Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   bka trojaner 1.14 hat mein winxp befallen (https://www.trojaner-board.de/124001-bka-trojaner-1-14-hat-winxp-befallen.html)

klaus196 19.09.2012 08:09

Code:

# AdwCleaner v2.002 - Datei am 09/19/2012 um 08:55:03 erstellt
# Aktualisiert am 16/09/2012 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzer : klaus.jama - NBKLAUSJAMA-1
# Bootmodus : Normal
# Ausgeführt unter : C:\Dokumente und Einstellungen\klaus.jama\Eigene Dateien\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM
Ordner Gelöscht : C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\pdfforge
Ordner Gelöscht : C:\Programme\SweetIM

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\SweetIm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sim-packages
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\Software\Freeze.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107}
Schlüssel Gelöscht : HKLM\SOFTWARE\Software
Schlüssel Gelöscht : HKLM\Software\SweetIm
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SweetIM]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.18702

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10005’ --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10005’ --> hxxp://www.google.com

*************************

AdwCleaner[R1].txt - [5429 octets] - [19/09/2012 08:33:27]
AdwCleaner[S1].txt - [5761 octets] - [19/09/2012 08:55:03]

########## EOF - C:\AdwCleaner[S1].txt - [5821 octets] ##########

Code:

# AdwCleaner v2.002 - Datei am 09/19/2012 um 08:55:03 erstellt
# Aktualisiert am 16/09/2012 von Xplode
# Betriebssystem : Microsoft Windows XP Service Pack 3 (32 bits)
# Benutzer : klaus.jama - NBKLAUSJAMA-1
# Bootmodus : Normal
# Ausgeführt unter : C:\Dokumente und Einstellungen\klaus.jama\Eigene Dateien\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SweetIM
Ordner Gelöscht : C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\pdfforge
Ordner Gelöscht : C:\Programme\SweetIM

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKCU\Software\SweetIm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sim-packages
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\Software\Freeze.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107}
Schlüssel Gelöscht : HKLM\SOFTWARE\Software
Schlüssel Gelöscht : HKLM\Software\SweetIm
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SweetIM]

***** [Internet Browser] *****

-\\ Internet Explorer v8.0.6001.18702

Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10005’ --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10005’ --> hxxp://www.google.com

*************************

AdwCleaner[R1].txt - [5429 octets] - [19/09/2012 08:33:27]
AdwCleaner[S1].txt - [5761 octets] - [19/09/2012 08:55:03]

########## EOF - C:\AdwCleaner[S1].txt - [5821 octets] ##########

Code:

ComboFix 12-09-18.07 - klaus.jama 19.09.2012  9:12.3.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.3574.2790 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\klaus.jama\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\dokumente und einstellungen\klaus.jama\Desktop\CFScript.txt
AV: G Data AntiVirus *Disabled/Updated* {71310606-6F3B-49F2-9A81-8315AA75FBB3}
FW: LANCOM Advanced VPN Client Firewall *Disabled* {33F684F9-95EF-4FC3-9196-012CF0A4D310}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokume~1\KLAUS~1.JAM\LOKALE~1\Temp\6573b3c6-4299-4ce1-bc75-7f3a9cd9d739\CliSecureRT.dll
c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Pwymykcpf
c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Ywccm
c:\dokumente und einstellungen\klaus.jama\Lokale Einstellungen\Temp\6573b3c6-4299-4ce1-bc75-7f3a9cd9d739\CliSecureRT.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-19 bis 2012-09-19  ))))))))))))))))))))))))))))))
.
.
2012-09-16 05:27 . 2012-09-16 05:27        73696        ----a-w-        c:\programme\Mozilla Firefox\breakpadinjector.dll
2012-09-13 05:22 . 2012-09-13 05:22        --------        d-----w-        c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Malwarebytes
2012-09-13 05:21 . 2012-09-13 05:21        --------        d-----w-        c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2012-09-13 05:21 . 2012-09-13 05:22        --------        d-----w-        c:\programme\Malwarebytes' Anti-Malware
2012-09-13 05:21 . 2012-09-07 15:04        22856        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-12 11:11 . 2012-09-13 07:13        --------        d---a-w-        C:\Kaspersky Rescue Disk 10.0
2012-09-04 08:29 . 2012-09-14 13:03        --------        d-----w-        c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\UseNeXT
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-09-03 13:23 . 2012-09-03 13:23        159744        ----a-w-        c:\programme\Internet Explorer\PLUGINS\npqtplugin.dll
2012-09-03 13:22 . 2012-09-03 13:23        --------        d-----w-        c:\programme\QuickTime
2012-09-03 08:30 . 2012-09-03 08:30        --------        d-----w-        c:\dokumente und einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Apple
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-05 06:50 . 2012-04-04 21:25        696520        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-09-05 06:50 . 2011-05-17 10:07        73416        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:59 . 2004-08-16 18:14        78336        ----a-w-        c:\windows\system32\browser.dll
2012-07-04 14:05 . 2009-10-26 16:42        139784        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:25 . 2004-08-16 18:30        1866240        ----a-w-        c:\windows\system32\win32k.sys
2012-07-02 17:39 . 2004-08-16 18:30        916992        ----a-w-        c:\windows\system32\wininet.dll
2012-07-02 17:39 . 2004-08-16 18:18        43520        ----a-w-        c:\windows\system32\licmgr10.dll
2012-07-02 17:39 . 2004-08-16 18:17        1469440        ------w-        c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2004-08-16 18:16        385024        ----a-w-        c:\windows\system32\html.iec
2012-09-16 05:27 . 2011-11-02 15:24        266720        ----a-w-        c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((  SnapShot@2012-09-19_05.42.32  )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-09-19 07:21 . 2012-09-19 07:21        16384              c:\windows\Temp\Perflib_Perfdata_40c.dat
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19        94208        ----a-w-        c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GladinetIconOverlay]
@="{3C3DC57A-7535-48AF-BB9E-C3576A4F34D0}"
[HKEY_CLASSES_ROOT\CLSID\{3C3DC57A-7535-48AF-BB9E-C3576A4F34D0}]
2011-06-22 01:32        194416        ----a-w-        c:\programme\Nuance\Nuance Cloud Connector\GlOverlayIcon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GladinetUploading]
@="{959A18D3-9CC9-41e8-B76F-34ED9A89D4EA}"
[HKEY_CLASSES_ROOT\CLSID\{959A18D3-9CC9-41e8-B76F-34ED9A89D4EA}]
2011-06-22 01:35        194416        ----a-w-        c:\programme\Nuance\Nuance Cloud Connector\GlOverlayIconU.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\programme\RocketDock\RocketDock.exe" [2007-09-02 495616]
"KiesHelper"="c:\programme\Samsung\Kies\KiesHelper.exe" [2012-02-03 943504]
"KiesPDLR"="c:\programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-03-20 21416]
"1und1Dispatcher"="c:\programme\1und1Softwareaktualisierung\SchedDispatcher.exe" [2011-07-13 216432]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-23 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-23 142360]
"SigmatelSysTrayApp"="c:\programme\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Apoint"="c:\programme\DellTPad\Apoint.exe" [2007-07-02 159744]
"IntelZeroConfig"="c:\programme\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
"IntelWireless"="c:\programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]
"NcpBudgetGui"="c:\programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe" [2010-05-21 1026560]
"NcpPopup"="c:\programme\LANCOM\Advanced VPN Client\ncppopup.exe" [2010-05-21 1192016]
"AVK Client"="c:\programme\G Data\AVKClient\AVKCl.exe" [2012-02-28 1800696]
"KASH0PTRCS41496284544875"="c:\programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe" [2011-08-24 409600]
"starter4g"="c:\windows\starter4g.exe" [2010-04-30 160424]
"ArcSoft Connection Service"="c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2012-04-18 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\klaus.jama\Startmenü\Programme\Autostart\
Dropbox.lnk - c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\fjtLUyyxEfjsnd [2012-5-24 27112840]
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\programme\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programme\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Bluetooth Manager.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^HP Digital Imaging Monitor.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^HP Photosmart Premier – Schnellstart.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\HP Photosmart Premier – Schnellstart.lnk
backup=c:\windows\pss\HP Photosmart Premier – Schnellstart.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Nuance Cloud Connector.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Nuance Cloud Connector.lnk
backup=c:\windows\pss\Nuance Cloud Connector.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Windows Search.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^WISO Mein Steuer-Sparbuch heute.lnk]
path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\WISO Mein Steuer-Sparbuch heute.lnk
backup=c:\windows\pss\WISO Mein Steuer-Sparbuch heute.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51        919008        ----a-w-        c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-05-30 18:06        59280        ----a-w-        c:\programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2011-05-10 01:41        49208        ----a-w-        c:\programme\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-06-07 17:33        421776        ----a-w-        c:\programme\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2012-02-03 16:50        3508624        ----a-w-        c:\programme\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nikon Message Center 2]
2010-05-25 18:16        619008        ----a-w-        c:\programme\Nikon\Nikon Message Center 2\NkMC2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nuance OmniPage 18-reminder]
2011-05-16 11:40        333088        ----a-w-        c:\programme\Nuance\OmniPage18\Ereg\Ereg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage Preload]
2011-07-13 00:56        1467240        ----a-w-        c:\programme\Nuance\OmniPage18\omnipage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Gemeinsame Dateien\\ArcSoft\\Connection Service\\Bin\\ACStart.exe"=
"c:\\Programme\\Nuance\\Nuance Cloud Connector\\GladinetClient.exe"=
"c:\\Programme\\G Data\\AVKClient\\AVKCl.exe"=
"c:\\Programme\\LANCOM\\Advanced VPN Client\\NCPMON.exe"=
"c:\\Programme\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Dokumente und Einstellungen\\klaus.jama\\Anwendungsdaten\\Dropbox\\bin\\Dropbox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows-Remoteverwaltung
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"119:TCP"= 119:TCP:news.usenext.de:119
.
R0 GDBehave;GDBehave;c:\windows\system32\drivers\GDBehave.sys [24.10.2011 10:40 40440]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [24.10.2011 09:23 51144]
R1 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [24.10.2011 10:40 79992]
R1 GRD;G Data Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys [18.06.2012 14:29 69272]
R1 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys [24.10.2011 10:40 40568]
R2 AntiVirusKit Client;G DATA AntiVirus Client;c:\programme\G Data\AVKClient\AVKCl.exe [24.10.2011 10:39 1800696]
R2 AVKProxy;G Data AntiVirus Proxy;c:\programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe [24.10.2011 10:39 1501192]
R2 AVKWCtl;G Data Dateisystem Wächter;c:\programme\G Data\AVKClient\AVKWCtl.exe [18.06.2012 14:29 1554696]
R2 DirMngr;DirMngr;c:\programme\GNU\GnuPG\dirmngr.exe [02.03.2011 17:20 224256]
R2 GDTdiInterceptor;GDTdiInterceptor;c:\windows\system32\drivers\GDTdiIcpt.sys [24.10.2011 10:40 52216]
R2 GladFileMonSvc;GladFileMonSvc;c:\programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe [22.06.2011 03:41 29552]
R2 KA0PTRCS41496284544875;Kaseya Agent;c:\programme\Kaseya\0PTRCS41496284544875\AgentMon.exe [24.10.2011 10:57 851968]
R2 MBAMScheduler;MBAMScheduler;c:\programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [13.09.2012 07:21 399432]
R2 MBAMService;MBAMService;c:\programme\Malwarebytes' Anti-Malware\mbamservice.exe [13.09.2012 07:21 676936]
R2 ncpclcfg;NCP Client Configuration Support;c:\programme\LANCOM\Advanced VPN Client\ncpclcfg.exe [24.10.2011 09:37 133712]
R2 ncprwsnt;NCP Client VPN und Dialing Service;c:\programme\LANCOM\Advanced VPN Client\ncprwsnt.exe [24.10.2011 09:37 1118288]
R2 NcpSec;NCP Client PKI Support;c:\programme\LANCOM\Advanced VPN Client\NCPSEC.EXE [24.10.2011 09:37 93184]
R2 NitroDriverReadSpool2;NitroPDFDriverCreatorReadSpool2;c:\programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe [12.04.2012 05:56 175624]
R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe [11.04.2012 23:07 175632]
R2 SolutoService;Soluto PCGenome Core Service;c:\programme\Soluto\SolutoService.exe [18.10.2011 22:02 456736]
R2 WTGService;WTGService;c:\programme\XSManager\WTGService.exe [02.11.2011 18:10 329168]
R2 XS Stick Service;XS Stick Service;c:\windows\service4g.exe [02.11.2011 18:10 145064]
R3 GDScan;G Data Scanner;c:\programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe [24.10.2011 10:39 459784]
R3 KAPFA;KAPFA;c:\windows\system32\drivers\KAPFA.sys [24.10.2011 10:57 17920]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [13.09.2012 07:21 22856]
R3 NcpFiltMP;NcpFiltMP;c:\windows\system32\drivers\ncpvaxp.sys [24.10.2011 09:37 81392]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [04.04.2012 23:25 250568]
S3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\drivers\cmnsusbser.sys [02.11.2011 18:10 103424]
S3 GDBackupSvc;G Data Backup Service;c:\programme\G Data\AVKClient\AVKBackupService.exe [24.10.2011 10:40 1498616]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\programme\Mozilla Maintenance Service\maintenanceservice.exe [31.07.2012 12:45 114144]
S3 NcpFilt;Ncp Filter Service;c:\windows\system32\drivers\ncpvaxp.sys [24.10.2011 09:37 81392]
S3 ncpvaxp;NCP Secure Client Virtual Adapter Driver;c:\windows\system32\drivers\ncpvaxp.sys [24.10.2011 09:37 81392]
S3 osppsvc;Office Software Protection Platform;c:\programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.01.2010 21:37 4640000]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [14.02.2012 09:36 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [14.02.2012 09:36 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [14.02.2012 09:36 136808]
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 06:50]
.
2012-09-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-09-19 c:\windows\Tasks\User_Feed_Synchronization-{0CDD7E22-5E6A-45B2-B31C-8D7446D529A1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
2012-09-19 c:\windows\Tasks\User_Feed_Synchronization-{0FC1045D-8DAD-4D1A-A132-D01B23212E6A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
2012-09-19 c:\windows\Tasks\User_Feed_Synchronization-{A375F577-6969-4115-956F-4E4771D9E2A5}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
2012-09-19 c:\windows\Tasks\User_Feed_Synchronization-{CE0BAAD5-A1CD-49A5-8CAA-0C04D1C52B7F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;127.0.0.1
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Web-Suche - c:\programme\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-09-19 09:24
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(180)
c:\windows\system32\netprovcredman.dll
.
- - - - - - - > 'explorer.exe'(5076)
c:\programme\RocketDock\RocketDock.dll
c:\windows\system32\igfxdo.dll
c:\dokumente und einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\DropboxExt.14.dll
c:\programme\Nuance\Nuance Cloud Connector\GlOverlayIcon.dll
c:\programme\Nuance\Nuance Cloud Connector\GlOverlayIconU.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programme\Nuance\Nuance Cloud Connector\GlCopyHandler.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\programme\Intel\WiFi\bin\S24EvMon.exe
c:\windows\System32\SCardSvr.exe
c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\programme\Intel\WiFi\bin\EvtEng.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe
c:\programme\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\HPZipm12.exe
c:\programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe
c:\programme\Malwarebytes' Anti-Malware\mbamgui.exe
c:\programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe
c:\programme\Intel\WiFi\bin\WLKeeper.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\programme\DellTPad\ApMsgFwd.exe
c:\programme\DellTPad\HidFind.exe
c:\programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\programme\DellTPad\Apntex.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
c:\programme\PC Connectivity Solution\ServiceLayer.exe
c:\programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programme\PC Connectivity Solution\Transports\NclToBTSrv.exe
c:\programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-09-19  09:31:28 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-09-19 07:31
ComboFix2.txt  2012-09-19 06:21
ComboFix3.txt  2012-09-19 05:45
.
Vor Suchlauf: 13 Verzeichnis(se), 21.849.387.008 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 21.829.468.160 Bytes frei
.
- - End Of File - - 6A467194AC200217393171ABB9215C11


schrauber 19.09.2012 09:07

Nice :)

Malwarebytes updaten, Quick Scan machen, Funde löschen lassen, Log posten.



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Poste bitte dann ein frisches OTl logfile. Wie läuft der Rechner?

klaus196 19.09.2012 09:21

hier der erste scan, der rest folgt....

danke!!!!!

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.17.10

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
klaus.jama :: NBKLAUSJAMA-1 [Administrator]

Schutz: Aktiviert

19.09.2012 10:11:21
mbam-log-2012-09-19 (10-11-21).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 263160
Laufzeit: 4 Minute(n), 56 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


schrauber 19.09.2012 10:30

Alles klar :)

klaus196 19.09.2012 10:42

Hallo Schrauber, der scan läuft noch. ist jetzt bei 49%...

gruß
klaus

schrauber 19.09.2012 11:16

der dauert ein wenig :)

klaus196 19.09.2012 13:24

Bin den rest des Tages außer Haus. Der Scan läuft noch. Durch den Anschluss der externen Festplatte dauert es wohl länger. er ist jetz bei 70%. Ich melde mich morgen früh wieder mit den ergebnissen.

Vielen Dank für deine Hilfe!!!!

