![]() |
ich habe die Zip Datei nicht geöffnet ich habe die zip nicht geöffnet |
ok den rest abarbeiten. wenn du mit meinen Anweisungen nicht zu rande hommst, hast du keinen bekannten der dir da durch helfen kann und meine Anleitungen bearbeitet. |
Leider nein :-( ich versuche, dass zu machen was Du mir schreibst ich muss mir microsoft security essencials herunterladen |
Microsoft Security Client ist schon instaliert, nichts neues runterladen, davon steht hier nichts. du kannst auch auf start, ausführen ereignissanzeige enter einträge mit: Microsoft Antimalware suchen, doppelklicken, und meldung(en) posten |
ok. und wo finde ich das :-( die Meldung lassen sich nicht hier rein kopieren hab 13 Suchergebnisse gefunden, aber hier kann sie nicht hier reinkopieren :-( |
doch geht, doppelklicke auf das ereigniss dann geht ein neues fenster mit den infos auf dort strg+a, das sollte alles markieren, dann strg+c und hier auf antworten, dort strg+v bzw einfügen, dass mit allen passenen meldungen |
Hallo J3142, markusg hat auf das Thema 'Word Datei verschlüsselt oder kann Sie nicht öffnen' im Forum 'Plagegeister aller Art und deren Bekämpfung' bei Trojaner-Board geantwortet. Dieses Thema ist hier zu finden: http://www.trojaner-board.de/135489-...-new-post.html Dies ist der Beitrag, der gerade geschrieben wurde: *************** gibts noch mehr funde? falls nein schau als nächstes in microsoft security essencials (mse) *************** Es könnte noch weitere Antworten auf das Thema geben, jedoch erhalten Sie keine zusätzlichen Benachrichtigungen, bis Sie das Forum wieder besucht haben. Mit freundlichen Grüßen Trojaner-Board ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sie erhalten diese E-Mail, da Sie das Thema 'Word Datei verschlüsselt oder kann Sie nicht öffnen' abonniert haben. Informationen zur Abbestellung: Um das Thema abzubestellen, klicken Sie bitte auf diesen Link: http://www.trojaner-board.de/subscri...64dc4eb371a437 Um ALLE Themen abzubestellen, klicken Sie bitte auf diesen Link: http://www.trojaner-board.de/subscri...n&folderid=all die Meldung kommt drei Mal html{border:0;margin:0;padding:0;font-family:Segoe ui,Helvetica,Arial,sans-serif;font-size:.75em}body{margin:0;padding:0;text-align:center}div.articlehighlight{width:97%;padding:10px;margin:20px 0;border:0;background-color:#e8e8e8}div.twocolumns{width:100%}div.twocolumns div.column{margin:0;padding:0;width:48%;float:left}div.twocolumns div.column div.articlehighlight{margin:0 0 10px 0}div.twocolumns div.column object{margin:0 0 10px 0}p{color:#333333;margin:0 0 10px 0;padding:0;line-height:1.4em}h1{color:#2c2c2c;font-size:2em;font-weight:normal;margin:0 0 10px 0;padding:0}h2{color:#2c2c2c;font-size:1.5em;font-weight:normal;margin:0 0 5px 0;padding:0}h3{color:#2c2c2c;font-size:1.25em;font-weight:normal;margin:0 0 5px 0;padding:0}h4{color:#2c2c2c;font-size:1em;font-weight:bold;margin:0 0 5px 0;padding:0}ul.bignumbers{list-style-type:none;padding:0;margin:0}ul.bignumbers li.number1{background-image:url('/global/security/PublishingImages/global/1.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number2{background-image:url('/global/security/PublishingImages/global/2.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number3{background-image:url('/global/security/PublishingImages/global/3.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number4{background-image:url('/global/security/PublishingImages/global/4.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number5{background-image:url('/global/security/PublishingImages/global/5.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number6{background-image:url('/global/security/PublishingImages/global/6.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number7{background-image:url('/global/security/PublishingImages/global/7.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number8{background-image:url('/global/security/PublishingImages/global/8.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number9{background-image:url('/global/security/PublishingImages/global/9.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number10{background-image:url('/global/security/PublishingImages/global/10.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number11{background-image:url('/global/security/PublishingImages/global/11.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number12{background-image:url('/global/security/PublishingImages/global/12.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number13{background-image:url('/global/security/PublishingImages/global/13.