Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Banking Trojaner (40 TANs eingeben) los werden

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 16.08.2010, 21:18   #1
saccara
 
Banking Trojaner (40 TANs eingeben) los werden - Standard

Banking Trojaner (40 TANs eingeben) los werden



Hallo zusammen!
Ich hatte letzte Woche das Problem, dass ich beim online Banking nach dem Login bei der Postbank aufgefordert wurde, 40 TANs einzugeben.

Bei der Postbank Servicehotline sagte man mir, dass ich zum Entfernen des Trojaners das Programm Anti-Malware von Emsisoft benutzen soll.
Das habe ich getan und es wurden auch viele Probleme gefunden (ich finde leider kein Logfile, daher kann ich nicht genau sagen welche).

Man Frage ist nun, wie herausfinden kann, ob ich clean bin?
Ich habe noch nicht versucht mich beim Banking einzuloggen, da ich eine neue PIN und TAN-Liste bekommen habe. Sonst geraten die neuen Daten wieder in die falschen Hände.

Das selbe Problem gab es schon hier im Forum: http://www.trojaner-board.de/88974-t...e-banking.html



info.txtRSIT Logfile:
Code:
ATTFilter
logfile of random's system information tool 1.08 2010-08-16 21:38:09

======Uninstall list======

-->C:\ProgramData\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER
-->MsiExec /X{8A809006-C25A-4A3A-9DAB-94659BCDB107}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10i_Plugin.exe -maintain plugin
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 9.3.3 - Deutsch-->MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A93000000001}
Adobe Shockwave Player-->C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log
Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Ashampoo Burning Studio 6-->"C:\Program Files\Ashampoo\Ashampoo Burning Studio 6\Uninstall\BS6_Uninstall.EXE"
Ashampoo Magical Optimizer-->"C:\Program Files\Ashampoo\Ashampoo Magical Optimizer\Uninstall\1406_Uninstall.exe"
AVS DVD Player version 2.4-->"C:\Program Files\AVS4YOU\AVSDVDPlayer\unins000.exe"
AVS4YOU Software Navigator 1.2-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
Battlefield: Bad Company™ 2-->MsiExec.exe /X{3AC8457C-0385-4BEA-A959-E095F05D6D67}
Call of Duty(R) - World at War(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{2BF0AE92-C3BC-4112-9066-1546342B1FAE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) - World at War(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{CC862A04-B2B0-4A79-ADD2-4B76D6CF4DCD}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0407
Canon iP4300-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300 /L0x0007
Canon Utilities My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
CanoScan Toolbox Ver4.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{143FB15C-0C48-41E3-9C30-F56FB69BF3D7}\Setup.exe" -l0x7 anything
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
Cossacks - Back To War-->C:\Windows\una2setup.exe
Counter-Strike: Source-->"C:\Program Files\Steam\steam.exe" steam://uninstall/240
Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10
CPUID CPU-Z 1.53.1-->"C:\Program Files\CPUID\CPU-Z\unins000.exe"
Desktop Restore-->MsiExec.exe /I{116D1725-3193-49AF-8999-036D385F701E}
DiRT 2-->"C:\Program Files\Steam\steam.exe" steam://uninstall/12840
DivX Converter-->C:\ProgramData\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER
DivX Plus DirectShow Filters-->C:\ProgramData\DivX\DivX7\DivX Plus DirectShow Filters\DivXDSFiltersUninstall.exe /DSFILTERS
DivX-Setup-->C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
DVD Solution-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe"  -uninstall
EA Download Manager UI-->msiexec /qb /x {4E5EE953-0D92-A385-E3A0-FBFCB2DE15AA}
EA Download Manager UI-->MsiExec.exe /I{4E5EE953-0D92-A385-E3A0-FBFCB2DE15AA}
EA Download Manager-->C:\Program Files\Electronic Arts\EADownloadManager\EADMUninstall.exe
Emsisoft Anti-Malware 5.0-->"C:\Program Files\Emsisoft Anti-Malware\unins000.exe"
Enemy Territory - QUAKE Wars(TM) Demo 1.1 Patch-->C:\Program Files\InstallShield Installation Information\{B7B6C0BE-C919-425C-A493-DF9FF11249F5}\setup.exe -runfromtemp -l0x0409
FileZilla Client 3.3.2.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
FlatOut2-->MsiExec.exe /I{7E641E46-81DB-4D1D-906A-48342523051C}
Fraps-->"C:\programme\fraps\uninstall.exe"
Free 3GP Video Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free 3GP Video Converter\unins000.exe"
Free Studio version 4.7-->"C:\Program Files\DVDVideoSoft\Free Studio\unins000.exe"
Free Video to Flash Converter version 4.2-->"C:\Program Files\DVDVideoSoft\Free Video to Flash Converter\unins000.exe"
Free Video to Mp3 Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free Video to Mp3 Converter\unins000.exe"
Free YouTube to Mp3 Converter version 2.5-->"C:\Program Files\DVDVideoSoft\Free YouTube to Mp3 Converter\unins000.exe"
Futuremark SystemInfo-->C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe -runfromtemp -l0x0009 -removeonly
GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins001.exe"
Google Earth-->MsiExec.exe /X{F7B0939E-58DF-11DF-B3A6-005056806466}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Gothic II Gold-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92510C2A-30E3-4F8D-AE8A-93AB7B63EE8F}\setup.exe" -l0x7  -removeonly
Gothic III-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{02B244A2-7F6A-42E8-A36F-8C385D7A1625}\setup.exe" -l0x7  -removeonly
Gothic_Patch-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{302AC480-43D2-11D5-A818-00500435FC18}\Setup.exe"  -uninst 
Gothic-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBF10B37-4ED3-11D5-A818-00500435FC18}\setup.exe" 
Grand Theft Auto IV-->"C:\Program Files\Steam\steam.exe" steam://uninstall/12210
GRID-->"C:\Program Files\InstallShield Installation Information\{5A0B7BA5-4682-4273-81C2-69B17E649103}\setup.exe" -runfromtemp -l0x0007 -removeonly