Gruß
Klaus

schrauber 19.09.2012 13:26

Kein Problem :)

klaus196 19.09.2012 19:44

hier der letzte scan...
otl folgt gleich
Code:

C:\System Volume Information\_restore{AB1DB8D0-179E-4E7E-95D0-CD0CF2EBB07F}\RP1\A0001159.exe        a variant of Win32/Kryptik.ALMO trojan
C:\System Volume Information\_restore{AB1DB8D0-179E-4E7E-95D0-CD0CF2EBB07F}\RP1\A0001172.exe        a variant of Win32/Kryptik.ALMO trojan
C:\System Volume Information\_restore{AB1DB8D0-179E-4E7E-95D0-CD0CF2EBB07F}\RP1\A0001174.exe        Win32/Trustezeb.C trojan
C:\System Volume Information\_restore{AB1DB8D0-179E-4E7E-95D0-CD0CF2EBB07F}\RP1\A0002805.exe        a variant of Win32/Kryptik.ALSJ trojan
C:\System Volume Information\_restore{AB1DB8D0-179E-4E7E-95D0-CD0CF2EBB07F}\RP2\A0002843.exe        a variant of Win32/Kryptik.ALSZ trojan
C:\System Volume Information\_restore{AB1DB8D0-179E-4E7E-95D0-CD0CF2EBB07F}\RP5\A0004035.exe        Win32/Spy.Bebloh.H trojan
E:\Daten\Documents\Download\vcs1200.exe        multiple threats
E:\Daten\Documents\Download\registrybooster.exe        Win32/RegistryBooster application

hier das otl file
Code:

OTL logfile created on: 19.09.2012 20:40:53 - Run 2
OTL by OldTimer - Version 3.2.63.0    Folder = C:\Dokumente und Einstellungen\klaus.jama\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,49 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 74,56% Memory free
5,33 Gb Paging File | 4,57 Gb Available in Paging File | 85,76% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 74,53 Gb Total Space | 20,14 Gb Free Space | 27,02% Space Free | Partition Type: NTFS
Drive E: | 698,46 Gb Total Space | 296,42 Gb Free Space | 42,44% Space Free | Partition Type: FAT32
 
Computer Name: NBKLAUSJAMA-1 | User Name: klaus.jama | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.18 14:51:33 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe
PRC - [2012.09.16 07:27:34 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.05.24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2012.04.12 05:56:08 | 000,175,624 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe
PRC - [2012.04.11 23:07:38 | 000,175,632 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
PRC - [2012.03.20 10:51:57 | 000,021,416 | ---- | M] () -- C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012.02.29 18:29:02 | 000,459,784 | ---- | M] (G Data Software AG) -- C:\Programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe
PRC - [2012.02.29 18:28:58 | 001,501,192 | ---- | M] (G Data Software AG) -- C:\Programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe
PRC - [2012.02.28 04:40:50 | 001,800,696 | ---- | M] (G Data Software AG) -- C:\Programme\G Data\AVKClient\AVKCl.exe
PRC - [2012.02.28 04:02:06 | 001,554,696 | ---- | M] (G Data Software AG) -- C:\Programme\G Data\AVKClient\AVKWCtl.exe
PRC - [2012.01.18 15:02:04 | 000,508,136 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe
PRC - [2012.01.18 15:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2012.01.04 14:32:36 | 000,718,888 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe
PRC - [2012.01.04 14:32:18 | 000,173,096 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2012.01.04 14:32:14 | 000,147,496 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclToBTSrv.exe
PRC - [2011.10.18 22:02:24 | 000,456,736 | ---- | M] (Soluto) -- C:\Programme\Soluto\SolutoService.exe
PRC - [2011.08.24 10:00:42 | 000,409,600 | ---- | M] (Kaseya International Limited) -- C:\Programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe
PRC - [2011.08.24 10:00:04 | 000,851,968 | ---- | M] (Kaseya International Limited) -- C:\Programme\Kaseya\0PTRCS41496284544875\AgentMon.exe
PRC - [2011.06.22 03:41:20 | 000,029,552 | ---- | M] (Gladinet, INC) -- C:\Programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe
PRC - [2011.06.22 03:14:36 | 000,145,264 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe
PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Programme\GNU\GnuPG\dirmngr.exe
PRC - [2010.12.21 01:07:48 | 000,227,712 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010.10.27 20:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010.08.25 12:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010.06.30 10:56:22 | 001,118,288 | ---- | M] (NCP Engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\ncprwsnt.exe
PRC - [2010.05.21 11:44:26 | 000,133,712 | ---- | M] (NCP engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\ncpclcfg.exe
PRC - [2010.05.21 11:39:22 | 001,026,560 | ---- | M] (NCP engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe
PRC - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE
PRC - [2010.04.30 13:24:26 | 000,160,424 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\starter4g.exe
PRC - [2010.04.30 13:24:18 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\service4g.exe
PRC - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
PRC - [2010.03.18 12:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
PRC - [2008.08.20 17:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe
PRC - [2008.08.20 17:28:34 | 000,348,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\WLKEEPER.exe
PRC - [2008.08.20 17:27:36 | 001,368,064 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe
PRC - [2008.08.20 17:18:34 | 000,905,216 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe
PRC - [2008.08.20 17:09:12 | 001,191,936 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe
PRC - [2008.08.20 17:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008.04.14 08:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
PRC - [2007.07.02 14:29:22 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\Apoint.exe
PRC - [2007.06.06 17:44:44 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApntEx.exe
PRC - [2007.05.22 15:18:56 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApMsgFwd.exe
PRC - [2007.05.10 11:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe
PRC - [2007.05.10 11:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2006.09.08 16:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\hidfind.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.09.19 09:26:25 | 000,115,137 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\temp\6573b3c6-4299-4ce1-bc75-7f3a9cd9d739\CliSecureRT.dll
MOD - [2012.09.16 07:27:32 | 002,244,064 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2012.06.14 09:36:33 | 000,677,376 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SolutoCleanup\416942261ca1cef810b97e1ff4b646c4\SolutoCleanup.ni.dll
MOD - [2012.06.14 09:36:30 | 000,766,464 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDataAggregation\1ae6c9da0192c81b6702f234030fdb0a\PCGDataAggregation.ni.dll
MOD - [2012.06.14 09:36:28 | 000,808,960 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGBrowsersProbe\457d07f5efcfcaf3c6a69b8a845eb8bb\PCGBrowsersProbe.ni.dll
MOD - [2012.06.14 09:36:26 | 000,891,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGClientCommunicat#\fb1de359a3660f8ce5acb29d0d1ef7ad\PCGClientCommunication.ni.dll
MOD - [2012.06.14 09:35:56 | 003,686,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGClientCommon\047ad9e06a7f33e5883975e0a0491a99\PCGClientCommon.ni.dll
MOD - [2012.06.14 09:35:48 | 001,260,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCommunication\134247d6cb313b02f7e3dc9912b6861b\PCGCommunication.ni.dll
MOD - [2012.06.14 09:35:38 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
MOD - [2012.06.14 09:35:15 | 002,414,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGFramework\597ce6ba7e6b43910b3489497566491d\PCGFramework.ni.dll
MOD - [2012.06.14 09:21:09 | 013,197,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\54d61af44b1dedee6aea0d1bbc46b13a\System.Windows.Forms.ni.dll
MOD - [2012.06.14 09:12:20 | 017,998,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\5d585d5428ce69abc28238ffa9f4d3a2\PresentationFramework.ni.dll