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number14{background-image:url('/global/security/PublishingImages/global/14.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}ul.bignumbers li.number15{background-image:url('/global/security/PublishingImages/global/15.gif');padding-left:30px;background-repeat:no-repeat;background-position:0 0}p a img{border:none}a:link{text-decoration:none;color:#008dc2}a:visited{text-decoration:none;color:#008dc2}a:hover{text-decoration:none;color:#333333}a:active{text-decoration:none;color:#333333}object{margin:10px 0;border:0;padding:0}#msviLSBWeb{display:none}div#logosearch{margin:0;padding:0;border:0}div#logosearch div#logo{margin:15px 0;float:left;width:auto}div#logosearch div#logo p{color:#fff;font-size:11px;margin:0;padding:0}div#logosearch div#logo p.mstitle{font-size:13px;margin:0px;padding:0px}div#logosearch div#logo p.headertitle{font-size:30px;font-weight:bold;margin-top:0px;padding-top:0px;padding-bottom:8px;line-height:25px}div#logosearch div#logo p.headersubtitle{font-weight:bold}div#logosearch div#sitesearch{margin:20px 9px 0 0;float:right}div#share p{float:left;padding:10px}div#share img{margin:0 5px 0 0}div.caption{padding:5px 0;border-bottom:1px solid black;margin:10px 0}div.caption p{font-size:.9em;font-style:italic}.border_margin{margin:13px -5px 0 15px !important}div#topNav ul#left,div#topNav ul#right{list-style-type:none;padding:0;margin:0}div#topNav ul#right{float:right;margin-right:20px}div#topNav ul#right li{float:left;margin:13px 0 0 10px}div#topNav ul#left li p,div#topNav ul#right li p{margin:0}div#topNav ul#right li img{margin-top:3px}div#topNav ul#left li a:link,div#topNav ul#left li a:visited{color:#0099cc;font-weight:bold;text-decoration:none;font-size:15px}div#topNav ul#right li a:link,div#topNav ul#right li a:visited{color:#009ad4;font-weight:normal;font-size:1.05em;text-decoration:none}div#topNav ul#left li a:hover{color:#898989;font-weight:bold;text-decoration:none}div#topNav ul#right li a:hover{color:#898989;font-weight:normal;text-decoration:none}div#topNav ul#left li a:active{color:#898989;font-weight:bold;text-decoration:none}div#topNav ul#right li a:active{color:#898989;font-weight:normal;text-decoration:none}div#topNav ul#left li p{text-transform:none}div#topNav ul#left li a.on{color:#898989}div#topNav p{font-size:1.05em}.breadcrumb{display:none}div#bodyContentLeft_Nav{ width:180px;height:auto}div.bodyContentLeft_Spacer{height:20px}div#bodyContentLeft_Ads{margin:0 0 0 22px;width:180px}div.border{border-top:double 1px #e0e0e0;border-bottom:double 1px #e0e0e0;height:3px;margin:0 0 20px 0}div.pageBackgroundMiddle{background-image:url('/global/security/PublishingImages/global/white_bg_middle.png');background-repeat:repeat-y;background-position:-6px 0px;margin:0}div.pageBackgroundBottom{background-image:url('/global/security/PublishingImages/global/white_bg_bottom.png');background-repeat:no-repeat;background-position:-6px 0px}.accordionhead{background:transparent url(/global/security/PublishingImages/global/i_want_to.jpg) no-repeat 0 0;width:223px;height:50px}.accordionhead h2{width:223px;height:50px;margin:0;padding:0 0 0 15px;font-size:27px;color:#fff;line-height:40px}#accordion{background:transparent url(/global/security/PublishingImages/global/bottom_bar_left_nav.jpg) no-repeat 0 bottom;width:223px;padding-bottom:26px}#accordion h3{border-left:none;border-right:none;border-bottom:none;border-color:#C1E4C3;margin:0;padding:0;background:#E9F7E6 url(/global/security/PublishingImages/global/plus.gif) no-repeat 10px 13px}#accordion h3.ui-state-active{background:#fff url(/global/security/PublishingImages/global/minus_icon.jpg) no-repeat 10px 17px;border:none}#accordion h3 a:link,#accordion h3 a:active,#accordion h3 a:visited,#accordion h3 a:hover{margin:0;padding:0;font-size:12px;color:#4f533f;padding:10px 20px 10px 25px;font-weight:bold}#accordion div{border:none;width:100%;height:auto;margin:0;padding:0;font-size:9.6pt}#accordion div ul{margin:0;padding:0 0 20px 0;height:auto;list-style-type:none}#accordion div ul li{margin:0;padding:0 20px 5px 40px;background:#fff url(/global/security/PublishingImages/global/square.jpg) no-repeat 30px 7px}#accordion div ul li a:link,#accordion div ul li a:active,#accordion div ul li a:visited,#accordion div ul li a:hover{color:#0099cc;text-decoration:none;margin:0;padding:0}.accordionhead span{width:223px;height:50px;margin:0;padding:0 0 0 15px;font-size:27px;color:#fff;line-height:40px}#accordion{background:transparent