Half-Life-->C:\Sierra\HALF-L~1\UNWISE.EXE C:\Sierra\HALF-L~1\INSTALL.LOG
Hamachi 1.0.1.5-->C:\Program Files\Hamachi\uninstall.exe
HLSW v1.3.1-->"C:\Program Files\HLSW\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall  /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
ICQ7-->"C:\Program Files\InstallShield Installation Information\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
ijji REACTOR-->"C:\Program Files\InstallShield Installation Information\{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}\setup.exe" -runfromtemp -l0x0009 -removeonly
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
Java(TM) 6 Update 20-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Manhunt-->MsiExec.exe /X{8A62C8DA-2DB7-4D94-B5BA-1D38FC36E830}
Mass Effect-->C:\Program Files\Common Files\BioWare\Uninstall Mass Effect.exe
MediaShow 3.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5A9B7C0-8751-11D8-9D75-000129760D75}\setup.exe"  -uninstall
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - deu\setup.exe
Microsoft .NET Framework 3.5 Language Pack SP1 - deu-->MsiExec.exe /I{052FDD78-A6EA-3187-8386-C82F4CA3A929}
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile DEU Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1031 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile DEU Language Pack-->MsiExec.exe /X{F750C986-5310-3A5A-95F8-4EC71C8AC01C}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{8FB1B528-E260-451E-9B55-E9152F94B80B}
Microsoft Games for Windows - LIVE-->MsiExec.exe /X{F97E3841-CA9D-4964-9D64-26066241D26F}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411-->MsiExec.exe /X{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
Mirror's Edge-->"C:\Program Files\Steam\steam.exe" steam://uninstall/17410
Mozilla Firefox (3.6.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
NVIDIA Display Control Panel-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe DisplayControlPanel
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{8A809006-C25A-4A3A-9DAB-94659BCDB107}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
O&O Defrag Professional-->MsiExec.exe /I{CF49A5C4-E09A-4A22-BE7B-E42C687952BC}
OpenAL-->"C:\Program Files\OpenAL\OpenALwEAX.exe" /U
OpenOffice.org 3.0-->MsiExec.exe /I{7EC19307-7C22-47A8-922B-3FA965291260}
Overlord-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11450
oZone3D.Net FurMark v1.6.5-->"C:\Program Files\oZone3D\Benchmarks\FurMark_v1.6.5\unins000.exe"
Parabellum Beta-->"C:\Program Files\GamersFirst\Parabellum Beta\uninstall.exe"
Parabellum-->"C:\Program Files\Acony Games GmbH\Parabellum\unins000.exe"
PDFCreator Toolbar-->"C:\Windows\PDFCreator_Toolbar_Uninstaller_6538.exe"  _?=C:\Program Files\PDFCreator Toolbar
PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
PhotoNow! 1.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\setup.exe"  -uninstall
Postal 2-->C:\Windows\unvise32.exe C:\Program Files\Postal2\uninstal.log
Power2Go 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe"  -uninstall
PowerBackup 2.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\setup.exe"  -uninstall
PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe"  -uninstall
PunkBuster Services-->C:\Windows\system32\pbsvc_bc2.exe -u
Quake Live Mozilla Plugin-->MsiExec.exe /I{A10D9B03-AABB-47D7-8A30-2FEA97E70BC7}
QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
Rapture3D 2.3.26 Game-->"C:\Program Files\BRS\unins000.exe"
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0007 -removeonly
REALTEK GbE & FE Ethernet PCI NIC Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe" -l0x7  -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x7  -removeonly
RealUpgrade 1.0-->MsiExec.exe /I{F4F4F84E-804F-4E9A-84D7-C34283F0088F}
Risen-->"C:\Program Files\InstallShield Installation Information\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}\setup.exe" -runfromtemp -l0x0007 -removeonly
RPG Maker 2000 -  Super Columbine Massacre RPG!-->C:\Windows\gamedelete.exe "C:\Program Files\ASCII\RPG2000\ColumbineRPG\RPG_RT.ind"
SAMSUNG Mobile Composite Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Serious Sam 2-->C:\Program Files\Serious Sam 2\Bin\Uninstall.exe
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Source SDK Base-->"C:\Program Files\Steam\steam.exe" steam://uninstall/215
SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
SuperRam-->"C:\Program Files\PGWARE\SuperRam\unins000.exe"
TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
Thrustmaster FFB Wheel driver-->C:\Program Files\InstallShield Installation Information\{57F9C8E9-A9B8-4E19-9AC2-F21EC5094B84}\setup.exe -runfromtemp -l0x0007 -removeonly
ToCA Race Driver 3-->"C:\Program Files\Steam\steam.exe" steam://uninstall/11500
Torchlight-->"C:\Program Files\Steam\steam.exe" steam://uninstall/41500
TuneUp Utilities 2008-->MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
UE3Redist-->"C:\Program Files\InstallShield Installation Information\{2FB04107-7BC2-449C-915A-530B29B5E0FE}\setup.exe" -runfromtemp -l0x0409 -removeonly
Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409
Versatel-->C:\WINDOWS\\Versatel_UTIL.exe -UnInstall
Warcraft III-->C:\Windows\War3Unin.exe C:\Windows\War3Unin.dat
Windows Live Anmelde-Assistent-->MsiExec.exe /I{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}
Windows Live installer-->MsiExec.exe /X{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}
Windows Live Writer-->MsiExec.exe /X{B8D42C3A-3CFF-4A8A-A7DA-4F44474D12C5}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
WinZip 14.0-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240BA}
Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe"
Z Engine-->MsiExec.exe /X{2AE2EFF4-A14B-42AB-B364-F04DB651180F}

