANs eingeben) los werden Hallo zusammen! Ich hatte letzte Woche das Problem, dass ich beim online Banking nach dem Login bei der Postbank aufgefordert wurde, 40 TANs einzugeben. Bei der Postbank Servicehotline sagte man mir, dass ich zum Entfernen des Trojaners das Programm Anti-Malware von Emsisoft benutzen soll. Das habe ich getan und es wurden auch viele Probleme gefunden (ich finde leider kein Logfile, daher kann ich nicht genau sagen welche). Man Frage ist nun, wie herausfinden kann, ob ich clean bin? Ich habe noch nicht versucht mich beim Banking einzuloggen, da ich eine neue PIN und TAN-Liste bekommen habe. Sonst geraten die neuen Daten wieder in die falschen Hände. Das selbe Problem gab es schon hier im Forum: http://www.trojaner-board.de/88974-t...e-banking.html info.txtRSIT Logfile: Code:
ATTFilter logfile of random's system information tool 1.08 2010-08-16 21:38:09 ======Uninstall list====== -->C:\ProgramData\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER -->MsiExec /X{8A809006-C25A-4A3A-9DAB-94659BCDB107} Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall Adobe AIR-->MsiExec.exe /I{B194272D-1F92-46DF-99EB-8D5CE91CB4EC} Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10i_Plugin.exe -maintain plugin Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 9.3.3 - Deutsch-->MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A93000000001} Adobe Shockwave Player-->C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415} Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033} Ashampoo Burning Studio 6-->"C:\Program Files\Ashampoo\Ashampoo Burning Studio 6\Uninstall\BS6_Uninstall.EXE" Ashampoo Magical Optimizer-->"C:\Program Files\Ashampoo\Ashampoo Magical Optimizer\Uninstall\1406_Uninstall.exe" AVS DVD Player version 2.4-->"C:\Program Files\AVS4YOU\AVSDVDPlayer\unins000.exe" AVS4YOU Software Navigator 1.2-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe" Battlefield: Bad Company™ 2-->MsiExec.exe /X{3AC8457C-0385-4BEA-A959-E095F05D6D67} Call of Duty(R) - World at War(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{2BF0AE92-C3BC-4112-9066-1546342B1FAE}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) - World at War(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{CC862A04-B2B0-4A79-ADD2-4B76D6CF4DCD}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0407 Canon iP4300-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300 /L0x0007 Canon Utilities My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini CanoScan Toolbox Ver4.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{143FB15C-0C48-41E3-9C30-F56FB69BF3D7}\Setup.exe" -l0x7 anything CCleaner-->"C:\Program Files\CCleaner\uninst.exe" CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe" Cossacks - Back To War-->C:\Windows\una2setup.exe Counter-Strike: Source-->"C:\Program Files\Steam\steam.exe" steam://uninstall/240 Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10 CPUID CPU-Z 1.53.1-->"C:\Program Files\CPUID\CPU-Z\unins000.exe" Desktop Restore-->MsiExec.exe /I{116D1725-3193-49AF-8999-036D385F701E} DiRT 2-->"C:\Program Files\Steam\steam.exe" steam://uninstall/12840 DivX Converter-->C:\ProgramData\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER DivX Plus DirectShow Filters-->C:\ProgramData\DivX\DivX7\DivX Plus DirectShow Filters\DivXDSFiltersUninstall.exe /DSFILTERS DivX-Setup-->C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com DVD Solution-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall EA Download Manager UI-->msiexec /qb /x {4E5EE953-0D92-A385-E3A0-FBFCB2DE15AA} EA Download Manager UI-->MsiExec.exe /I{4E5EE953-0D92-A385-E3A0-FBFCB2DE15AA} EA Download Manager-->C:\Program Files\Electronic Arts\EADownloadManager\EADMUninstall.exe Emsisoft Anti-Malware 5.0-->"C:\Program Files\Emsisoft Anti-Malware\unins000.exe" Enemy Territory - QUAKE Wars(TM) Demo 1.1 Patch-->C:\Program Files\InstallShield Installation Information\{B7B6C0BE-C919-425C-A493-DF9FF11249F5}\setup.exe -runfromtemp -l0x0409 FileZilla Client 3.3.2.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe FlatOut2-->MsiExec.exe /I{7E641E46-81DB-4D1D-906A-48342523051C} Fraps-->"C:\programme\fraps\uninstall.exe" Free 3GP Video Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free 3GP Video Converter\unins000.exe" Free Studio version 4.7-->"C:\Program Files\DVDVideoSoft\Free Studio\unins000.exe" Free Video to Flash Converter version 4.2-->"C:\Program Files\DVDVideoSoft\Free Video to Flash Converter\unins000.exe" Free Video to Mp3 Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free Video to Mp3 Converter\unins000.exe" Free YouTube to Mp3 Converter version 2.5-->"C:\Program Files\DVDVideoSoft\Free YouTube to Mp3 Converter\unins000.exe" Futuremark SystemInfo-->C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe -runfromtemp -l0x0009 -removeonly GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins001.exe" Google Earth-->MsiExec.exe /X{F7B0939E-58DF-11DF-B3A6-005056806466} Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall Gothic II Gold-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92510C2A-30E3-4F8D-AE8A-93AB7B63EE8F}\setup.exe" -l0x7 -removeonly Gothic III-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{02B244A2-7F6A-42E8-A36F-8C385D7A1625}\setup.exe" -l0x7 -removeonly Gothic_Patch-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{302AC480-43D2-11D5-A818-00500435FC18}\Setup.exe" -uninst Gothic-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBF10B37-4ED3-11D5-A818-00500435FC18}\setup.exe" Grand Theft Auto IV-->"C:\Program Files\Steam\steam.exe" steam://uninstall/12210 