url(/global/security/PublishingImages/global/bottom_bar_left_nav.jpg) no-repeat 0 bottom;width:223px;padding-bottom:26px}#accordion p{border-left:none;border-right:none;border-bottom:none;border-color:#C1E4C3;margin:0;padding:0;background:#E9F7E6 url(/global/security/PublishingImages/global/plus.gif) no-repeat 10px 13px}#accordion p.ui-state-active{background:#fff url(/global/security/PublishingImages/global/minus_icon.jpg) no-repeat 10px 17px;border:none}#accordion p a:link,#accordion p a:active,#accordion p a:visited,#accordion p a:hover{margin:0;padding:0;font-size:10pt;color:#4f533f;padding:10px 20px 10px 25px;font-weight:bold}.selectblock{margin-top:15px}.selectblock span{padding-right:20px}.filtersection{width:100%;margin:20px 0 0 0;clear:both}.filtersection h2{font-size:22px;margin-bottom:12px;font-weight:normal;color:#555;clear:both}.filtersection p{margin:0 50px 20px 0;padding:0;width:170px;float:left}.filtersection p span{display:block}.filtersection a{display:block}.filtersection a img{clear:both;width:170px;height:109px;border:none}#related-feedback{margin:0;padding:0;border:0}#related{width:450px;float:left;margin:0;padding:0;border:0}.feedback{margin:0;padding:0;border:0;width:150px;flo at:right}#pageTools{ margin:0;padding:0;font:9px Verdana,Arial,Geneva,sans-serif;color:#00275b;width:75px}#pageTools ul{ list-style:none;margin:1px 0 0;padding:0}#pageTools ul li{ display:line-height:2em;padding-left:1em;margin-right:1em;margin:0 0 10px 0;border:0;background-image:none}#pageTools ul li:first-child{ margin-left:0}#pageTools a.print{ padding:0;margin:0;background:url('hxxp://i3.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/pt-button-print.gif') no-repeat top left;color:#00275b;display:block;width:75px;height:19px;text-indent:-150px;overflow:hidden}#pageTools a.share{ padding:0;margin:0;background:url('hxxp://i3.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/pt-button-share.gif') no-repeat top left;display:block;width:75px;height:19px;text-indent:-150px;overflow:hidden}#pageTools a.email{ padding:0;margin:0;background:url('hxxp://i3.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/pt-button-email.gif') no-repeat top left;color:#00275b;display:block;width:75px;height:19px;text-indent:-150px;overflow:hidden}#pageTools .dynSBM-hide{display:none}#pageTools .dynSBM-show{display:block}ul #share-this-page{ list-style:none;margin:0;padding:0;background:#fff;border:1px solid #929292;width:120px;position:absolute}ul #share-this-page li{ margin:0;padding:5px;border:0;background-color:#fff;width:110px}#share-this-page a.delicious{padding:0.25em 0 0.25em 20px;background:url('hxxp://i2.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/delicious.png') no-repeat 0 0;display:block;margin:0;border:0}#share-this-page a.digg{padding:0.25em 0 0.25em 20px;background:url('hxxp://i.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/digg.png') no-repeat 0 0;display:block;margin:0;border:0}#share-this-page a.facebook{padding:0.25em 0 0.25em 20px;background:url('hxxp://i2.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/facebook.gif') no-repeat 0 0;display:block;margin:0;border:0}#share-this-page a.twitter{padding:0.25em 0 0.25em 20px;background:url('hxxp://i3.microsoft.com/de-de/security/shared/Templates/components/_msSecurity_ShareEmailPrint/images/twitter.png') no-repeat 0 0;display:block;margin:0;border:0}.topstoryheading,.videoHeading{font-size:13px}@media print{#page-tools{ display:none}}div#faq{margin:0;padding:0;font-family:Segoe UI}div#faq a:link,div#faq a:visited,div#faq a:hover,div#faq a:active{text-decoration:none;color:#008dc2}div#faq ul#showLinks{list-style-type:none;padding:0;margin:0;float:right;width:auto;position:relative;top:10px}div#faq ul#showLinks #showAll,div#faq ul#showLinks #hideAll{padding:5px 0 0 0}div#faq ul#showLinks li{float:left;margin:0;padding:0}div#faq ul#showLinks li p{margin:0;padding:0}div#faq ul#showLinks li img{margin:5px 10px 0 10px;padding:0}div#faq ul#showLinks li p a:link,div#faq ul#showLinks li p a:visited,div#faq ul#showLinks li p a:active{text-decoration:none;font-size:12px}div#faq ul#showLinks li p a:hover{text-decoration:underline}div#faq div#faqContainer{clear:both;margin-bottom:30px} div#faq div#faqContainer .question{padding:10px 0;margin:0;height:auto}div#faq div#faqContainer .question a:link,div#faq div#faqContainer .question a:visited,div#faq div#faqContainer .question a:hover,div#faq div#faqContainer .question a:active{text-decoration:none;color:#000000;font-size:13px;line-height:24px;font-weight:bold;padding:0 