======Hosts File======

84.38.66.128 datenklo.org 

======Security center information======

AS: Windows-Defender

======System event log======

Computer Name: Ims-PC
Event Code: 7036
Message: Dienst "Unterstützung in der Systemsteuerung unter Lösungen für Probleme" befindet sich jetzt im Status "Ausgeführt".
Record Number: 218969
Source Name: Service Control Manager
Time Written: 20100113112243.000000-000
Event Type: Informationen
User: 

Computer Name: Ims-PC
Event Code: 10029
Message: DCOM hat den Dienst wercplsupport mit den Argumenten "" gestartet, um den Server auszuführen:
{0E9A7BB5-F699-4D66-8A47-B919F5B6A1DB}
Record Number: 218968
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100113112243.000000-000
Event Type: Informationen
User: 

Computer Name: Ims-PC
Event Code: 20003
Message: Der Prozess zum Hinzufügen von Dienst tunnel für Geräteinstanz-ID ROOT\*6TO4MP\0249 wurde mit folgendem Status beendet: 0.
Record Number: 218967
Source Name: Microsoft-Windows-User-PnP
Time Written: 20100113111407.256892-000
Event Type: Informationen
User: NT-AUTORITÄT\SYSTEM

Computer Name: Ims-PC
Event Code: 20003
Message: Der Prozess zum Hinzufügen von Dienst tunnel für Geräteinstanz-ID ROOT\*ISATAP\0075 wurde mit folgendem Status beendet: 0.
Record Number: 218966
Source Name: Microsoft-Windows-User-PnP
Time Written: 20100113111354.620892-000
Event Type: Informationen
User: NT-AUTORITÄT\SYSTEM

Computer Name: Ims-PC
Event Code: 20267
Message: CoID={43C790BC-6AF4-449E-9620-77C0E63B2ABD}: Der Benutzer *****@versatel hat unter Verwendung des Geräts PPPoE2-0 eine Verbindung mit Breitbandverbindung hergestellt.
Record Number: 218965
Source Name: RemoteAccess
Time Written: 20100113111312.000000-000
Event Type: Informationen
User: 

=====Application event log=====

Computer Name: Ims-PC
Event Code: 1531
Message: Der Benutzerprofildienst wurde erfolgreich gestartet.  


Record Number: 29789
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20080929135249.000000-000
Event Type: Informationen
User: NT-AUTORITÄT\SYSTEM

Computer Name: Ims-PC
Event Code: 900
Message: Der Softwarelizenzierungsdienst wird gestartet.

Record Number: 29788
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20080929135249.000000-





Logfile of random's system information tool 1.08 (written by random/random)
Run by Ims at 2010-08-16 21:45:52
Microsoft® Windows Vista™ Home Premium  Service Pack 2
System drive C: has 8 GB (3%) free of 238 GB
Total RAM: 2046 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:46:05, on 16.08.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Ims\Program Files\DNA\btdna.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\Ims\Desktop\RSIT.exe
C:\Program Files\trend micro\Ims.exe
C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.versatel.de/internet-cd/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: (no name) -  - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 84.38.66.128 datenklo.org
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: (no name) - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SuperRam] "C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe" /start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ Malwarebytes Anti-Malware  (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Ims\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [{40600DC1-73CE-5E4C-36A4-7AFB0D1553AB}] C:\Users\Ims\AppData\Roaming\Piqaip\azom.exe
O4 - HKCU\..\Run: [{74EBC31A-57E4-0727-309F-4ED849E6E338}] C:\Users\Ims\AppData\Roaming\Loumu\iwyxx.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Startup: Optimieren - Verknüpfung.lnk = C:\Users\Ims\Desktop\ClearMem\Optimieren.bat
O8 - Extra context menu item: Free YouTube Download - C:\Users\Ims\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Ims\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in &Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{27D809BC-1889-46D8-BFC6-A8702AAA84BE}: NameServer = 62.220.18.38 89.246.64.38
O17 - HKLM\System\CS1\Services\Tcpip\..\{27D809BC-1889-46D8-BFC6-A8702AAA84BE}: NameServer = 62.220.18.38 89.246.64.38
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Emsisoft Anti-Malware 5.0 - Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\Emsisoft Anti-Malware\a2service.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SuperRam Speicher Service (SuperRam) - PGWARE LLC - C:\Program Files\PGWARE\SuperRam\SuperRamService.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 8074 bytes