MOD - [2012.06.14 09:11:56 | 011,451,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\fe068ba4be8f6cb7d6a58bccff05c75e\PresentationCore.ni.dll
MOD - [2012.06.14 09:11:39 | 003,856,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\62f103f9e662d263ec2ecacc49d4525b\WindowsBase.ni.dll
MOD - [2012.06.14 09:11:34 | 001,666,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4a668799513e369a54fdab8b3f74de92\System.Drawing.ni.dll
MOD - [2012.05.30 20:06:48 | 000,087,912 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\zlib1.dll
MOD - [2012.05.30 20:06:30 | 001,242,512 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\libxml2.dll
MOD - [2012.05.13 12:36:26 | 001,218,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\1409dc3832b37f850569c69a795f834b\System.Management.ni.dll
MOD - [2012.05.13 12:33:50 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\082473bbeed448eb13a7f348cf33e98f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.13 12:32:51 | 001,781,760 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\9b6f1bcb2cf4e6ad429cd721b942f30f\System.Xaml.ni.dll
MOD - [2012.05.13 12:30:24 | 000,410,112 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGBootVisualizingC#\e98fa80e84af386b9c8cac5409c5ce5c\PCGBootVisualizingCore.ni.dll
MOD - [2012.05.13 12:30:23 | 000,362,496 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCatalogItemFootp#\77f31da58740fa6bf132aaf7008c74fb\PCGCatalogItemFootprint.ni.dll
MOD - [2012.05.13 12:30:20 | 000,328,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGSAProbe\d94f98bb221e4e55bc87a82055eb3319\PCGSAProbe.ni.dll
MOD - [2012.05.13 12:30:20 | 000,117,248 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCatalogItemCache\c7744b2daff6165f4fb68ef306ae50fc\PCGCatalogItemCache.ni.dll
MOD - [2012.05.13 12:30:19 | 000,047,616 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGEntities\6c5bd792147c582d24809c83053f9823\PCGEntities.ni.dll
MOD - [2012.05.13 12:30:16 | 000,137,216 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGUpgrader\a38513a2d17566a09459486a527f5cbd\PCGUpgrader.ni.dll
MOD - [2012.05.13 12:30:15 | 001,482,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SolutoService\efc6c3aa2eea52533b93724b1dc3a8b8\SolutoService.ni.exe
MOD - [2012.05.13 12:30:00 | 000,202,240 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGWuInfo\95f6f2f79188d4d7c16319829ccc4072\PCGWuInfo.ni.dll
MOD - [2012.05.13 12:29:56 | 002,327,552 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Community.CsharpSql#\fee1c62db73c777cf9b4401574c461ac\Community.CsharpSqlite.ni.dll
MOD - [2012.05.13 12:29:54 | 000,100,864 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\3d79ecc1212228d8074cceb00e268e77\Interop.IWshRuntimeLibrary.ni.dll
MOD - [2012.05.13 12:29:54 | 000,065,024 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGUsersCenter\169e956824c3d1b9c608f4ab0f3e7500\PCGUsersCenter.ni.dll
MOD - [2012.05.13 12:29:48 | 000,063,488 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGConfiguration\526fbf85e96ccdb425022f1cfacf3252\PCGConfiguration.ni.dll
MOD - [2012.05.13 12:29:45 | 003,789,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDatabase\077460da9e9554c6ed4cab08a4fc3db4\PCGDatabase.ni.dll
MOD - [2012.05.13 12:29:42 | 000,045,568 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGAzureEntityFrame#\4ecd770531f97e2c8fb9dcfc13fd61d7\PCGAzureEntityFramework.ni.dll
MOD - [2012.05.13 12:29:41 | 001,038,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGAzureShared\182032e709f493400f410def8d3bd919\PCGAzureShared.ni.dll
MOD - [2012.05.13 12:29:39 | 000,172,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDriverProbe\43298aa25a92112b59d8a97682c83b37\PCGDriverProbe.ni.dll
MOD - [2012.05.13 12:29:37 | 002,845,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGPreCompiled\1b77418a303d83913aa96fe6ee4559d3\PCGPreCompiled.ni.dll
MOD - [2012.05.13 12:29:35 | 000,186,880 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGPrestoSerializer\56885fe9df4ee8bcfaef60d441c52432\PCGPrestoSerializer.ni.dll
MOD - [2012.05.13 12:29:34 | 000,596,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Ionic.Zip.Reduced\8e581a164c74acf7f2e5aab4989edee6\Ionic.Zip.Reduced.ni.dll
MOD - [2012.05.13 12:03:42 | 002,295,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\38d07a5ac34b99d94fd14f42e779f625\System.Core.ni.dll
MOD - [2012.05.13 12:02:26 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012.05.13 12:02:12 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012.05.13 11:57:17 | 000,755,712 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\190e1740c9b998105a47ec31df0b6f11\PresentationFramework.Luna.ni.dll
MOD - [2012.05.13 11:48:37 | 007,052,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\14ba6251d6ec84c9579ed3d3e10b30c1\System.Core.ni.dll
MOD - [2012.05.13 11:48:36 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5ee8bf77e7b3e25cdbff6e1c299574fe\System.Xml.ni.dll
MOD - [2012.05.13 11:48:22 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\6f399163bb35597da7141ccdb7f39d16\System.ni.dll
MOD - [2012.05.13 11:48:09 | 014,412,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2012.03.20 10:51:57 | 000,021,416 | ---- | M] () -- C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2011.08.24 09:59:24 | 000,135,168 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\LogParser.dll
MOD - [2011.08.24 09:59:18 | 000,131,072 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\KEventLog.dll
MOD - [2011.08.24 09:58:24 | 000,131,072 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\KAgentExt.dll
MOD - [2011.08.23 16:32:42 | 000,446,464 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\libkacm.dll
MOD - [2011.06.22 03:14:36 | 000,145,264 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe
MOD - [2011.06.22 03:02:16 | 000,015,216 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSMui.dll
MOD - [2011.06.22 03:02:12 | 000,079,728 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\zlib125.dll
MOD - [2011.06.22 03:02:00 | 000,292,720 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\sqlite3.dll
MOD - [2011.05.28 23:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2011.05.17 11:58:44 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Programme\GNU\GnuPG\dirmngr.exe
MOD - [2011.03.02 17:17:18 | 000,603,136 | ---- | M] () -- C:\Programme\GNU\GnuPG\libgcrypt-11.dll
MOD - [2011.03.02 17:16:20 | 000,208,384 | ---- | M] () -- C:\Programme\GNU\GnuPG\libksba-8.dll
MOD - [2011.03.02 17:16:08 | 000,073,216 | ---- | M] () -- C:\Programme\GNU\GnuPG\libassuan-0.dll
MOD - [2011.03.02 17:13:52 | 000,048,640 | ---- | M] () -- C:\Programme\GNU\GnuPG\libgpg-error-0.dll
MOD - [2011.03.02 17:11:52 | 000,038,400 | ---- | M] () -- C:\Programme\GNU\GnuPG\libw32pth-0.dll
MOD - [2010.06.24 11:03:30 | 001,578,496 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\ncpgacc.dll
MOD - [2010.06.09 12:45:54 | 000,097,792 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPMIF32.DLL
MOD - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE
MOD - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
MOD - [2009.10.21 13:29:20 | 000,139,264 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPDLG.DLL
MOD - [2009.09.23 15:35:06 | 000,129,536 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NcpBudget2008.dll
MOD - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
MOD - [2008.08.20 17:10:50 | 000,200,704 | ---- | M] () -- C:\Programme\Intel\WiFi\bin\iWMSProv.dll
MOD - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
MOD - [2007.09.02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.dll
MOD - [2004.07.20 18:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
MOD - [2002.06.28 11:16:42 | 000,151,552 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPCFG.DLL
 