0 0 25px}div#faq div#faqContainer .answer{font-size:13px;padding:0 0 0 25px;margin:0}div#faq div#faqContainer .minus{background:url(/global/security/PublishingImages/global/minus.png) no-repeat 0 13px}div#faq div#faqContainer .plus{background:url(/global/security/PublishingImages/global/plus.png) no-repeat 0 13px} table{border:0;margin:10px 0}table tr td,table tr th{border:0;border-bottom:1px solid #333}table tbody.noborder tr td,table thead.noborder tr th{border:0}table.alternate tr{background-color:#dadada}table.alternate tr.alternating{background-color:#eee}table.alternate tr th{background-color:#b1e8e5}p.lefthalf{float:left;width:50%}p.righthalf{float:left;width:47%;padding-left:20px}p.righthalf select{margin:10px 0}p.righthalf span{display:block}span#downloadterms{display:none}span#downloadterms span{font-weight:bold;margin:10px 0}span#downloadterms a.acceptlink{display:block;padding:15px 0 0 0}p.presentationimage{padding:15px 0}p.downloadbutton a:link,p.downloadbutton a:visited,p.downloadbutton a:active{background:url(/global/security/PublishingImages/global/btn_dwnload_sprite.png) no-repeat 0px -42px;padding-left:35px;height:42px;display:inline-block;width:auto;color:#fff;font-weight:bold}p.downloadbutton a span{background:url(/global/security/PublishingImages/global/btn_dwnload_sprite.png) no-repeat 100% 0px;height:42px;line-height:42px;padding-right:35px;padding-left:6px;display:inline-block;width:auto}table.pwchecker tr td{border-bottom:none;padding-right:6px}.clear:after{content:".";display:block;height:0;clear:both;visibility:hidden} .clear{display:inline-table}* html .clear{height:1%}.clear{display:block} |
was soll ich damit jetzt anfangen? ich möchte die meldungen von microsoft scanner sehen wie beschrieben, nicht deine Benachichtigungen das ich geantwortet hab |
.homepage_AccordianHeadings > li > h4 { height:35px; } #bodycontent { height:365px; } .copyright_right{float:right;} .bottom_links { /*padding-left: 228px !important;*/ padding-left: 0 !important; text-align:right; width:800px; } .headersubtitle{ color:#000000 !important; display:block !important; } .homepage_Accordian { /*margin-bottom: 15px !important;*/ height:311px !important; margin-top: -6px !important; } .homepage_AccordianContent li h4 { margin: 0px 0px 0px 10px !important; } .homepage_Accordian p { line-height:12px !important; margin:5px 0px 0px !important; } .homepage_AccordianContent { padding-top:2px !important; } .homepage_AccordianHeadings li h4 { height: 30px !important; font-size:12px !important; padding-right:5px !important; } .homepage_AccordianHeadings li { line-height:14px !important; /*background-position: 3px 0px !important;*/ } ._1LinerText{padding-top:6px !important;} .noalternate td{ vertical-align:top; } #topnav #topmenu, #topnav #topmenu #container{width:700px !important;} /*de-de changes begin*/ #imgslider .bjqs-markers li > a { background-image:url(/global/de-de/security/publishingimages/header/bullet.png); } #topmenu .root>a { padding: 0 15px 0 15px; } .copyright .copyright_left .globe { padding-left:6px; } /*de-de changes end*/ #dsin{display:none;} <?xml version="1.0" encoding="UTF-8"?> -<de-de_security> -<HeaderShareLinks> <NewsLetterLink Link="hxxp://technet.microsoft.com/de-de/security/cc307424.aspx" Text="Newsletter"/> <FollowText Text="Follow:"/> <PrintText Text="Drucken" Image="/global/security/PublishingImages/global/print.png"/> </HeaderShareLinks> </de-de_security> |
was soll das sein? |
ich bin einfach zu blöd, bin gerade voll überfordert :-( sorry das Du Deine Zeit für mich opferst. |
du hast doch schon die ergebnisse gefunden hast du gesagt,in der ereignissanzeige, für Microsoft Antimalware da einfach auf jedes, du sagst es waren 13, doppelklicken, mit der maus alles markieren, strg+c drücken, antworten und hier die ergebnisse einfügen, nacheinander. |