GRID-->"C:\Program Files\InstallShield Installation Information\{5A0B7BA5-4682-4273-81C2-69B17E649103}\setup.exe" -runfromtemp -l0x0007 -removeonly Half-Life-->C:\Sierra\HALF-L~1\UNWISE.EXE C:\Sierra\HALF-L~1\INSTALL.LOG Hamachi 1.0.1.5-->C:\Program Files\Hamachi\uninstall.exe HLSW v1.3.1-->"C:\Program Files\HLSW\unins000.exe" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT="" ICQ7-->"C:\Program Files\InstallShield Installation Information\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly ijji REACTOR-->"C:\Program Files\InstallShield Installation Information\{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}\setup.exe" -runfromtemp -l0x0009 -removeonly IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe Java(TM) 6 Update 20-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF} Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Manhunt-->MsiExec.exe /X{8A62C8DA-2DB7-4D94-B5BA-1D38FC36E830} Mass Effect-->C:\Program Files\Common Files\BioWare\Uninstall Mass Effect.exe MediaShow 3.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5A9B7C0-8751-11D8-9D75-000129760D75}\setup.exe" -uninstall Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp" Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 3.5 Language Pack SP1 - DEU-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - deu\setup.exe Microsoft .NET Framework 3.5 Language Pack SP1 - deu-->MsiExec.exe /I{052FDD78-A6EA-3187-8386-C82F4CA3A929} Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} Microsoft .NET Framework 4 Client Profile DEU Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1031 /parameterfolder ClientLP Microsoft .NET Framework 4 Client Profile DEU Language Pack-->MsiExec.exe /X{F750C986-5310-3A5A-95F8-4EC71C8AC01C} Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6} Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{8FB1B528-E260-451E-9B55-E9152F94B80B} Microsoft Games for Windows - LIVE-->MsiExec.exe /X{F97E3841-CA9D-4964-9D64-26066241D26F} Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7} Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411-->MsiExec.exe /X{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989} mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC Mirror's Edge-->"C:\Program Files\Steam\steam.exe" steam://uninstall/17410 Mozilla Firefox (3.6.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF} MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC} MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC} MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13} NVIDIA Display Control Panel-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe DisplayControlPanel NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI NVIDIA PhysX-->MsiExec.exe /X{8A809006-C25A-4A3A-9DAB-94659BCDB107} NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask O&O Defrag Professional-->MsiExec.exe /I{CF49A5C4-E09A-4A22-BE7B-E42C687952BC} OpenAL-->"C:\Program Files\OpenAL\OpenALwEAX.exe" /U OpenOffice.org 3.0-->MsiExec.exe /I{7EC19307-7C22-47A8-922B-3FA965291260} Overlord-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11450 oZone3D.Net FurMark v1.6.5-->"C:\Program Files\oZone3D\Benchmarks\FurMark_v1.6.5\unins000.exe" Parabellum Beta-->"C:\Program Files\GamersFirst\Parabellum Beta\uninstall.exe" Parabellum-->"C:\Program Files\Acony Games GmbH\Parabellum\unins000.exe" PDFCreator Toolbar-->"C:\Windows\PDFCreator_Toolbar_Uninstaller_6538.exe" _?=C:\Program Files\PDFCreator Toolbar PDFCreator-->C:\Program Files\PDFCreator\unins000.exe PhotoNow! 1.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\setup.exe" -uninstall Postal 2-->C:\Windows\unvise32.exe C:\Program Files\Postal2\uninstal.log Power2Go 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall PowerBackup 2.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\setup.exe" -uninstall PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall PunkBuster Services-->C:\Windows\system32\pbsvc_bc2.exe -u Quake Live Mozilla Plugin-->MsiExec.exe /I{A10D9B03-AABB-47D7-8A30-2FEA97E70BC7} QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD} Rapture3D 2.3.26 Game-->"C:\Program Files\BRS\unins000.exe" RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0 Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0007 -removeonly REALTEK GbE & FE Ethernet PCI NIC Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe" -l0x7 -removeonly Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x7 -removeonly RealUpgrade 1.0-->MsiExec.exe /I{F4F4F84E-804F-4E9A-84D7-C34283F0088F} Risen-->"C:\Program Files\InstallShield Installation Information\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}\setup.exe" -runfromtemp -l0x0007 -removeonly RPG Maker 2000 - Super Columbine Massacre RPG!-->C:\Windows\gamedelete.exe "C:\Program Files\ASCII\RPG2000\ColumbineRPG\RPG_RT.ind" SAMSUNG Mobile Composite Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe Serious Sam 2-->C:\Program Files\Serious Sam 2\Bin\Uninstall.exe Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36} Source SDK Base-->"C:\Program Files\Steam\steam.exe" steam://uninstall/215 SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe" Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3} SuperRam-->"C:\Program Files\PGWARE\SuperRam\unins000.exe" TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe" TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe" Thrustmaster FFB Wheel driver-->C:\Program Files\InstallShield Installation Information\{57F9C8E9-A9B8-4E19-9AC2-F21EC5094B84}\setup.exe -runfromtemp -l0x0007 -removeonly ToCA Race Driver 