======Scheduled tasks folder======

C:\Windows\tasks\1-Klick-Wartung.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3908416098-2138756303-2722824237-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3908416098-2138756303-2722824237-1000UA.job
C:\Windows\tasks\RegCure Program Check.job
C:\Windows\tasks\RegCure.job
C:\Windows\tasks\User_Feed_Synchronization-{B805C3A6-58FB-431E-B800-C9B792561349}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-08-09 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Anmelde-Hilfsprogramm - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-21 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-05-15 352256]
{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-01 4702208]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2008-03-18 1848648]
"Zboard"=C:\Program Files\Ideazon\ZEngine\Zboard.exe [2009-06-04 57344]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"SuperRam"=C:\Program Files\PGWARE\SuperRam\SuperRamTray.exe [2009-04-01 988872]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-08-09 202256]
" Malwarebytes Anti-Malware  (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-05-16 213936]
""= []
"Google Update"=C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-05 133104]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"BitTorrent DNA"=C:\Users\Ims\Program Files\DNA\btdna.exe [2010-08-11 323392]
"{40600DC1-73CE-5E4C-36A4-7AFB0D1553AB}"=C:\Users\Ims\AppData\Roaming\Piqaip\azom.exe []
"{74EBC31A-57E4-0727-309F-4ED849E6E338}"=C:\Users\Ims\AppData\Roaming\Loumu\iwyxx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
C:\Users\Ims\Program Files\DNA\btdna.exe [2010-08-11 323392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Ims\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-05 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\Windows\system32\NvCpl.dll [2010-07-09 13939816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe clear []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Windows\system32\oodtray.exe [2008-11-03 2540800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
C:\Program Files\Pando Networks\Media Booster\PMB.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PDFCreator.lnk]
C:\PROGRA~1\PDFCRE~1\PDFCRE~1.EXE [2009-03-07 2641920]