<?xml version="1.0"?> -<SMlog> -<ID> <NA>A Note.lnk</NA> <ST>1</ST> <PU>A Note</PU> <PA>%PROGRAMFILES%\a note\a note.exe</PA> <SL>3</SL> <SP>C:\Users\Herrmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup</SP> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>c76bb600153e9a62493c0e3077a6b04c</MD5> </ID> -<ID> <NA>ApnUpdater</NA> <ST>1</ST> <PU>Ask</PU> <PA>%PROGRAMFILES%\ask.com\updater\updater.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>1acba585d47fb69c12f26074517efe5a</MD5> </ID> -<ID> <NA>AppleSyncNotifier</NA> <ST>1</ST> <PU>Apple Inc.</PU> <PA>%PROGRAMFILES%\common files\apple\mobile device support\applesyncnotifier.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>3417e5691ac9e5b6c3176d2b66dae82d</MD5> </ID> -<ID> <NA>APSDaemon</NA> <ST>1</ST> <PU>Apple Inc.</PU> <PA>%PROGRAMFILES%\common files\apple\apple application support\apsdaemon.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>46da8e7484ac7a52ce1d6e428398724b</MD5> </ID> -<ID> <NA>DAEMON Tools Lite</NA> <ST>1</ST> <PU>DT Soft Ltd</PU> <PA>%PROGRAMFILES%\daemon tools lite\dtlite.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>f34e7705751bb413283434697bf8e55d</MD5> </ID> -<ID> <NA>DriverScanner</NA> <ST>1</ST> <PU>Uniblue Systems Limited</PU> <PA>%PROGRAMFILES%\uniblue\driverscanner\launcher.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>98d7c3f58884d89d1f16f4f77bcd00ee</MD5> </ID> -<ID> <NA>DriverScanner</NA> <ST>1</ST> <PU>Uniblue Systems Limited</PU> <PA>%PROGRAMFILES%\uniblue\driverscanner\dsmonitor.exe</PA> <SL>2</SL> <SP/> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>0b14724f4869639b92cef25f2cf72448</MD5> </ID> -<ID> <NA>EzPrint</NA> <ST>1</ST> <PU>Lexmark International Inc.</PU> <PA>%PROGRAMFILES%\lexmark 5200 series\ezprint.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>5f9f9dcc28733f6601a9f49fb44351d5</MD5> </ID> -<ID> <NA>FineReader7NewsReaderPro</NA> <ST>1</ST> <PU>ABBYY (BIT Software)</PU> <PA>%PROGRAMFILES%\abbyy finereader 7.0 professional edition\abbyynewsreader.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>87b07e85119d7679667026980364354d</MD5> </ID> -<ID> <NA>Google Update</NA> <ST>1</ST> <PU>Google Inc.</PU> <PA>%USERPROFILE%\appdata\local\google\update\googleupdate.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>f02a533f517eb38333cb12a9e8963773</MD5> </ID> -<ID> <NA>GoogleUpdateTaskMachineCore</NA> <ST>1</ST> <PU>Google Inc.</PU> <PA>%PROGRAMFILES%\google\update\googleupdate.exe</PA> <SL>2</SL> <SP/> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>f02a533f517eb38333cb12a9e8963773</MD5> </ID> -<ID> <NA>ISDNWatch.lnk</NA> <ST>1</ST> <PU>AVM Berlin</PU> <PA>%PROGRAMFILES%\fritz!\iwatch.exe</PA> <SL>3</SL> <SP>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup</SP> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>415e58504ad193cf7847cde3faf0cdfa</MD5> </ID> -<ID> <NA>iTunesHelper</NA> <ST>1</ST> <PU>Apple Inc.</PU> <PA>%PROGRAMFILES%\itunes\ituneshelper.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>8e2a7f1f62467a7dcb8ab2c0642f47ca</MD5> </ID> -<ID> <NA>LXBTCATS</NA> <ST>1</ST> <PU/> <PA>rundll32 %WINDIR%\system32\spool\drivers\w32x86\3\lxbttime.dll,_rundllentry@16</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>1</IE> <IS>0</IS> <IN/> <MD5/> </ID> -<ID> <NA>lxbtmon.exe</NA> <ST>1</ST> <PU>Lexmark International, Inc.</PU> <PA>%PROGRAMFILES%\lexmark 5200 series\lxbtmon.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>dff894775fd74510ff572e44f023a191</MD5> </ID> -<ID> <NA>McAfee Security Scan Plus.lnk</NA> <ST>1</ST> <PU>McAfee, Inc.</PU> <PA>%PROGRAMFILES%\mcafee security scan\3.0.318\ssscheduler.exe</PA> <SL>3</SL> <SP>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup</SP> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>bd713579a87d698e1f2158ce10e48130</MD5> </ID> -<ID> <NA>MedionVFD</NA> <ST>1</ST> <PU>Dritek System Inc.</PU> <PA>%PROGRAMFILES%\medion info display\mdionlcmlh.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>cf05ae23b1fbaf3e01d9f42002f8fc9b</MD5> </ID> -<ID> <NA>MobileDocuments</NA> <ST>1</ST> <PU/> <PA>%PROGRAMFILES%\common files\apple\internet services\ubd.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>1</IE> <IS>0</IS> <IN/> <MD5/> </ID> -<ID> <NA>MSC</NA> <ST>1</ST> <PU>Microsoft Corporation</PU> <PA>%PROGRAMFILES%\microsoft security client\msseces.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>7e1b0c85b7347d9391fe60f6dadfddf0</MD5> </ID> -<ID> <NA>msnmsgr</NA> <ST>1</ST> <PU>Microsoft Corporation</PU> <PA>%PROGRAMFILES%\windows live\messenger\msnmsgr.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>24b1666fd14cc71c7b0679ac61625b90</MD5> </ID> -<ID> <NA>OpenOffice.org 3.1.lnk</NA> <ST>1</ST> <PU/> <PA>%PROGRAMFILES%\openoffice.org 3\program\quickstart.exe</PA> <SL>3</SL> <SP>C:\Users\Herrmann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup</SP> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>c047c9c6cd8e134afdfdb374e80547e5</MD5> </ID> -<ID> <NA>PC Performer</NA> <ST>1</ST> <PU>PerformerSoft LLC</PU> <PA>%PROGRAMFILES%\pc performer\pcperformer.exe</PA> <SL>2</SL> <SP/> <RP/> <WOW/> <IE>0</IE> <IS>2</IS> <IN/> <MD5>ee3ec3bf27ec6c6fb45e4125255cabe5</MD5> </ID> -<ID> <NA>QuickTime Task</NA> <ST>1</ST> <PU>Apple Inc.