3-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11500 Torchlight-->"C:\Program Files\Steam\steam.exe" steam://uninstall/41500 TuneUp Utilities 2008-->MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA} UE3Redist-->"C:\Program Files\InstallShield Installation Information\{2FB04107-7BC2-449C-915A-530B29B5E0FE}\setup.exe" -runfromtemp -l0x0409 -removeonly Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe" Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT="" VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421} Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F} VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409 Versatel-->C:\WINDOWS\\Versatel_UTIL.exe -UnInstall Warcraft III-->C:\Windows\War3Unin.exe C:\Windows\War3Unin.dat Windows Live Anmelde-Assistent-->MsiExec.exe /I{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60} Windows Live installer-->MsiExec.exe /X{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6} Windows Live Writer-->MsiExec.exe /X{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5} Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} WinRAR-->C:\Program Files\WinRAR\uninstall.exe WinZip 14.0-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240BA} Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe" Z Engine-->MsiExec.exe /X{2AE2EFF4-A14B-42AB-B364-F04DB651180F} ======Hosts File====== 84.38.66.128 datenklo.org ======Security center information====== AS: Windows-Defender ======System event log====== Computer Name: Ims-PC Event Code: 7036 Message: Dienst "Unterstützung in der Systemsteuerung unter Lösungen für Probleme" befindet sich jetzt im Status "Ausgeführt". Record Number: 218969 Source Name: Service Control Manager Time Written: 20100113112243.000000-000 Event Type: Informationen User: Computer Name: Ims-PC Event Code: 10029 Message: DCOM hat den Dienst wercplsupport mit den Argumenten "" gestartet, um den Server auszuführen: {0E9A7BB5-F699-4D66-8A47-B919F5B6A1DB} Record Number: 218968 Source Name: Microsoft-Windows-DistributedCOM Time Written: 20100113112243.000000-000 Event Type: Informationen User: Computer Name: Ims-PC Event Code: 20003 Message: Der Prozess zum Hinzufügen von Dienst tunnel für Geräteinstanz-ID ROOT\*6TO4MP\0249 wurde mit folgendem Status beendet: 0. Record Number: 218967 Source Name: Microsoft-Windows-User-PnP Time Written: 20100113111407.256892-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: Ims-PC Event Code: 20003 Message: Der Prozess zum Hinzufügen von Dienst tunnel für Geräteinstanz-ID ROOT\*ISATAP\0075 wurde mit folgendem Status beendet: 0. Record Number: 218966 Source Name: Microsoft-Windows-User-PnP Time Written: 20100113111354.620892-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: Ims-PC Event Code: 20267 Message: CoID={43C790BC-6AF4-449E-9620-77C0E63B2ABD}: Der Benutzer *****@versatel hat unter Verwendung des Geräts PPPoE2-0 eine Verbindung mit Breitbandverbindung hergestellt. Record Number: 218965 Source Name: RemoteAccess Time Written: 20100113111312.000000-000 Event Type: Informationen User: =====Application event log===== Computer Name: Ims-PC Event Code: 1531 Message: Der Benutzerprofildienst wurde erfolgreich gestartet. Record Number: 29789 Source Name: Microsoft-Windows-User Profiles Service Time Written: 20080929135249.000000-000 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: Ims-PC Event Code: 900 Message: Der Softwarelizenzierungsdienst wird gestartet. Record Number: 29788 Source Name: Microsoft-Windows-Security-Licensing-SLC Time Written: 20080929135249.000000- Logfile of random's system information tool 1.08 (written by random/random) Run by Ims at 2010-08-16 21:45:52 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 8 GB (3%) free of 238 GB Total RAM: 2046 MB (59% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:46:05, on 16.08.2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18943) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Ideazon\ZEngine\Zboard.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Windows\ehome\ehtray.exe C:\Users\Ims\Program Files\DNA\btdna.exe C:\Windows\ehome\ehmsas.exe C:\Users\Ims\Desktop\RSIT.exe C:\Program Files\trend micro\Ims.exe C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.versatel.de/internet-cd/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - - (no file) O1 - Hosts: ::1 localhost O1 - Hosts: 84.38.66.128 datenklo.org O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll O3 - Toolbar: (no name) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - (no file) O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [SuperRam] "C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe" /start O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\Run: [Google Update] "C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Ims\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [{40600DC1-73CE-5E4C-36A4-7AFB0D1553AB}] C:\Users\Ims\AppData\Roaming\Piqaip\azom.exe O4 - HKCU\..\Run: [{74EBC31A-57E4-0727-309F-4ED849E6E338}] C:\Users\Ims\AppData\Roaming\Loumu\iwyxx.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O4 - Startup: Optimieren - Verknüpfung.lnk = C:\Users\Ims\Desktop\ClearMem\Optimieren.bat O8 - Extra context menu item: Free YouTube Download - C:\Users\Ims\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Ims\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{27D809BC-1889-46D8-BFC6-A8702AAA84BE}: NameServer = 62.220.18.38 89.246.64.38 O17 - HKLM\System\CS1\Services\Tcpip\..\{27D809BC-1889-46D8-BFC6-A8702AAA84BE}: NameServer = 62.220.18.38 89.246.64.38 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Emsisoft Anti-Malware 5.0 - Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\Emsisoft Anti-Malware\a2service.