C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Optimieren - Verknüpfung.lnk - C:\Users\Ims\Desktop\ClearMem\Optimieren.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Programme\BitTorrent\bittorrent.exe"="C:\Programme\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Combat Arms\CombatArms.exe"="C:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\Program Files\Combat Arms\Engine.exe"="C:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe"
"C:\Program Files\Combat Arms EU\CombatArms.exe"="C:\Program Files\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\Program Files\Combat Arms EU\Engine.exe"="C:\Program Files\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-08-16 21:37:13 ----D---- C:\rsit
2010-08-16 21:37:13 ----D---- C:\Program Files\trend micro
2010-08-16 20:48:37 ----D---- C:\Users\Ims\AppData\Roaming\Malwarebytes
2010-08-16 20:48:18 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-08-16 20:48:17 ----D---- C:\ProgramData\Malwarebytes
2010-08-16 20:48:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-08-16 20:48:17 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-08-16 20:40:17 ----D---- C:\Program Files\CCleaner
2010-08-10 21:26:30 ----A---- C:\Windows\system32\mshtml.dll
2010-08-10 21:26:30 ----A---- C:\Windows\system32\iertutil.dll
2010-08-10 21:26:29 ----A---- C:\Windows\system32\ieframe.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\wininet.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\urlmon.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\occache.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\mstime.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-10 21:26:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\ieUnatt.exe
2010-08-10 21:26:28 ----A---- C:\Windows\system32\ieui.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\iesysprep.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\iesetup.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\iernonce.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\iepeers.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-10 21:26:28 ----A---- C:\Windows\system32\ie4uinit.exe
2010-08-10 21:26:24 ----A---- C:\Windows\system32\win32k.sys
2010-08-10 21:26:22 ----A---- C:\Windows\system32\iccvid.dll
2010-08-10 21:26:21 ----A---- C:\Windows\system32\schannel.dll
2010-08-10 21:26:19 ----A---- C:\Windows\system32\rtutils.dll
2010-08-10 21:26:11 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-10 21:26:10 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-10 21:26:08 ----A---- C:\Windows\system32\msxml3.dll
2010-08-10 21:26:07 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-10 21:26:07 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-10 21:26:06 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-10 16:41:27 ----D---- C:\Users\Ims\AppData\Roaming\DNA
2010-08-10 16:41:27 ----D---- C:\Program Files\DNA
2010-08-09 15:52:08 ----D---- C:\Program Files\Emsisoft Anti-Malware
2010-08-09 01:45:39 ----D---- C:\Program Files\Common Files\xing shared
2010-08-03 13:27:23 ----A---- C:\Windows\system32\shell32.dll
2010-07-29 18:16:19 ----D---- C:\Windows\system32\WindowsPowerShell
2010-07-29 18:15:26 ----A---- C:\Windows\system32\winrsmgr.dll
2010-07-29 18:15:06 ----A---- C:\Windows\system32\wsmprovhost.exe
2010-07-29 18:15:06 ----A---- C:\Windows\system32\winrshost.exe
2010-07-29 18:15:06 ----A---- C:\Windows\system32\winrs.exe
2010-07-29 18:15:05 ----A---- C:\Windows\system32\wsmplpxy.dll
2010-07-29 18:15:05 ----A---- C:\Windows\system32\winrssrv.dll
2010-07-29 18:15:02 ----A---- C:\Windows\system32\WsmRes.dll
2010-07-29 18:15:02 ----A---- C:\Windows\system32\wevtfwd.dll
2010-07-29 18:15:02 ----A---- C:\Windows\system32\wecutil.exe
2010-07-29 18:15:02 ----A---- C:\Windows\system32\wecsvc.dll
2010-07-29 18:15:02 ----A---- C:\Windows\system32\wecapi.dll
2010-07-29 18:15:01 ----A---- C:\Windows\system32\pwrshplugin.dll
2010-07-29 18:14:58 ----A---- C:\Windows\system32\winrm.vbs
2010-07-29 18:14:57 ----A---- C:\Windows\system32\WsmWmiPl.dll
2010-07-29 18:14:57 ----A---- C:\Windows\system32\WsmAuto.dll
2010-07-29 18:14:57 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2010-07-29 18:14:57 ----A---- C:\Windows\system32\winrscmd.dll
2010-07-29 18:14:56 ----A---- C:\Windows\system32\WsmSvc.dll
2010-07-29 18:14:56 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2010-07-26 21:51:48 ----D---- C:\Program Files\Mass Effect
2010-07-26 18:07:03 ----D---- C:\ProgramData\EA Core
2010-07-26 18:06:15 ----D---- C:\ProgramData\Electronic Arts
2010-07-25 23:48:07 ----D---- C:\ProgramData\RegCure
2010-07-25 23:48:06 ----D---- C:\Program Files\RegCure
2010-07-25 22:12:42 ----D---- C:\ProgramData\NVIDIA Corporation
2010-07-25 22:07:41 ----A---- C:\Windows\system32\OpenCL.dll
2010-07-25 22:07:41 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-07-25 22:07:41 ----A---- C:\Windows\system32\nvoglv32.dll
2010-07-25 22:07:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2010-07-25 22:07:39 ----A---- C:\Windows\system32\nvcuvid.dll
2010-07-25 22:07:39 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcuda.dll
2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcompiler.dll
2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcod1922.dll
2010-07-25 22:07:38 ----A---- C:\Windows\system32\nvcod.dll
2010-07-25 14:31:57 ----D---- C:\ProgramData\Media Center Programs
2010-07-24 22:04:48 ----D---- C:\Users\Ims\AppData\Roaming\NVIDIA
2010-07-24 21:37:10 ----D---- C:\Program Files\Common Files\BioWare
2010-07-24 00:41:51 ----D---- C:\Program Files\c&c