</PU> <PA>%PROGRAMFILES%\quicktime\qttask.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>8dda2b606279753601f9415da503ca63</MD5> </ID> -<ID> <NA>RtHDVCpl</NA> <ST>1</ST> <PU/> <PA>rthdvcpl.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>1</IE> <IS>0</IS> <IN/> <MD5/> </ID> -<ID> <NA>Sidebar</NA> <ST>1</ST> <PU>Microsoft Corporation</PU> <PA>%PROGRAMFILES%\windows sidebar\sidebar.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>9e35ff7f943ae0fb89192bfe058b7fd4</MD5> </ID> -<ID> <NA>SunJavaUpdateSched</NA> <ST>1</ST> <PU>Sun Microsystems, Inc.</PU> <PA>%PROGRAMFILES%\common files\java\java update\jusched.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>12916e0642e92561c98b18a2a2d01b14</MD5> </ID> -<ID> <NA>Windows Defender</NA> <ST>1</ST> <PU>Microsoft Corporation</PU> <PA>%PROGRAMFILES%\windows defender\msascui.exe</PA> <SL>1</SL> <SP>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>1</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>0d392ede3b97e0b3131b2f63ef1db94e</MD5> </ID> -<ID> <NA>Yontoo Desktop</NA> <ST>1</ST> <PU>Yontoo LLC</PU> <PA>%APPDATA%\yontoo\yontoodesktop.exe</PA> <SL>1</SL> <SP>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</SP> <RP/> <WOW>0</WOW> <IE>0</IE> <IS>2</IS> <IN/> <MD5>2a6c01bac0f8aa9143d61ae1e28e263a</MD5> </ID> </SMlog> OTL Logfile: Code: OTL logfile created on: 19.05.2013 10:40:19 - Run 2 |
das sind die Funde unter der von mir genannten kategorie? |
<?xml version="1.0" encoding="UTF-8"?> -<SerializableDictionaryOfStringListOfcFoundItems> -<Item> -<Key> <string>trojan-downloader.istbar</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\classes\eurogrand</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211338</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\classes\eurogrand</V2> <V3>url protocol</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211338</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>livedefault</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>livedefaultid</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>dlgl</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>firstconnecthurl</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>funaccount</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>funnickname</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>funusername</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>nickname</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options-fullscreen</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options-volume</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_autologinfun</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_autologinreal</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_bj_warning</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_cardback</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_dealervoices</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_dealervoiceset</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_fastplay</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_fullscreen</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_multiwindow</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_music</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_sounds</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_speed</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_volume</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_vpdouble</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_xl</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>options_xlslots</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>uninstall_lang</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino</V2> <V3>username</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino\lobby_favouritegames</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino\lobby_favouritegames</V2> <V3>roulette_premium</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino\ro_g</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino\ro_g</V2> <V3>donotshow</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>28</C> <TL>1</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\eurogrand casino\ro_g</V2> <V3>history</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>trojan-spy.vb</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>79</C> <TL>2</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\ptech</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211568</ID> </FI> -<FI> <C>79</C> <TL>2</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\ptech</V2> <V3>ptserialnum</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>trojan.agent</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>9</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>FileSignature</FT> <V1>c:\program