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: SuperRam Speicher Service (SuperRam) - PGWARE LLC - C:\Program Files\PGWARE\SuperRam\SuperRamService.exe O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe -- End of file - 8074 bytes ======Scheduled tasks folder====== C:\Windows\tasks\1-Klick-Wartung.job C:\Windows\tasks\Google Software Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3908416098-2138756303-2722824237-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3908416098-2138756303-2722824237-1000UA.job C:\Windows\tasks\RegCure Program Check.job C:\Windows\tasks\RegCure.job C:\Windows\tasks\User_Feed_Synchronization-{B805C3A6-58FB-431E-B800-C9B792561349}.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}] RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-08-09 341600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-21 668656] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-05-15 352256] {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184] "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-01 4702208] "CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2008-03-18 1848648] "Zboard"=C:\Program Files\Ideazon\ZEngine\Zboard.exe [2009-06-04 57344] "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040] "SuperRam"=C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe [2009-04-01 988872] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760] "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832] "DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104] "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-08-09 202256] " Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-05-16 213936] ""= [] "Google Update"=C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-05 133104] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952] "BitTorrent DNA"=C:\Users\Ims\Program Files\DNA\btdna.exe [2010-08-11 323392] "{40600DC1-73CE-5E4C-36A4-7AFB0D1553AB}"=C:\Users\Ims\AppData\Roaming\Piqaip\azom.exe [] "{74EBC31A-57E4-0727-309F-4ED849E6E338}"=C:\Users\Ims\AppData\Roaming\Loumu\iwyxx.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA] C:\Users\Ims\Program Files\DNA\btdna.exe [2010-08-11 323392] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-05 133104] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] C:\Windows\system32\NvCpl.dll [2010-07-09 13939816] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe clear [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray] C:\Windows\system32\oodtray.exe [2008-11-03 2540800] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PDFCreator.lnk] C:\PROGRA~1\PDFCRE~1\PDFCRE~1.EXE [2009-03-07 2641920] C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Optimieren - Verknüpfung.lnk - C:\Users\Ims\Desktop\ClearMem\Optimieren.bat [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent" "C:\Programme\BitTorrent\bittorrent.exe"="C:\Programme\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent" "C:\Program Files\Combat Arms\CombatArms.exe"="C:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe" "C:\Program Files\Combat Arms\Engine.exe"="C:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe" "C:\Program Files\Combat Arms EU\CombatArms.exe"="C:\Program Files\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe" "C:\Program Files\Combat Arms EU\Engine.exe"="C:\Program Files\Combat Arms EU\Engine.exe:*Enabled:Engine.exe" "C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 months====== 2010-08-16 21:37:13 ----D---- C:\rsit 2010-08-16 21:37:13 ----D---- C:\Program Files\trend micro 2010-08-16 20:48:37 ----D---- C:\Users\Ims\AppData\Roaming\Malwarebytes 2010-08-16 20:48:18 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys 2010-08-16 20:48:17 ----D---- C:\ProgramData\Malwarebytes 2010-08-16 20:48:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2010-08-16 20:48:17 ----A---- C:\Windows\system32\drivers\mbam.sys 2010-08-16 20:40:17 ----D---- C:\Program Files\CCleaner 2010-08-10 21:26:30 ----A---- C:\Windows\system32\mshtml.dll 2010-08-10 21:26:30 ----A---- C:\Windows\system32\iertutil.dll 2010-08-10 21:26:29 ----A---- C:\Windows\system32\ieframe.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\wininet.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\urlmon.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\occache.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\mstime.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\msfeedssync.exe 2010-08-10 21:26:28 ----A---- C:\Windows\system32\msfeedsbs.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\msfeeds.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\jsproxy.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\ieUnatt.exe 2010-08-10 21:26:28 ----A---- C:\Windows\system32\ieui.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\iesysprep.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\iesetup.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\iernonce.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\iepeers.