 
========== Services (SafeList) ==========
 
SRV - [2012.09.16 07:27:33 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.05 08:50:31 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2012.04.12 05:56:08 | 000,175,624 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe -- (NitroDriverReadSpool2)
SRV - [2012.04.11 23:07:38 | 000,175,632 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe -- (NitroReaderDriverReadSpool2)
SRV - [2012.02.29 18:29:02 | 000,459,784 | ---- | M] (G Data Software AG) [On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe -- (GDScan)
SRV - [2012.02.29 18:28:58 | 001,501,192 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe -- (AVKProxy)
SRV - [2012.02.28 04:40:50 | 001,800,696 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\G Data\AVKClient\AVKCl.exe -- (AntiVirusKit Client)
SRV - [2012.02.28 04:02:06 | 001,554,696 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\G Data\AVKClient\AVKWCtl.exe -- (AVKWCtl)
SRV - [2012.02.28 03:59:06 | 001,498,616 | ---- | M] (G Data Software AG) [On_Demand | Stopped] -- C:\Programme\G Data\AVKClient\AVKBackupService.exe -- (GDBackupSvc)
SRV - [2012.01.04 14:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011.10.18 22:02:24 | 000,456,736 | ---- | M] (Soluto) [Auto | Running] -- C:\Programme\Soluto\SolutoService.exe -- (SolutoService)
SRV - [2011.08.24 10:00:04 | 000,851,968 | ---- | M] (Kaseya International Limited) [Auto | Running] -- C:\Programme\Kaseya\0PTRCS41496284544875\AgentMon.exe -- (KA0PTRCS41496284544875)
SRV - [2011.06.22 03:41:20 | 000,029,552 | ---- | M] (Gladinet, INC) [Auto | Running] -- C:\Programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe -- (GladFileMonSvc)
SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Programme\GNU\GnuPG\dirmngr.exe -- (DirMngr)
SRV - [2010.06.30 10:56:22 | 001,118,288 | ---- | M] (NCP Engineering GmbH) [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\ncprwsnt.exe -- (ncprwsnt)
SRV - [2010.05.21 11:44:26 | 000,133,712 | ---- | M] (NCP engineering GmbH) [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\ncpclcfg.exe -- (ncpclcfg)
SRV - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE -- (NcpSec)
SRV - [2010.04.30 13:24:18 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\WINDOWS\service4g.exe -- (XS Stick Service)
SRV - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () [Auto | Running] -- C:\Programme\XSManager\WTGService.exe -- (WTGService)
SRV - [2010.03.18 12:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2008.08.20 17:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2008.08.20 17:28:34 | 000,348,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2008.08.20 17:18:34 | 000,905,216 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor)
SRV - [2008.08.20 17:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2007.05.10 11:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) [Auto | Running] -- C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe -- (STacSV)
SRV - [2006.03.03 22:03:10 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2005.04.04 01:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOKUME~1\KLAUS~1.JAM\LOKALE~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.06.18 14:29:25 | 000,052,216 | ---- | M] (G Data Software AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\GDTdiIcpt.sys -- (GDTdiInterceptor)
DRV - [2012.06.18 14:29:21 | 000,079,992 | ---- | M] (G Data Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MiniIcpt.sys -- (GDMnIcpt)
DRV - [2012.06.18 14:29:21 | 000,040,568 | ---- | M] (G Data Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\HookCentre.sys -- (HookCentre)
DRV - [2012.06.18 14:29:21 | 000,040,440 | ---- | M] (G Data Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\GDBehave.sys -- (GDBehave)
DRV - [2012.06.18 14:29:11 | 000,069,272 | ---- | M] (G Data Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\GRD.sys -- (GRD)
DRV - [2012.05.11 07:53:22 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2011.12.08 06:22:26 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011.12.08 06:22:26 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011.12.08 06:22:26 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011.11.02 18:10:32 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2011.11.01 11:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011.11.01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011.11.01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.11.01 11:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011.10.18 21:50:18 | 000,051,144 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\Soluto.sys -- (Soluto)
DRV - [2011.06.23 11:09:02 | 000,017,920 | ---- | M] (Kaseya) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KAPFA.sys -- (KAPFA)
DRV - [2010.08.04 06:33:28 | 000,061,696 | ---- | M] (ASIX Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ax88772.sys -- (AX88772)
DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (ncpvaxp)
DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (NcpFiltMP)
DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (NcpFilt)
DRV - [2009.09.28 22:57:28 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2008.08.29 00:34:30 | 003,632,384 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.08.04 12:32:26 | 000,011,904 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007.12.23 18:18:48 | 000,068,696 | ---- | M] (O2Micro) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\oz776.sys -- (guardian2)
DRV - [2007.08.02 18:35:12 | 000,989,952 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2007.08.02 18:34:30 | 000,211,200 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2007.08.02 18:34:26 | 000,731,136 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2007.06.25 19:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007.05.10 11:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007.04.23 17:39:00 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2007.04.10 21:29:42 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2007.02.16 16:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.01.16 11:22:00 | 000,031,744 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\csrbcxp.sys -- (CSRBC)
DRV - [2006.11.22 17:09:22 | 000,053,504 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2006.11.20 18:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2006.10.10 20:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2006.10.05 17:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2005.08.01 17:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005.01.06 14:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C4 91 C0 0B E1 05 CD 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{B56635D2-7485-49B6-85F3-9EAB0E0DAF4F}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Programme\Nitro PDF\Professional 7\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_8.0@nokia.com: C:\Programme\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_8.0 [2012.02.14 10:14:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.09.16 07:27:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.09.03 15:23:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_11.0@nokia.com: C:\Programme\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_11.0
 