======List of files/folders modified in the last 1 months======

2010-08-16 21:45:57 ----D---- C:\Windows\Temp
2010-08-16 21:43:26 ----D---- C:\Windows\Prefetch
2010-08-16 21:37:52 ----D---- C:\Windows\system32\Tasks
2010-08-16 21:37:13 ----D---- C:\Program Files
2010-08-16 21:30:13 ----D---- C:\Windows\inf
2010-08-16 21:28:33 ----D---- C:\Windows\tracing
2010-08-16 21:06:35 ----D---- C:\Windows\Tasks
2010-08-16 21:04:22 ----D---- C:\ProgramData\NVIDIA
2010-08-16 21:03:16 ----D---- C:\Windows\RegisteredPackages
2010-08-16 21:03:15 ----D---- C:\Windows\system32\drivers
2010-08-16 21:01:29 ----D---- C:\Users\Ims\AppData\Roaming\Piqaip
2010-08-16 21:01:29 ----D---- C:\Users\Ims\AppData\Roaming\Loumu
2010-08-16 20:52:23 ----D---- C:\Users\Ims\AppData\Roaming\Uctifo
2010-08-16 20:48:17 ----D---- C:\ProgramData
2010-08-16 20:41:29 ----D---- C:\Windows\Debug
2010-08-16 20:41:29 ----D---- C:\Windows
2010-08-16 20:31:07 ----D---- C:\Users\Ims\AppData\Roaming\Okag
2010-08-16 17:51:24 ----D---- C:\ProgramData\Google Updater
2010-08-16 17:35:10 ----SHD---- C:\System Volume Information
2010-08-13 15:00:09 ----D---- C:\Windows\system32\catroot2
2010-08-12 00:15:07 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-08-12 00:11:54 ----D---- C:\Program Files\TeamSpeak 3 Client
2010-08-11 14:46:33 ----D---- C:\Windows\Microsoft.NET
2010-08-11 14:46:12 ----RSD---- C:\Windows\assembly
2010-08-11 14:30:31 ----D---- C:\Windows\winsxs
2010-08-11 03:07:52 ----D---- C:\Windows\system32\migration
2010-08-11 03:07:52 ----D---- C:\Windows\System32
2010-08-11 03:07:52 ----D---- C:\Program Files\Movie Maker
2010-08-11 03:07:52 ----D---- C:\Program Files\Internet Explorer
2010-08-11 03:00:43 ----D---- C:\Windows\system32\catroot
2010-08-11 03:00:38 ----D---- C:\Program Files\Windows Mail
2010-08-09 19:12:10 ----D---- C:\Program Files\Common Files\DivX Shared
2010-08-09 01:46:16 ----D---- C:\Program Files\Common Files\Real
2010-08-09 01:46:15 ----A---- C:\Windows\system32\rmoc3260.dll
2010-08-09 01:45:49 ----A---- C:\Windows\system32\pndx5032.dll
2010-08-09 01:45:49 ----A---- C:\Windows\system32\pndx5016.dll
2010-08-09 01:45:46 ----SHD---- C:\Windows\Installer
2010-08-09 01:45:46 ----D---- C:\Program Files\Real
2010-08-09 01:45:39 ----D---- C:\Program Files\Common Files
2010-08-09 01:45:13 ----A---- C:\Windows\system32\pncrt.dll
2010-08-08 22:16:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-07 00:13:16 ----D---- C:\Users\Ims\AppData\Roaming\ICQ
2010-08-03 20:09:31 ----A---- C:\Windows\system32\mrt.exe
2010-07-30 16:17:46 ----D---- C:\ProgramData\Xfire
2010-07-29 21:45:17 ----D---- C:\Windows\rescache
2010-07-29 18:16:21 ----D---- C:\Windows\system32\de-DE
2010-07-29 18:16:21 ----D---- C:\Windows\PolicyDefinitions
2010-07-26 18:05:58 ----D---- C:\Program Files\Electronic Arts
2010-07-26 17:50:17 ----D---- C:\Windows\system32\config
2010-07-26 17:35:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-26 17:35:30 ----D---- C:\Users\Ims\AppData\Roaming\Samsung
2010-07-25 22:12:59 ----D---- C:\Program Files\NVIDIA Corporation
2010-07-25 21:58:37 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-07-25 14:36:22 ----D---- C:\Users\Ims\AppData\Roaming\Xfire
2010-07-25 12:47:01 ----D---- C:\Program Files\Steam
2010-07-25 11:54:36 ----D---- C:\Program Files\Adobe
2010-07-25 11:54:34 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-07-25 11:30:23 ----D---- C:\Program Files\Mozilla Firefox
2010-07-25 02:31:29 ----D---- C:\ProgramData\DivX
2010-07-25 02:30:42 ----D---- C:\Program Files\DivX
2010-07-24 01:55:21 ----D---- C:\Program Files\Common Files\Steam
2010-07-23 16:15:02 ----D---- C:\Users\Ims\AppData\Roaming\Adobe
2010-07-20 18:29:26 ----A---- C:\Windows\disney.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\Windows\System32\drivers\sfdrv01.sys [2006-07-05 59256]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\Windows\System32\drivers\sfsync04.sys [2006-08-11 59776]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-10-18 717296]
R1 a2injectiondriver;a2injectiondriver; \??\C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [2010-05-15 39576]
R1 a2util;a-squared Malware-IDS utility driver; \??\C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776]
R1 BIOS;BIOS; \??\C:\Windows\system32\drivers\BIOS.sys [2005-03-16 13696]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2008-09-30 5632]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-01 281760]
R2 cpuz132;cpuz132; \??\C:\Windows\system32\drivers\cpuz132_x32.sys [2009-03-27 12672]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-01 25888]
R2 SVKP;SVKP; \??\C:\Windows\system32\SVKP.sys [2008-06-23 2368]
R3 Alpham1;Ideazon Merc USB Human Interface Device; C:\Windows\system32\DRIVERS\Alpham1.sys [2007-07-23 42624]
R3 Alpham2;Ideazon Merc MM USB Human Interface Device; C:\Windows\system32\DRIVERS\Alpham2.sys [2007-03-20 18432]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-10-02 1967576]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-07-10 11008040]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-09-17 98816]
S1 ATITool;ATITool Overclocking Utility; C:\Windows\system32\DRIVERS\ATITool.sys [2007-08-08 28968]
S3 a2acc;a2acc; \??\C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [2010-06-28 71008]
S3 Alpham;Ideazon Merc Composite Keyboard Driver; C:\Windows\system32\DRIVERS\Alpham.sys [2006-03-12 37248]
S3 asot5hqv;asot5hqv; C:\Windows\system32\drivers\asot5hqv.sys []
S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2007-08-20 27672]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2007-10-05 17480]
S3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 imhidusb;Immersion's HID USB Driver; C:\Windows\system32\DRIVERS\imhidusb.sys [2007-04-19 17920]
S3 motmodem;Motorola USB CDC ACM Driver; C:\Windows\system32\DRIVERS\motmodem.sys [2007-06-18 23680]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Proxy für Streaming Clock; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Proxy für Streaming Quality Manager; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\sscdbus.sys [2007-07-03 80552]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\Windows\system32\DRIVERS\sscdmdfl.sys [2007-07-03 11944]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\Windows\system32\DRIVERS\sscdmdm.sys [2007-07-03 106792]
S3 usbscan;USB-Scannertreiber; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 XDva020;XDva020; \??\C:\Windows\system32\XDva020.sys []
S3 XDva342;XDva342; \??\C:\Windows\system32\XDva342.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2010-07-28 1935656]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 O&O Defrag;O&O Defrag; C:\Windows\system32\oodag.exe [2008-11-03 1332480]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-01-15 75064]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 SuperRam;SuperRam Speicher Service; C:\Program Files\PGWARE\SuperRam\SuperRamService.exe [2009-04-01 977600]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-08 135664]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-21 183280]
S3 aspnet_state;ASP.NET-Zustandsdienst; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2009-06-07 2837852]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-07-24 407336]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2009-06-02 361728]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------
         