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\iedkcs32.dll 2010-08-10 21:26:28 ----A---- C:\Windows\system32\ie4uinit.exe 2010-08-10 21:26:24 ----A---- C:\Windows\system32\win32k.sys 2010-08-10 21:26:22 ----A---- C:\Windows\system32\iccvid.dll 2010-08-10 21:26:21 ----A---- C:\Windows\system32\schannel.dll 2010-08-10 21:26:19 ----A---- C:\Windows\system32\rtutils.dll 2010-08-10 21:26:11 ----A---- C:\Windows\system32\ntkrnlpa.exe 2010-08-10 21:26:10 ----A---- C:\Windows\system32\ntoskrnl.exe 2010-08-10 21:26:08 ----A---- C:\Windows\system32\msxml3.dll 2010-08-10 21:26:07 ----A---- C:\Windows\system32\drivers\srv2.sys 2010-08-10 21:26:07 ----A---- C:\Windows\system32\drivers\srv.sys 2010-08-10 21:26:06 ----A---- C:\Windows\system32\drivers\tcpip.sys 2010-08-10 16:41:27 ----D---- C:\Users\Ims\AppData\Roaming\DNA 2010-08-10 16:41:27 ----D---- C:\Program Files\DNA 2010-08-09 15:52:08 ----D---- C:\Program Files\Emsisoft Anti-Malware 2010-08-09 01:45:39 ----D---- C:\Program Files\Common Files\xing shared 2010-08-03 13:27:23 ----A---- C:\Windows\system32\shell32.dll 2010-07-29 18:16:19 ----D---- C:\Windows\system32\WindowsPowerShell 2010-07-29 18:15:26 ----A---- C:\Windows\system32\winrsmgr.dll 2010-07-29 18:15:06 ----A---- C:\Windows\system32\wsmprovhost.exe 2010-07-29 18:15:06 ----A---- C:\Windows\system32\winrshost.exe 2010-07-29 18:15:06 ----A---- C:\Windows\system32\winrs.exe 2010-07-29 18:15:05 ----A---- C:\Windows\system32\wsmplpxy.dll 2010-07-29 18:15:05 ----A---- C:\Windows\system32\winrssrv.dll 2010-07-29 18:15:02 ----A---- C:\Windows\system32\WsmRes.dll 2010-07-29 18:15:02 ----A---- C:\Windows\system32\wevtfwd.dll 2010-07-29 18:15:02 ----A---- C:\Windows\system32\wecutil.exe 2010-07-29 18:15:02 ----A---- C:\Windows\system32\wecsvc.dll 2010-07-29 18:15:02 ----A---- C:\Windows\system32\wecapi.dll 2010-07-29 18:15:01 ----A---- C:\Windows\system32\pwrshplugin.dll 2010-07-29 18:14:58 ----A---- C:\Windows\system32\winrm.vbs 2010-07-29 18:14:57 ----A---- C:\Windows\system32\WsmWmiPl.dll 2010-07-29 18:14:57 ----A---- C:\Windows\system32\WsmAuto.dll 2010-07-29 18:14:57 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll 2010-07-29 18:14:57 ----A---- C:\Windows\system32\winrscmd.dll 2010-07-29 18:14:56 ----A---- C:\Windows\system32\WsmSvc.dll 2010-07-29 18:14:56 ----A---- C:\Windows\system32\WSManHTTPConfig.exe 2010-07-26 21:51:48 ----D---- C:\Program Files\Mass Effect 2010-07-26 18:07:03 ----D---- C:\ProgramData\EA Core 2010-07-26 18:06:15 ----D---- C:\ProgramData\Electronic Arts 2010-07-25 23:48:07 ----D---- C:\ProgramData\RegCure 2010-07-25 23:48:06 ----D---- C:\Program Files\RegCure 2010-07-25 22:12:42 ----D---- C:\ProgramData\NVIDIA Corporation 2010-07-25 22:07:41 ----A---- C:\Windows\system32\OpenCL.dll 2010-07-25 22:07:41 ----A---- C:\Windows\system32\nvwgf2um.dll 2010-07-25 22:07:41 ----A---- C:\Windows\system32\nvoglv32.dll 2010-07-25 22:07:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys 2010-07-25 22:07:39 ----A---- C:\Windows\system32\nvcuvid.dll 2010-07-25 22:07:39 ----A---- C:\Windows\system32\nvcuvenc.dll 2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcuda.dll 2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcompiler.dll 2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcod1922.dll 2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcod.dll 2010-07-25 14:31:57 ----D---- C:\ProgramData\Media Center Programs 2010-07-24 22:04:48 ----D---- C:\Users\Ims\AppData\Roaming\NVIDIA 2010-07-24 21:37:10 ----D---- C:\Program Files\Common Files\BioWare 2010-07-24 00:41:51 ----D---- C:\Program Files\c&c ======List of files/folders modified in the last 1 months====== 2010-08-16 21:45:57 ----D---- C:\Windows\Temp 2010-08-16 21:43:26 ----D---- C:\Windows\Prefetch 2010-08-16 21:37:52 ----D---- C:\Windows\system32\Tasks 2010-08-16 21:37:13 ----D---- C:\Program Files 2010-08-16 21:30:13 ----D---- C:\Windows\inf 2010-08-16 21:28:33 ----D---- C:\Windows\tracing 2010-08-16 21:06:35 ----D---- C:\Windows\Tasks 2010-08-16 21:04:22 ----D---- C:\ProgramData\NVIDIA 2010-08-16 21:03:16 ----D---- C:\Windows\RegisteredPackages 2010-08-16 21:03:15 ----D---- C:\Windows\system32\drivers 2010-08-16 21:01:29 ----D---- C:\Users\Ims\AppData\Roaming\Piqaip 2010-08-16 21:01:29 ----D---- C:\Users\Ims\AppData\Roaming\Loumu 2010-08-16 20:52:23 ----D---- C:\Users\Ims\AppData\Roaming\Uctifo 2010-08-16 20:48:17 ----D---- C:\ProgramData 2010-08-16 20:41:29 ----D---- C:\Windows\Debug 2010-08-16 20:41:29 ----D---- C:\Windows 2010-08-16 20:31:07 ----D---- C:\Users\Ims\AppData\Roaming\Okag 2010-08-16 17:51:24 ----D---- C:\ProgramData\Google Updater 2010-08-16 17:35:10 ----SHD---- C:\System Volume Information 2010-08-13 15:00:09 ----D---- C:\Windows\system32\catroot2 2010-08-12 00:15:07 ----A---- C:\Windows\system32\PnkBstrB.exe 2010-08-12 00:11:54 ----D---- C:\Program Files\TeamSpeak 3 Client 2010-08-11 14:46:33 ----D---- C:\Windows\Microsoft.NET 2010-08-11 14:46:12 ----RSD---- C:\Windows\assembly 2010-08-11 14:30:31 ----D---- C:\Windows\winsxs 2010-08-11 03:07:52 ----D---- C:\Windows\system32\migration 2010-08-11 03:07:52 ----D---- C:\Windows\System32 2010-08-11 03:07:52 ----D---- C:\Program Files\Movie Maker 2010-08-11 03:07:52 ----D---- C:\Program Files\Internet Explorer 2010-08-11 03:00:43 ----D---- C:\Windows\system32\catroot 2010-08-11 03:00:38 ----D---- C:\Program Files\Windows Mail 2010-08-09 19:12:10 ----D---- C:\Program Files\Common Files\DivX Shared 2010-08-09 01:46:16 ----D---- C:\Program Files\Common Files\Real 2010-08-09 01:46:15 ----A---- C:\Windows\system32\rmoc3260.dll 2010-08-09 01:45:49 ----A---- C:\Windows\system32\pndx5032.dll 2010-08-09 01:45:49 ----A---- C:\Windows\system32\pndx5016.dll 2010-08-09 01:45:46 ----SHD---- C:\Windows\Installer 2010-08-09 01:45:46 ----D---- C:\Program Files\Real 2010-08-09 01:45:39 ----D---- C:\Program Files\Common Files 2010-08-09 01:45:13 ----A---- C:\Windows\system32\pncrt.dll 2010-08-08 22:16:20 ----A---- C:\Windows\system32\PerfStringBackup.INI 2010-08-07 00:13:16 ----D---- C:\Users\Ims\AppData\Roaming\ICQ 