[2011.11.02 17:24:57 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Extensions
[2012.09.13 07:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\extensions
[2012.04.30 13:52:40 | 000,003,941 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\searchplugins\gXverNTuDgXvssrJsNTu
[2012.07.16 09:12:42 | 000,000,925 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\searchplugins\oGjfLssqUoGjVn
[2012.07.31 12:45:35 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.09.16 07:27:35 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.16 07:27:28 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.09.19 09:23:53 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Programme\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [AVK Client] C:\Programme\G Data\AVKClient\AVKCl.exe (G Data Software AG)
O4 - HKLM..\Run: [IntelWireless] C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [KASH0PTRCS41496284544875] C:\Programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe (Kaseya International Limited)
O4 - HKLM..\Run: [NcpBudgetGui] C:\Programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe (NCP engineering GmbH)
O4 - HKLM..\Run: [NcpPopup] C:\Programme\LANCOM\Advanced VPN Client\ncppopup.exe (NCP engineering GmbH)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [starter4g] C:\WINDOWS\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [1und1Dispatcher] C:\Programme\1und1Softwareaktualisierung\SchedDispatcher.exe (1&1 Mail & Media GmbH)
O4 - HKCU..\Run: [KiesHelper] C:\Programme\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [RocketDock] C:\Programme\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\fjtLUyyxEfjsnd (Dropbox, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Web-Suche - C:\Programme\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256658069250 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ild-group.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4693966C-F27A-4969-BADC-BA0232CFA337}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOKUME~1/KLAUS~1.JAM/LOKALE~1/Temp/msohtmlclip1/01/clip_image001.gif
O24 - Desktop Components:1 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.26 18:47:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.19 10:19:14 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.09.19 10:18:37 | 002,322,184 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\esetsmartinstaller_enu.exe
[2012.09.19 09:25:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.09.19 08:12:18 | 004,752,754 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ComboFix.exe
[2012.09.19 07:35:09 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.09.19 07:27:25 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.09.19 07:27:25 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.09.19 07:27:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.09.19 07:27:25 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.09.19 07:27:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.09.19 07:27:05 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Verwaltung
[2012.09.19 07:26:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012.09.18 16:19:09 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\aswMBR.exe
[2012.09.18 14:51:30 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe
[2012.09.14 15:52:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox
[2012.09.14 15:51:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Eigene Dateien\Neuer Ordner
[2012.09.14 14:45:40 | 000,448,816 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\rannohdecryptor.exe
[2012.09.13 07:22:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Malwarebytes
[2012.09.13 07:22:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.09.13 07:21:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.09.13 07:21:56 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.09.13 07:21:56 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.09.12 13:11:45 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012.09.04 10:29:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\UseNeXT
[2012.09.03 15:22:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\QuickTime
[2012.09.03 15:22:23 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime
[2012.09.03 10:30:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Apple
[2012.08.29 14:39:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\eggebrecht anton safkow
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.19 20:45:00 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0FC1045D-8DAD-4D1A-A132-D01B23212E6A}.job
[2012.09.19 20:44:00 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A375F577-6969-4115-956F-4E4771D9E2A5}.job
[2012.09.19 20:43:02 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{CE0BAAD5-A1CD-49A5-8CAA-0C04D1C52B7F}.job
[2012.09.19 20:43:00 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0CDD7E22-5E6A-45B2-B31C-8D7446D529A1}.job
[2012.09.19 17:56:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.09.19 12:10:12 | 000,799,585 | ---- | M] () -- C:\WINDOWS\System32\sig.bin
[2012.09.19 12:10:12 | 000,044,197 | ---- | M] () -- C:\WINDOWS\System32\nmp.map
[2012.09.19 10:18:45 | 002,322,184 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\esetsmartinstaller_enu.exe
[2012.09.19 09:23:53 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.09.19 09:23:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.09.19 09:21:05 | 000,000,021 | ---- | M] () -- C:\WINDOWS\S.dirmngr
[2012.09.19 09:20:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.09.19 09:20:43 | 3747,573,760 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.19 08:12:09 | 004,752,754 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ComboFix.exe
[2012.09.19 07:35:16 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012.09.18 16:31:55 | 000,000,512 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\MBR.dat
[2012.09.18 14:59:30 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\aswMBR.exe
[2012.09.18 14:51:33 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe
[2012.09.18 14:49:08 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.09.18 09:08:55 | 000,001,479 | ---- | M] () -- C:\WINDOWS\System32\.lck
[2012.09.18 09:08:54 | 000,019,320 | ---- | M] () -- C:\WINDOWS\System32\.rsp
[2012.09.14 15:52:23 | 000,001,031 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox.lnk
[2012.09.13 07:22:00 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.12 11:16:26 | 000,448,816 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\rannohdecryptor.exe
[2012.09.12 07:59:21 | 000,001,074 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.09.05 09:15:47 | 000,027,648 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.05 08:50:30 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.09.05 08:50:29 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.09.05 07:28:20 | 000,093,696 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\lraJseOXQlrTJJsO
[2012.09.05 07:26:53 | 000,550,669 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\DrTvegXQuDNTvegXXQDr
[2012.09.04 12:00:30 | 000,001,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nitro Pro 7.lnk
[2012.09.03 15:22:49 | 000,001,590 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.09.03 10:30:06 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.09.03 08:25:12 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLev.DAT
[2012.09.03 08:24:18 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT
[2012.08.30 16:35:10 | 000,019,418 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntjjVExydLstjVExy
[2012.08.30 16:34:30 | 000,016,896 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydLsAfoxqqdLtAfoGG
[2012.08.30 16:33:46 | 000,052,243 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntAAfExqdLstAVExq
[2012.08.25 20:31:04 | 000,172,477 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ysnVAxxEUqtLVAAGEU
[2012.08.25 20:30:14 | 000,164,793 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\tAfExxydLsjfoExqdLs
[2012.08.25 20:29:11 | 000,010,975 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\XODQTTrsJXgDuQaNs
[2012.08.25 20:26:23 | 000,106,494 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\geuXXNDJageuuXNDJ
[2012.08.25 20:24:24 | 000,188,697 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\toVqxLLUjsofyxxLdj
[2012.08.25 20:22:48 | 000,103,164 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\jxEdysnffAGEUys
[2012.08.25 20:19:10 | 000,119,223 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\oVqGLLUAsEVyxGLdAto
[2012.08.25 20:18:15 | 000,136,189 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\JTOsQXprDvTOsuQX
[2012.08.25 20:17:44 | 000,237,939 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\yUntAAVExydnttjVExq
[2012.08.25 20:15:34 | 000,138,218 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\LVjxodqttLVjGodqqt
[2012.08.25 20:14:23 | 000,003,540 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ndjtooVqxndAssoVyx
[2012.08.25 20:00:32 | 000,001,039 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\AVExxydntAfoEx
[2012.08.24 18:31:40 | 000,174,227 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\VqxndjtoVVqGLd
[2012.08.24 18:24:25 | 000,816,518 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\qxLdjttEVqxndjjtoVq
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.19 07:35:16 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012.09.19 07:35:12 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2012.09.19 07:27:25 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.09.19 07:27:25 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.09.19 07:27:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.09.19 07:27:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.09.19 07:27:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.09.18 16:22:35 | 000,000,512 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\MBR.dat
[2012.09.14 15:52:23 | 000,001,031 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox.lnk
[2012.09.13 07:41:38 | 000,000,021 | ---- | C] () -- C:\WINDOWS\S.dirmngr
[2012.09.13 07:22:00 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.04 12:00:30 | 000,001,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nitro Pro 7.lnk
[2012.09.04 12:00:28 | 000,001,888 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Nitro Pro 7.lnk
[2012.09.04 11:13:29 | 3747,573,760 | -HS- | C] () -- C:\hiberfil.sys
[2012.09.03 15:22:49 | 000,001,590 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.05.13 14:48:27 | 001,005,848 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.04.03 10:36:28 | 000,009,263 | ---- | C] () -- C:\WINDOWS\System32\UpdateAction_30032012.exe.dmp
[2012.03.19 17:14:38 | 000,000,646 | ---- | C] () -- C:\WINDOWS\wiso.ini
[2012.02.27 11:45:00 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.02.15 09:19:54 | 000,559,362 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-2172849378-3237517302-3047019274-1120-0.dat
[2012.02.15 07:51:19 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.02.14 11:24:10 | 000,270,318 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2012.01.31 19:15:44 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe
[2012.01.31 19:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012.01.31 19:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012.01.31 19:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012.01.31 19:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012.01.02 11:45:50 | 000,000,383 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2011.12.13 07:13:27 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2011.11.30 06:29:41 | 000,007,494 | ---- | C] () -- C:\WINDOWS\System32\Upd20111125.exe.dmp
[2011.11.26 22:17:24 | 000,001,205 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini
[2011.11.25 20:24:20 | 000,000,143 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2011.11.25 20:12:08 | 000,000,163 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2011.11.25 20:11:38 | 000,000,690 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2011.11.25 19:56:23 | 000,127,878 | ---- | C] () -- C:\WINDOWS\hpoins11.dat
[2011.11.25 19:54:40 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2011.11.25 19:53:49 | 000,011,634 | ---- | C] () -- C:\WINDOWS\hpomdl11.dat
[2011.11.08 16:12:15 | 000,027,648 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.08 13:11:33 | 000,799,585 | ---- | C] () -- C:\WINDOWS\System32\sig.bin
[2011.11.03 07:58:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLev.DAT
[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT
[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLes.DAT
[2011.10.24 09:25:55 | 000,000,094 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft.SqlServer.Compact.351.32.bc
[1601.02.13 10:28:18 | 001,597,464 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\VAtndqGEEVAtnUq
[1601.02.13 10:28:18 | 000,078,022 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\GEUqsnnfAGodqts
[1601.02.13 10:28:18 | 000,004,211 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\QDrTJJsOpQDrTaJe
[1601.02.13 10:28:18 | 000,003,090 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\GqdLtjjfoxydnttjfo
[1601.02.13 10:28:18 | 000,001,601 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JeNTQDDOXJeNauulg
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\uyUaJlAVnsyUEvJ
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TujOXJxyfosjdpp
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\JTNlluXgevaNNDuXgsvaa
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JDNXuegaavlNXueggavlr
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\gsvTrllupgsJTrrl
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\DuXOeJvaNlupgeeJaNDu
 