files\yontoo\yontooieclient.dll</V1> <V2>0</V2> <V3>247065459825303623</V3> <V4>5677a8d244739d5ad46691c7ace29280</V4> <V5>9275257075565914642|CN=Yontoo LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Yontoo LLC, L=Carlsbad, S=California, C=US</V5> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV>c:\program files\yontoo\yontooieclient.dll</DV> <FA>FileSystem</FA> <RBT>None</RBT> <ID>218671</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>adware.casino</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211100</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>livedefault</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>livedefaultid</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>fav_dealer_enable</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>firstconnecthurl</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>funaccount</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>funnickname</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>funusername</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>last_lobby_tmpl</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>lobby-rememberfunpassword</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>lobby_favouritegames_</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>lobby_template_swr52455772</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>lobby_tmpl_</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>lobby_tmpl_swr52455772</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>nickname</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options-fullscreen</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options-volume</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_autologinfun</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_autologinreal</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_bj_warning</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_cardback</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_dealervoices</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_dealervoiceset</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_fastplay</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_fullscreen</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_hideadvisor</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_music</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_music_track</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_sounds</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_speed</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_volume</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_vpdouble</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_xl</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>options_xlslots</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>uninstall_lang</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>username</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino</V2> <V3>usernmae</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\frr_g</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\frr_g</V2> <V3>donotshow</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\frr_g</V2> <V3>history</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\frr_g</V2> <V3>roulette_window_nowarning</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_favouritegames_swf52433852</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_favouritegames_swf52433852</V2> <V3>roulette_french2_premium</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_favouritegames_swr52455772</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_favouritegames_swr52455772</V2> <V3>roulette_french2_premium</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_window_pos</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_window_pos</V2> <V3>0</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_window_pos</V2> <V3>1</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_window_size</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_window_size</V2> <V3>0</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\lobby_window_size</V2> <V3>1</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\ro</V2> <V3/> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_current_user</V1> <V2>software\swiss