2010-08-03 20:09:31 ----A---- C:\Windows\system32\mrt.exe 2010-07-30 16:17:46 ----D---- C:\ProgramData\Xfire 2010-07-29 21:45:17 ----D---- C:\Windows\rescache 2010-07-29 18:16:21 ----D---- C:\Windows\system32\de-DE 2010-07-29 18:16:21 ----D---- C:\Windows\PolicyDefinitions 2010-07-26 18:05:58 ----D---- C:\Program Files\Electronic Arts 2010-07-26 17:50:17 ----D---- C:\Windows\system32\config 2010-07-26 17:35:31 ----HD---- C:\Program Files\InstallShield Installation Information 2010-07-26 17:35:30 ----D---- C:\Users\Ims\AppData\Roaming\Samsung 2010-07-25 22:12:59 ----D---- C:\Program Files\NVIDIA Corporation 2010-07-25 21:58:37 ----A---- C:\Windows\system32\CmdLineExt.dll 2010-07-25 14:36:22 ----D---- C:\Users\Ims\AppData\Roaming\Xfire 2010-07-25 12:47:01 ----D---- C:\Program Files\Steam 2010-07-25 11:54:36 ----D---- C:\Program Files\Adobe 2010-07-25 11:54:34 ----D---- C:\Program Files\Common Files\Adobe AIR 2010-07-25 11:30:23 ----D---- C:\Program Files\Mozilla Firefox 2010-07-25 02:31:29 ----D---- C:\ProgramData\DivX 2010-07-25 02:30:42 ----D---- C:\Program Files\DivX 2010-07-24 01:55:21 ----D---- C:\Program Files\Common Files\Steam 2010-07-23 16:15:02 ----D---- C:\Users\Ims\AppData\Roaming\Adobe 2010-07-20 18:29:26 ----A---- C:\Windows\disney.ini ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248] R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\Windows\System32\drivers\sfdrv01.sys [2006-07-05 59256] R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2006-06-14 13680] R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\Windows\System32\drivers\sfsync04.sys [2006-08-11 59776] R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248] R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-10-18 717296] R1 a2injectiondriver;a2injectiondriver; \??\C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [2010-05-15 39576] R1 a2util;a-squared Malware-IDS utility driver; \??\C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776] R1 BIOS;BIOS; \??\C:\Windows\system32\drivers\BIOS.sys [2005-03-16 13696] R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520] R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2008-09-30 5632] R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-01 281760] R2 cpuz132;cpuz132; \??\C:\Windows\system32\drivers\cpuz132_x32.sys [2009-03-27 12672] R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-01 25888] R2 SVKP;SVKP; \??\C:\Windows\system32\SVKP.sys [2008-06-23 2368] R3 Alpham1;Ideazon Merc USB Human Interface Device; C:\Windows\system32\DRIVERS\Alpham1.sys [2007-07-23 42624] R3 Alpham2;Ideazon Merc MM USB Human Interface Device; C:\Windows\system32\DRIVERS\Alpham2.sys [2007-03-20 18432] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-10-02 1967576] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-07-10 11008040] R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-09-17 98816] S1 ATITool;ATITool Overclocking Utility; C:\Windows\system32\DRIVERS\ATITool.sys [2007-08-08 28968] S3 a2acc;a2acc; \??\C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [2010-06-28 71008] S3 Alpham;Ideazon Merc Composite Keyboard Driver; C:\Windows\system32\DRIVERS\Alpham.sys [2006-03-12 37248] S3 asot5hqv;asot5hqv; C:\Windows\system32\drivers\asot5hqv.sys [] S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632] S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [] S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2007-08-20 27672] S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2007-10-05 17480] S3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520] S3 imhidusb;Immersion's HID USB Driver; C:\Windows\system32\DRIVERS\imhidusb.sys [2007-04-19 17920] S3 motmodem;Motorola USB CDC ACM Driver; C:\Windows\system32\DRIVERS\motmodem.sys [2007-06-18 23680] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192] S3 MSPCLOCK;Microsoft Proxy für Streaming Clock; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888] S3 MSPQM;Microsoft Proxy für Streaming Quality Manager; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016] S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\sscdbus.sys [2007-07-03 80552] S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\Windows\system32\DRIVERS\sscdmdfl.sys [2007-07-03 11944] S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\Windows\system32\DRIVERS\sscdmdm.sys [2007-07-03 106792] S3 usbscan;USB-Scannertreiber; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328] S3 XDva020;XDva020; \??\C:\Windows\system32\XDva020.sys [] S3 XDva342;XDva342; \??\C:\Windows\system32\XDva342.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2010-07-28 1935656] R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640] R2 O&O Defrag;O&O Defrag; C:\Windows\system32\oodag.exe [2008-11-03 1332480] R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-01-15 75064] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936] R2 SuperRam;SuperRam Speicher Service; C:\Program Files\PGWARE\SuperRam\SuperRamService.exe [2009-04-01 977600] R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-08 135664] S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-21 183280] S3 aspnet_state;ASP.NET-Zustandsdienst; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048] S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2009-06-07 2837852] S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-07-24 407336] S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2009-06-02 361728] S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240] S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] -----------------EOF----------------- Emsisoft Anti-Malware - Version 5.0 Letztes Update: 09.08.2010 15:54:19 Scan Einstellungen: Scan Methode: N/A Objekte: Speicher, Traces, Cookies, C:\ Archiv Scan: Aus Heuristik: Aus ADS Scan: An Scan Beginn: 09.08.2010 15:59:53 Key: HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\RegCure gefunden: Trace.Registry.RegCure!