--- --- ---




Emsisoft Anti-Malware - Version 5.0
Letztes Update: 09.08.2010 15:54:19

Scan Einstellungen:

Scan Methode: N/A
Objekte: Speicher, Traces, Cookies, C:\
Archiv Scan: Aus
Heuristik: Aus
ADS Scan: An

Scan Beginn: 09.08.2010 15:59:53

Key: HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\RegCure gefunden: Trace.Registry.RegCure!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino\SDL gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\init gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\SDL gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pokerinstaller gefunden: Trace.Registry.PacificPoker!A2
Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems gefunden: Trace.Registry.Trymedia!A2
Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software gefunden: Trace.Registry.Trymedia!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211} gefunden: Trace.Registry.BijbelBar!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211}\iexplore gefunden: Trace.Registry.BijbelBar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> fullpath gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> INSTALLER_GUID gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> URL_CASINO_2 gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> COOKIE_ID gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_PASSWORD gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_USERNAME gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P1 gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> serial gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> test_data gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\Movies --> LobbyMovAct gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upd_Flag gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upg_Date gefunden: Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AlertMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoComplete gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoSearch gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> autoUpdateMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoWild gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> closeAllWindowsForUpdate gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> connectionError gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextMenuItemName gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextSearch gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> corruptedMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> DescriptiveText gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ErrorMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstTime gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstURL gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> KeepHistory gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> lastVersionMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> OpenNew gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> PopStop gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchAutomatically gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchDragAutomatically gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> serverpath gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowFindButtons gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowHighlightButton gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> TBShow gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_id gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_version gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> uninstallMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> UpdateAutomatically gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateMsg gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateUrl gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUninstall gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUpdate gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> versionError gefunden: Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Elapse gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Not_Response gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_TimeOut gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> serial gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> test_data gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Version gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upd_Flag gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upg_Date gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> fullpath gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> INSTALLER_GUID gefunden: Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> URL_CASINO_2 gefunden: Trace.Registry.Pacific Poker!A2
C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@doubleclick[1].txt gefunden: Trace.TrackingCookie.doubleclick!A2
C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@tradedoubler[2].txt gefunden: Trace.TrackingCookie.tradedoubler!A2
C:\Program Files\Common Files\DivX Shared\libdivx.dll gefunden: Backdoor.Win32.IRCNite.po!A2
C:\Program Files\DivX\DivX Converter\libdivx.dll gefunden: Backdoor.Win32.IRCNite.po!A2
C:\Users\Ims\AppData\Roaming\Adobe\Update\flacor.dat gefunden: Trojan-PWS.Win32.Yaludle!IK

Gescannt

Dateien: 226380
Traces: 619200
Cookies: 41
Prozesse: 53

Gefunden

Dateien: 3
Traces: 70
Cookies: 2
Prozesse: 0
Registry Keys: 0

Scan Ende: 09.08.2010 18:28:56
Scan Zeit: 2:29:03

C:\Users\Ims\AppData\Roaming\Adobe\Update\flacor.dat Quarantäne Trojan-PWS.Win32.Yaludle!IK
C:\Program Files\Common Files\DivX Shared\libdivx.dll Quarantäne Backdoor.Win32.IRCNite.po!A2
C:\Program Files\DivX\DivX Converter\libdivx.dll Quarantäne Backdoor.Win32.IRCNite.po!A2
C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@tradedoubler[2].txt Quarantäne Trace.TrackingCookie.tradedoubler!A2
C:\Users\Ims\AppData\Roaming\Microsoft\Windows\Cookies\ims@doubleclick[1].txt Quarantäne Trace.TrackingCookie.doubleclick!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Elapse Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_Not_Response Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Reconnection_TimeOut Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> serial Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> test_data Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\init --> Version Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upd_Flag Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pacificpoker\poker\SDL --> Upg_Date Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> fullpath Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> INSTALLER_GUID Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\pokerinstaller --> URL_CASINO_2 Quarantäne Trace.Registry.Pacific Poker!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AlertMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoComplete Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoSearch Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> autoUpdateMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> AutoWild Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> closeAllWindowsForUpdate Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> connectionError Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextMenuItemName Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> contextSearch Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> corruptedMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> DescriptiveText Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ErrorMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstTime Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> firstURL Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> KeepHistory Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> lastVersionMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> OpenNew Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> PopStop Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchAutomatically Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> RunSearchDragAutomatically Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> serverpath Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowFindButtons Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> ShowHighlightButton Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> TBShow Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_id Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> toolbar_version Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> uninstallMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> UpdateAutomatically Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateMsg Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> updateUrl Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUninstall Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> urlAfterUpdate Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\XTTB00001\Toolbar --> versionError Quarantäne Trace.Registry.Eqiso Toolbar!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> fullpath Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> INSTALLER_GUID Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\CasinonetInstaller --> URL_CASINO_2 Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> COOKIE_ID Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_PASSWORD Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> DEMO_USERNAME Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> P1 Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> serial Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\init --> test_data Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\Movies --> LobbyMovAct Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upd_Flag Quarantäne Trace.Registry.CasinoOnNet!A2
Value: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\Software\casinoonnet\casino\SDL --> Upg_Date Quarantäne Trace.Registry.CasinoOnNet!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211} Quarantäne Trace.Registry.BijbelBar!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01E69986-A054-4C52-ABE8-EF63DF1C5211}\iexplore Quarantäne Trace.Registry.BijbelBar!A2
Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Quarantäne Trace.Registry.Trymedia!A2
Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Quarantäne Trace.Registry.Trymedia!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\casinopoker\casino\SDL Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\init Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pacificpoker\poker\SDL Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_USERS\S-1-5-21-3908416098-2138756303-2722824237-1000\software\pokerinstaller Quarantäne Trace.Registry.PacificPoker!A2
Key: HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\RegCure Quarantäne Trace.Registry.RegCure!A2