========== ZeroAccess Check ==========
 
[2009.10.27 16:09:51 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

< End of report >


klaus196 19.09.2012 20:08

hier das otl file
Code:

OTL logfile created on: 19.09.2012 20:40:53 - Run 2
OTL by OldTimer - Version 3.2.63.0    Folder = C:\Dokumente und Einstellungen\klaus.jama\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,49 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 74,56% Memory free
5,33 Gb Paging File | 4,57 Gb Available in Paging File | 85,76% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 74,53 Gb Total Space | 20,14 Gb Free Space | 27,02% Space Free | Partition Type: NTFS
Drive E: | 698,46 Gb Total Space | 296,42 Gb Free Space | 42,44% Space Free | Partition Type: FAT32
 
Computer Name: NBKLAUSJAMA-1 | User Name: klaus.jama | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.09.18 14:51:33 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe
PRC - [2012.09.16 07:27:34 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.05.24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2012.04.12 05:56:08 | 000,175,624 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe
PRC - [2012.04.11 23:07:38 | 000,175,632 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
PRC - [2012.03.20 10:51:57 | 000,021,416 | ---- | M] () -- C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012.02.29 18:29:02 | 000,459,784 | ---- | M] (G Data Software AG) -- C:\Programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe
PRC - [2012.02.29 18:28:58 | 001,501,192 | ---- | M] (G Data Software AG) -- C:\Programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe
PRC - [2012.02.28 04:40:50 | 001,800,696 | ---- | M] (G Data Software AG) -- C:\Programme\G Data\AVKClient\AVKCl.exe
PRC - [2012.02.28 04:02:06 | 001,554,696 | ---- | M] (G Data Software AG) -- C:\Programme\G Data\AVKClient\AVKWCtl.exe
PRC - [2012.01.18 15:02:04 | 000,508,136 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe
PRC - [2012.01.18 15:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2012.01.04 14:32:36 | 000,718,888 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe
PRC - [2012.01.04 14:32:18 | 000,173,096 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2012.01.04 14:32:14 | 000,147,496 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclToBTSrv.exe
PRC - [2011.10.18 22:02:24 | 000,456,736 | ---- | M] (Soluto) -- C:\Programme\Soluto\SolutoService.exe
PRC - [2011.08.24 10:00:42 | 000,409,600 | ---- | M] (Kaseya International Limited) -- C:\Programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe
PRC - [2011.08.24 10:00:04 | 000,851,968 | ---- | M] (Kaseya International Limited) -- C:\Programme\Kaseya\0PTRCS41496284544875\AgentMon.exe
PRC - [2011.06.22 03:41:20 | 000,029,552 | ---- | M] (Gladinet, INC) -- C:\Programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe
PRC - [2011.06.22 03:14:36 | 000,145,264 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe
PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Programme\GNU\GnuPG\dirmngr.exe
PRC - [2010.12.21 01:07:48 | 000,227,712 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010.10.27 20:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010.08.25 12:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010.06.30 10:56:22 | 001,118,288 | ---- | M] (NCP Engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\ncprwsnt.exe
PRC - [2010.05.21 11:44:26 | 000,133,712 | ---- | M] (NCP engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\ncpclcfg.exe
PRC - [2010.05.21 11:39:22 | 001,026,560 | ---- | M] (NCP engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe
PRC - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE
PRC - [2010.04.30 13:24:26 | 000,160,424 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\starter4g.exe
PRC - [2010.04.30 13:24:18 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\service4g.exe
PRC - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
PRC - [2010.03.18 12:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
PRC - [2008.08.20 17:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe
PRC - [2008.08.20 17:28:34 | 000,348,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\WLKEEPER.exe
PRC - [2008.08.20 17:27:36 | 001,368,064 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe
PRC - [2008.08.20 17:18:34 | 000,905,216 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe
PRC - [2008.08.20 17:09:12 | 001,191,936 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe
PRC - [2008.08.20 17:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008.04.14 08:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
PRC - [2007.07.02 14:29:22 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\Apoint.exe
PRC - [2007.06.06 17:44:44 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApntEx.exe
PRC - [2007.05.22 15:18:56 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApMsgFwd.exe
PRC - [2007.05.10 11:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe
PRC - [2007.05.10 11:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2006.09.08 16:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\hidfind.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.09.19 09:26:25 | 000,115,137 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\temp\6573b3c6-4299-4ce1-bc75-7f3a9cd9d739\CliSecureRT.dll
MOD - [2012.09.16 07:27:32 | 002,244,064 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2012.06.14 09:36:33 | 000,677,376 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SolutoCleanup\416942261ca1cef810b97e1ff4b646c4\SolutoCleanup.ni.dll
MOD - [2012.06.14 09:36:30 | 000,766,464 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDataAggregation\1ae6c9da0192c81b6702f234030fdb0a\PCGDataAggregation.ni.dll
MOD - [2012.06.14 09:36:28 | 000,808,960 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGBrowsersProbe\457d07f5efcfcaf3c6a69b8a845eb8bb\PCGBrowsersProbe.ni.dll
MOD - [2012.06.14 09:36:26 | 000,891,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGClientCommunicat#\fb1de359a3660f8ce5acb29d0d1ef7ad\PCGClientCommunication.ni.dll
MOD - [2012.06.14 09:35:56 | 003,686,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGClientCommon\047ad9e06a7f33e5883975e0a0491a99\PCGClientCommon.ni.dll
MOD - [2012.06.14 09:35:48 | 001,260,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCommunication\134247d6cb313b02f7e3dc9912b6861b\PCGCommunication.ni.dll
MOD - [2012.06.14 09:35:38 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
MOD - [2012.06.14 09:35:15 | 002,414,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGFramework\597ce6ba7e6b43910b3489497566491d\PCGFramework.ni.dll
MOD - [2012.06.14 09:21:09 | 013,197,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\54d61af44b1dedee6aea0d1bbc46b13a\System.Windows.Forms.ni.dll
MOD - [2012.06.14 09:12:20 | 017,998,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\5d585d5428ce69abc28238ffa9f4d3a2\PresentationFramework.ni.dll
MOD - [2012.06.14 09:11:56 | 011,451,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\fe068ba4be8f6cb7d6a58bccff05c75e\PresentationCore.ni.dll
MOD - [2012.06.14 09:11:39 | 003,856,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\62f103f9e662d263ec2ecacc49d4525b\WindowsBase.ni.dll
MOD - [2012.06.14 09:11:34 | 001,666,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4a668799513e369a54fdab8b3f74de92\System.Drawing.ni.dll
MOD - [2012.05.30 20:06:48 | 000,087,912 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\zlib1.dll
MOD - [2012.05.30 20:06:30 | 001,242,512 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\libxml2.dll
MOD - [2012.05.13 12:36:26 | 001,218,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\1409dc3832b37f850569c69a795f834b\System.Management.ni.dll
MOD - [2012.05.13 12:33:50 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\082473bbeed448eb13a7f348cf33e98f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.13 12:32:51 | 001,781,760 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\9b6f1bcb2cf4e6ad429cd721b942f30f\System.Xaml.ni.dll
MOD - [2012.05.13 12:30:24 | 000,410,112 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGBootVisualizingC#\e98fa80e84af386b9c8cac5409c5ce5c\PCGBootVisualizingCore.ni.dll
MOD - [2012.05.13 12:30:23 | 000,362,496 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCatalogItemFootp#\77f31da58740fa6bf132aaf7008c74fb\PCGCatalogItemFootprint.ni.dll
MOD - [2012.05.13 12:30:20 | 000,328,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGSAProbe\d94f98bb221e4e55bc87a82055eb3319\PCGSAProbe.ni.dll
MOD - [2012.05.13 12:30:20 | 000,117,248 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCatalogItemCache\c7744b2daff6165f4fb68ef306ae50fc\PCGCatalogItemCache.ni.dll
MOD - [2012.05.13 12:30:19 | 000,047,616 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGEntities\6c5bd792147c582d24809c83053f9823\PCGEntities.ni.dll
MOD - [2012.05.13 12:30:16 | 000,137,216 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGUpgrader\a38513a2d17566a09459486a527f5cbd\PCGUpgrader.ni.dll
MOD - [2012.05.13 12:30:15 | 001,482,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SolutoService\efc6c3aa2eea52533b93724b1dc3a8b8\SolutoService.ni.exe
MOD - [2012.05.13 12:30:00 | 000,202,240 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGWuInfo\95f6f2f79188d4d7c16319829ccc4072\PCGWuInfo.ni.dll
MOD - [2012.05.13 12:29:56 | 002,327,552 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Community.CsharpSql#\fee1c62db73c777cf9b4401574c461ac\Community.CsharpSqlite.ni.dll
MOD - [2012.05.13 12:29:54 | 000,100,864 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\3d79ecc1212228d8074cceb00e268e77\Interop.IWshRuntimeLibrary.ni.dll
MOD - [2012.05.13 12:29:54 | 000,065,024 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGUsersCenter\169e956824c3d1b9c608f4ab0f3e7500\PCGUsersCenter.ni.dll
MOD - [2012.05.13 12:29:48 | 000,063,488 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGConfiguration\526fbf85e96ccdb425022f1cfacf3252\PCGConfiguration.ni.dll
MOD - [2012.05.13 12:29:45 | 003,789,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDatabase\077460da9e9554c6ed4cab08a4fc3db4\PCGDatabase.ni.dll
MOD - [2012.05.13 12:29:42 | 000,045,568 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGAzureEntityFrame#\4ecd770531f97e2c8fb9dcfc13fd61d7\PCGAzureEntityFramework.ni.dll
MOD - [2012.05.13 12:29:41 | 001,038,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGAzureShared\182032e709f493400f410def8d3bd919\PCGAzureShared.ni.dll
MOD - [2012.05.13 12:29:39 | 000,172,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDriverProbe\43298aa25a92112b59d8a97682c83b37\PCGDriverProbe.ni.dll
MOD - [2012.05.13 12:29:37 | 002,845,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGPreCompiled\1b77418a303d83913aa96fe6ee4559d3\PCGPreCompiled.ni.dll
MOD - [2012.05.13 12:29:35 | 000,186,880 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGPrestoSerializer\56885fe9df4ee8bcfaef60d441c52432\PCGPrestoSerializer.ni.dll
MOD - [2012.05.13 12:29:34 | 000,596,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Ionic.Zip.Reduced\8e581a164c74acf7f2e5aab4989edee6\Ionic.Zip.Reduced.ni.dll
MOD - [2012.05.13 12:03:42 | 002,295,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\38d07a5ac34b99d94fd14f42e779f625\System.Core.ni.dll
MOD - [2012.05.13 12:02:26 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012.05.13 12:02:12 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012.05.13 11:57:17 | 000,755,712 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\190e1740c9b998105a47ec31df0b6f11\PresentationFramework.Luna.ni.dll
MOD - [2012.05.13 11:48:37 | 007,052,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\14ba6251d6ec84c9579ed3d3e10b30c1\System.Core.ni.dll
MOD - [2012.05.13 11:48:36 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5ee8bf77e7b3e25cdbff6e1c299574fe\System.Xml.ni.dll
MOD - [2012.05.13 11:48:22 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\6f399163bb35597da7141ccdb7f39d16\System.ni.dll
MOD - [2012.05.13 11:48:09 | 014,412,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2012.03.20 10:51:57 | 000,021,416 | ---- | M] () -- C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2011.08.24 09:59:24 | 000,135,168 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\LogParser.dll
MOD - [2011.08.24 09:59:18 | 000,131,072 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\KEventLog.dll
MOD - [2011.08.24 09:58:24 | 000,131,072 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\KAgentExt.dll
MOD - [2011.08.23 16:32:42 | 000,446,464 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\libkacm.dll
MOD - [2011.06.22 03:14:36 | 000,145,264 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe
MOD - [2011.06.22 03:02:16 | 000,015,216 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSMui.dll
MOD - [2011.06.22 03:02:12 | 000,079,728 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\zlib125.dll
MOD - [2011.06.22 03:02:00 | 000,292,720 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\sqlite3.dll
MOD - [2011.05.28 23:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2011.05.17 11:58:44 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Programme\GNU\GnuPG\dirmngr.exe
MOD - [2011.03.02 17:17:18 | 000,603,136 | ---- | M] () -- C:\Programme\GNU\GnuPG\libgcrypt-11.dll
MOD - [2011.03.02 17:16:20 | 000,208,384 | ---- | M] () -- C:\Programme\GNU\GnuPG\libksba-8.dll
MOD - [2011.03.02 17:16:08 | 000,073,216 | ---- | M] () -- C:\Programme\GNU\GnuPG\libassuan-0.dll
MOD - [2011.03.02 17:13:52 | 000,048,640 | ---- | M] () -- C:\Programme\GNU\GnuPG\libgpg-error-0.dll
MOD - [2011.03.02 17:11:52 | 000,038,400 | ---- | M] () -- C:\Programme\GNU\GnuPG\libw32pth-0.dll
MOD - [2010.06.24 11:03:30 | 001,578,496 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\ncpgacc.dll
MOD - [2010.06.09 12:45:54 | 000,097,792 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPMIF32.DLL
MOD - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE
MOD - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
MOD - [2009.10.21 13:29:20 | 000,139,264 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPDLG.DLL
MOD - [2009.09.23 15:35:06 | 000,129,536 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NcpBudget2008.dll
MOD - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
MOD - [2008.08.20 17:10:50 | 000,200,704 | ---- | M] () -- C:\Programme\Intel\WiFi\bin\iWMSProv.dll
MOD - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
MOD - [2007.09.02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.dll
MOD - [2004.07.20 18:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll
MOD - [2002.06.28 11:16:42 | 000,151,552 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPCFG.DLL
 