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino\SDL gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\init gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\SDL gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pokerinstaller gefunden: Trace.Registry.PacificPoker!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems gefunden: Trace.Registry.Trymedia!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software gefunden: Trace.Registry.Trymedia!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211} gefunden: Trace.Registry.BijbelBar!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211}\iexplore gefunden: Trace.Registry.BijbelBar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> fullpath gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> INSTALLER_GUID gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> URL_CASINO_2 gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> COOKIE_ID gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_PASSWORD gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_USERNAME gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P1 gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> serial gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> test_data gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\Movies --> LobbyMovAct gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upd_Flag gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upg_Date gefunden: Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AlertMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoComplete gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoSearch gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> autoUpdateMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoWild gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> closeAllWindowsForUpdate gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> connectionError gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextMenuItemName gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextSearch gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> corruptedMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> DescriptiveText gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ErrorMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstTime gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstURL gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> KeepHistory gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> lastVersionMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> OpenNew gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> PopStop gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchAutomatically gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchDragAutomatically gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> serverpath gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowFindButtons gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowHighlightButton gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> TBShow gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_id gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_version gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> uninstallMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> UpdateAutomatically gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateMsg gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateUrl gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUninstall gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUpdate gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> versionError gefunden: Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Elapse gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Not_Response gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_TimeOut gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> serial gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> test_data gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Version gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upd_Flag gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upg_Date gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> fullpath gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> INSTALLER_GUID gefunden: Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> URL_CASINO_2 gefunden: Trace.Registry.Pacific Poker!A2 C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@doubleclick[1].txt gefunden: Trace.TrackingCookie.doubleclick!A2 C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@tradedoubler[2].txt gefunden: Trace.TrackingCookie.tradedoubler!A2 C:\Program Files\Common Files\DivX Shared\libdivx.dll gefunden: Backdoor.Win32.IRCNite.po!A2 C:\Program Files\DivX\DivX Converter\libdivx.dll gefunden: Backdoor.Win32.IRCNite.po!A2 C:\Users\Ims\AppData\Roaming\Adobe\Update\flacor.dat gefunden: Trojan-PWS.Win32.Yaludle!IK Gescannt Dateien: 226380 Traces: 619200 Cookies: 41 Prozesse: 53 Gefunden Dateien: 3 Traces: 70 Cookies: 2 Prozesse: 0 Registry Keys: 0 Scan Ende: 09.08.2010 18:28:56 Scan Zeit: 2:29:03 C:\Users\Ims\AppData\Roaming\Adobe\Update\flacor.dat Quarantäne Trojan-PWS.Win32.Yaludle!IK C:\Program Files\Common Files\DivX Shared\libdivx.dll Quarantäne Backdoor.Win32.IRCNite.po!A2 C:\Program Files\DivX\DivX Converter\libdivx.dll Quarantäne Backdoor.Win32.IRCNite.po!A2 C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@tradedoubler[2].txt Quarantäne Trace.TrackingCookie.tradedoubler!A2 C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@doubleclick[1].txt Quarantäne Trace.TrackingCookie.doubleclick!