Quarantäne

Dateien: 3
Traces: 70
Cookies: 2

 

Themen zu Banking Trojaner (40 TANs eingeben) los werden
40 tans, banking trojaner, benutzerprofildienst, bho, converter, cpu-z, device driver, downloader, emsisoft, entfernen, error, firefox, flash player, fontcache, frage, hdaudio.sys, hijack, hijackthis, home, home premium, hotfix.exe, iexplore, install.exe, logfile, media center, mp3, msiexec, msiexec.exe, notepad.exe, pando media booster, plug-in, problem, programdata, programm, registry, security, security update, server, sierra, software, sptd.sys, staropen, start menu, studio, super, svchost.exe, system, tan-liste, timeout, torrent.exe, trace.registry.trymedia, traces, trojaner, trymedia, tunnel, updates, video converter, windows, world at war, wscript.exe




Ähnliche Themen: Banking Trojaner (40 TANs eingeben) los werden


  1. Trojaner TR/Bublik.I.11 fordert beim Online-Banking TANs an
    Log-Analyse und Auswertung - 24.05.2013 (23)
  2. 1. Java lädt Viren runter, 2. Online Banking TANs gesperrt
    Log-Analyse und Auswertung - 21.07.2011 (3)
  3. Online Banking Sparkasse- mehrere Tans eingeben
    Plagegeister aller Art und deren Bekämpfung - 17.05.2011 (14)
  4. Sparkasse 20 Tans eingeben
    Log-Analyse und Auswertung - 16.05.2011 (7)
  5. Postbank Online-Banking: Aufforderung zur Eingabe von 40 TANs
    Plagegeister aller Art und deren Bekämpfung - 07.02.2011 (3)
  6. 20 Tans bei Sparkasse eingeben - Trojaner
    Plagegeister aller Art und deren Bekämpfung - 07.02.2011 (7)
  7. Sparkasse Banking - Aufforderung 20 Tans
    Plagegeister aller Art und deren Bekämpfung - 18.01.2011 (14)
  8. 40 TANs Eingabe beim Online Banking
    Plagegeister aller Art und deren Bekämpfung - 10.01.2011 (17)
  9. Trojaner Sparkasse Banking Aufforderung 20 TANs
    Plagegeister aller Art und deren Bekämpfung - 09.01.2011 (13)
  10. Sparkasse Banking - Aufforderung 40 TANs und Antivir meldet TR/Crypt.ZPACK.Gen
    Plagegeister aller Art und deren Bekämpfung - 04.01.2011 (10)
  11. Sparkasse Banking - Aufforderung 20 TANs
    Plagegeister aller Art und deren Bekämpfung - 03.01.2011 (8)
  12. Meine Lösung des Problems 20 Tans eingeben bei der Sparkasse
    Plagegeister aller Art und deren Bekämpfung - 29.12.2010 (1)
  13. 20 Tan eingeben Sparkasse Online Banking
    Plagegeister aller Art und deren Bekämpfung - 23.12.2010 (7)
  14. Banking Trojaner Sparkasse 20 Tans
    Plagegeister aller Art und deren Bekämpfung - 12.12.2010 (17)
  15. Trojaner - Fishing der TANs beim Online Banking der Postbank
    Plagegeister aller Art und deren Bekämpfung - 18.10.2010 (17)
  16. Trojaner: Online Banking Sparkasse - 50 Tans eingeben
    Plagegeister aller Art und deren Bekämpfung - 26.08.2010 (10)
  17. Trojaner möchte 40 Tans zum Sparkassen Online Banking
    Plagegeister aller Art und deren Bekämpfung - 03.08.2010 (16)

Zum Thema Banking Trojaner (40 TANs eingeben) los werden - Hallo zusammen! Ich hatte letzte Woche das Problem, dass ich beim online Banking nach dem Login bei der Postbank aufgefordert wurde, 40 TANs einzugeben. Bei der Postbank Servicehotline sagte man - Banking Trojaner (40 TANs eingeben) los werden...
Archiv
Du betrachtest: Banking Trojaner (40 TANs eingeben) los werden auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.