casino\ro</V2> <V3>tablelimitsshown</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>adware.activshopper</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncher.1\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncher.1</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncher\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncher\curver</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncher</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncherbho.1\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncherbho.1</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncherbho\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncherbho\curver</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>mynewsbarlauncher.ie5barlauncherbho</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\proxystubclsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\proxystubclsid32</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\typelib</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\typelib</V2> <V3>version</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\proxystubclsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\proxystubclsid32</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\typelib</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\typelib</V2> <V3>version</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncher.1\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncher.1</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncher\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncher\curver</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncher</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncherbho.1\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncherbho.1</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncherbho\clsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncherbho\curver</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\mynewsbarlauncher.ie5barlauncherbho</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211248</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>worm-email.generic</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>83</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_local_machine</V1> <V2>software\classes\.cff</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>211519</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>adware.activeshopper</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\proxystubclsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\proxystubclsid32</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\typelib</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}\typelib</V2> <V3>version</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{3d782bb2-f2a5-11d3-bf4c-000000000000}</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\proxystubclsid</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\proxystubclsid32</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\typelib</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}\typelib</V2> <V3>version</V3> <WSS>None</WSS> <PID>false</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>0</ID> </FI> -<FI> <C>1</C> <TL>3</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Registry</FT> <V1>hkey_classes_root</V1> <V2>interface\{db1f5554-582c-4f53-82cc-458d2c04a2f1}</V2> <V3/> <WSS>None</WSS> <PID>true</PID> <CMP>NotPacked</CMP> <DV/> <FA>Registry</FA> <RBT>None</RBT> <ID>212763</ID> </FI> </ArrayOfFI> </Value> </Item> -<Item> -<Key> <string>pup.casino</string> </Key> -<Value> -<ArrayOfFI> -<FI> <C>37</C> <TL>5</TL> <AP>NoActionTaken</AP> <ActionToPerform>None</ActionToPerform> <FT>Md5</FT> <V1>c:\users\herrmann\downloads\setupcasino_bb9eda_de.exe</V1> <V2>16579620143503616204</V2> <V3>0</V3> <V4>cb4f23596c6a4ac64fcade981368e2a8</V4> <V5>5879253557381762925|CN=PLAYTECH LIMITED, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PLAYTECH LIMITED, L=Douglas, S=Isle of Man, C=IM</V5> <WSS>None</WSS> <PID>false</PID> <CMP>Packed</CMP> <DV>c:\users\herrmann\downloads\setupcasino_bb9eda_de.exe</DV> <FA>FileSystem</FA> <RBT>None</RBT> <ID>211144</ID> </FI> </ArrayOfFI> </Value> </Item> </SerializableDictionaryOfStringListOfcFoundItems> OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 19.05.2013 10:40:19 - Run 2 eine geht nicht da geht es ums Registrieren. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:17 Uhr. |
Copyright ©2000-2025, Trojaner-Board