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Elapse Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Not_Response Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_TimeOut Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> serial Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> test_data Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Version Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upd_Flag Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upg_Date Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> fullpath Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> INSTALLER_GUID Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> URL_CASINO_2 Quarantäne Trace.Registry.Pacific Poker!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AlertMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoComplete Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoSearch Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> autoUpdateMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoWild Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> closeAllWindowsForUpdate Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> connectionError Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextMenuItemName Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextSearch Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> corruptedMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> DescriptiveText Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ErrorMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstTime Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstURL Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> KeepHistory Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> lastVersionMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> OpenNew Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> PopStop Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchAutomatically Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchDragAutomatically Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> serverpath Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowFindButtons Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowHighlightButton Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> TBShow Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_id Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_version Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> uninstallMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> UpdateAutomatically Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateUrl Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUninstall Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUpdate Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> versionError Quarantäne Trace.Registry.Eqiso Toolbar!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> fullpath Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> INSTALLER_GUID Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> URL_CASINO_2 Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> COOKIE_ID Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_PASSWORD Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_USERNAME Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P1 Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> serial Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> test_data Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\Movies --> LobbyMovAct Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upd_Flag Quarantäne Trace.Registry.CasinoOnNet!A2 Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upg_Date Quarantäne Trace.Registry.CasinoOnNet!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211} Quarantäne Trace.Registry.BijbelBar!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211}\iexplore Quarantäne Trace.Registry.BijbelBar!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Quarantäne Trace.Registry.Trymedia!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Quarantäne Trace.Registry.Trymedia!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino\SDL Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\init Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\SDL Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pokerinstaller Quarantäne Trace.Registry.PacificPoker!A2 Key: HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\RegCure Quarantäne Trace.Registry.RegCure!A2 Quarantäne Dateien: 3 Traces: 70 Cookies: 2 |
Themen zu Banking Trojaner (40 TANs eingeben) los werden |
40 tans, banking trojaner, benutzerprofildienst, bho, converter, cpu-z, device driver, downloader, emsisoft, entfernen, error, firefox, flash player, fontcache, frage, hdaudio.sys, hijack, hijackthis, home, home premium, hotfix.exe, iexplore, install.exe, logfile, media center, mp3, msiexec, msiexec.exe, notepad.exe, pando media booster, plug-in, problem, programdata, programm, registry, security, security update, server, sierra, software, sptd.sys, staropen, start menu, studio, super, svchost.exe, system, tan-liste, timeout, torrent.exe, trace.registry.trymedia, traces, trojaner, trymedia, tunnel, updates, video converter, windows, world at war, wscript.exe |