 
========== Services (SafeList) ==========
 
SRV - [2012.09.16 07:27:33 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.09.05 08:50:31 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2012.04.12 05:56:08 | 000,175,624 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe -- (NitroDriverReadSpool2)
SRV - [2012.04.11 23:07:38 | 000,175,632 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe -- (NitroReaderDriverReadSpool2)
SRV - [2012.02.29 18:29:02 | 000,459,784 | ---- | M] (G Data Software AG) [On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe -- (GDScan)
SRV - [2012.02.29 18:28:58 | 001,501,192 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe -- (AVKProxy)
SRV - [2012.02.28 04:40:50 | 001,800,696 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\G Data\AVKClient\AVKCl.exe -- (AntiVirusKit Client)
SRV - [2012.02.28 04:02:06 | 001,554,696 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\G Data\AVKClient\AVKWCtl.exe -- (AVKWCtl)
SRV - [2012.02.28 03:59:06 | 001,498,616 | ---- | M] (G Data Software AG) [On_Demand | Stopped] -- C:\Programme\G Data\AVKClient\AVKBackupService.exe -- (GDBackupSvc)
SRV - [2012.01.04 14:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011.10.18 22:02:24 | 000,456,736 | ---- | M] (Soluto) [Auto | Running] -- C:\Programme\Soluto\SolutoService.exe -- (SolutoService)
SRV - [2011.08.24 10:00:04 | 000,851,968 | ---- | M] (Kaseya International Limited) [Auto | Running] -- C:\Programme\Kaseya\0PTRCS41496284544875\AgentMon.exe -- (KA0PTRCS41496284544875)
SRV - [2011.06.22 03:41:20 | 000,029,552 | ---- | M] (Gladinet, INC) [Auto | Running] -- C:\Programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe -- (GladFileMonSvc)
SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Programme\GNU\GnuPG\dirmngr.exe -- (DirMngr)
SRV - [2010.06.30 10:56:22 | 001,118,288 | ---- | M] (NCP Engineering GmbH) [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\ncprwsnt.exe -- (ncprwsnt)
SRV - [2010.05.21 11:44:26 | 000,133,712 | ---- | M] (NCP engineering GmbH) [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\ncpclcfg.exe -- (ncpclcfg)
SRV - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE -- (NcpSec)
SRV - [2010.04.30 13:24:18 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\WINDOWS\service4g.exe -- (XS Stick Service)
SRV - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () [Auto | Running] -- C:\Programme\XSManager\WTGService.exe -- (WTGService)
SRV - [2010.03.18 12:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2008.08.20 17:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2008.08.20 17:28:34 | 000,348,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2008.08.20 17:18:34 | 000,905,216 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor)
SRV - [2008.08.20 17:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2007.05.10 11:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) [Auto | Running] -- C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe -- (STacSV)
SRV - [2006.03.03 22:03:10 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2005.04.04 01:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOKUME~1\KLAUS~1.JAM\LOKALE~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.06.18 14:29:25 | 000,052,216 | ---- | M] (G Data Software AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\GDTdiIcpt.sys -- (GDTdiInterceptor)
DRV - [2012.06.18 14:29:21 | 000,079,992 | ---- | M] (G Data Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MiniIcpt.sys -- (GDMnIcpt)
DRV - [2012.06.18 14:29:21 | 000,040,568 | ---- | M] (G Data Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\HookCentre.sys -- (HookCentre)
DRV - [2012.06.18 14:29:21 | 000,040,440 | ---- | M] (G Data Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\GDBehave.sys -- (GDBehave)
DRV - [2012.06.18 14:29:11 | 000,069,272 | ---- | M] (G Data Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\GRD.sys -- (GRD)
DRV - [2012.05.11 07:53:22 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2011.12.08 06:22:26 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011.12.08 06:22:26 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011.12.08 06:22:26 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011.11.02 18:10:32 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2011.11.01 11:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011.11.01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011.11.01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.11.01 11:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011.10.18 21:50:18 | 000,051,144 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\Soluto.sys -- (Soluto)
DRV - [2011.06.23 11:09:02 | 000,017,920 | ---- | M] (Kaseya) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KAPFA.sys -- (KAPFA)
DRV - [2010.08.04 06:33:28 | 000,061,696 | ---- | M] (ASIX Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ax88772.sys -- (AX88772)
DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (ncpvaxp)
DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (NcpFiltMP)
DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (NcpFilt)
DRV - [2009.09.28 22:57:28 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2008.08.29 00:34:30 | 003,632,384 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.08.04 12:32:26 | 000,011,904 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007.12.23 18:18:48 | 000,068,696 | ---- | M] (O2Micro) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\oz776.sys -- (guardian2)
DRV - [2007.08.02 18:35:12 | 000,989,952 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2007.08.02 18:34:30 | 000,211,200 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2007.08.02 18:34:26 | 000,731,136 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2007.06.25 19:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007.05.10 11:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007.04.23 17:39:00 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2007.04.10 21:29:42 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2007.02.16 16:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.01.16 11:22:00 | 000,031,744 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\csrbcxp.sys -- (CSRBC)
DRV - [2006.11.22 17:09:22 | 000,053,504 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2006.11.20 18:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2006.10.10 20:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)
DRV - [2006.10.05 17:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2005.08.01 17:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005.01.06 14:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C4 91 C0 0B E1 05 CD 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{B56635D2-7485-49B6-85F3-9EAB0E0DAF4F}: "URL" = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:{language}:{referrer:source}&amp;ie={inputEncoding?}&oe={outputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Programme\Nitro PDF\Professional 7\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_8.0@nokia.com: C:\Programme\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_8.0 [2012.02.14 10:14:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.09.16 07:27:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.09.03 15:23:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_11.0@nokia.com: C:\Programme\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_11.0
 
[2011.11.02 17:24:57 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Extensions
[2012.09.13 07:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\extensions
[2012.04.30 13:52:40 | 000,003,941 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\searchplugins\gXverNTuDgXvssrJsNTu
[2012.07.16 09:12:42 | 000,000,925 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\searchplugins\oGjfLssqUoGjVn
[2012.07.31 12:45:35 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.09.16 07:27:35 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.16 07:27:28 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.09.19 09:23:53 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Programme\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [AVK Client] C:\Programme\G Data\AVKClient\AVKCl.exe (G Data Software AG)
O4 - HKLM..\Run: [IntelWireless] C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [KASH0PTRCS41496284544875] C:\Programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe (Kaseya International Limited)
O4 - HKLM..\Run: [NcpBudgetGui] C:\Programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe (NCP engineering GmbH)
O4 - HKLM..\Run: [NcpPopup] C:\Programme\LANCOM\Advanced VPN Client\ncppopup.exe (NCP engineering GmbH)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [starter4g] C:\WINDOWS\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [1und1Dispatcher] C:\Programme\1und1Softwareaktualisierung\SchedDispatcher.exe (1&1 Mail & Media GmbH)
O4 - HKCU..\Run: [KiesHelper] C:\Programme\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [RocketDock] C:\Programme\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\fjtLUyyxEfjsnd (Dropbox, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Web-Suche - C:\Programme\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256658069250 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ild-group.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4693966C-F27A-4969-BADC-BA0232CFA337}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOKUME~1/KLAUS~1.JAM/LOKALE~1/Temp/msohtmlclip1/01/clip_image001.gif
O24 - Desktop Components:1 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.26 18:47:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.19 10:19:14 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2012.09.19 10:18:37 | 002,322,184 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\esetsmartinstaller_enu.exe
[2012.09.19 09:25:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.09.19 08:12:18 | 004,752,754 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ComboFix.exe
[2012.09.19 07:35:09 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.09.19 07:27:25 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.09.19 07:27:25 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.09.19 07:27:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.09.19 07:27:25 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.09.19 07:27:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.09.19 07:27:05 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Verwaltung
[2012.09.19 07:26:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012.09.18 16:19:09 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\aswMBR.exe
[2012.09.18 14:51:30 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe
[2012.09.14 15:52:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox
[2012.09.14 15:51:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Eigene Dateien\Neuer Ordner
[2012.09.14 14:45:40 | 000,448,816 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\rannohdecryptor.exe
[2012.09.13 07:22:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Malwarebytes
[2012.09.13 07:22:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.09.13 07:21:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.09.13 07:21:56 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.09.13 07:21:56 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.09.12 13:11:45 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012.09.04 10:29:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\UseNeXT
[2012.09.03 15:22:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\QuickTime
[2012.09.03 15:22:23 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime
[2012.09.03 10:30:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Apple
[2012.08.29 14:39:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\eggebrecht anton safkow
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.19 20:45:00 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0FC1045D-8DAD-4D1A-A132-D01B23212E6A}.job
[2012.09.19 20:44:00 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A375F577-6969-4115-956F-4E4771D9E2A5}.job
[2012.09.19 20:43:02 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{CE0BAAD5-A1CD-49A5-8CAA-0C04D1C52B7F}.job
[2012.09.19 20:43:00 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0CDD7E22-5E6A-45B2-B31C-8D7446D529A1}.job
[2012.09.19 17:56:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.09.19 12:10:12 | 000,799,585 | ---- | M] () -- C:\WINDOWS\System32\sig.bin
[2012.09.19 12:10:12 | 000,044,197 | ---- | M] () -- C:\WINDOWS\System32\nmp.map
[2012.09.19 10:18:45 | 002,322,184 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\esetsmartinstaller_enu.exe
[2012.09.19 09:23:53 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.09.19 09:23:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.09.19 09:21:05 | 000,000,021 | ---- | M] () -- C:\WINDOWS\S.dirmngr
[2012.09.19 09:20:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.09.19 09:20:43 | 3747,573,760 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.19 08:12:09 | 004,752,754 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ComboFix.exe
[2012.09.19 07:35:16 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012.09.18 16:31:55 | 000,000,512 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\MBR.dat
[2012.09.18 14:59:30 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\aswMBR.exe
[2012.09.18 14:51:33 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe
[2012.09.18 14:49:08 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.09.18 09:08:55 | 000,001,479 | ---- | M] () -- C:\WINDOWS\System32\.lck
[2012.09.18 09:08:54 | 000,019,320 | ---- | M] () -- C:\WINDOWS\System32\.rsp
[2012.09.14 15:52:23 | 000,001,031 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox.lnk
[2012.09.13 07:22:00 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.12 11:16:26 | 000,448,816 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\rannohdecryptor.exe
[2012.09.12 07:59:21 | 000,001,074 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk
[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.09.05 09:15:47 | 000,027,648 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.05 08:50:30 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.09.05 08:50:29 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.09.05 07:28:20 | 000,093,696 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\lraJseOXQlrTJJsO
[2012.09.05 07:26:53 | 000,550,669 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\DrTvegXQuDNTvegXXQDr
[2012.09.04 12:00:30 | 000,001,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nitro Pro 7.lnk
[2012.09.03 15:22:49 | 000,001,590 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.09.03 10:30:06 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.09.03 08:25:12 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLev.DAT
[2012.09.03 08:24:18 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT
[2012.08.30 16:35:10 | 000,019,418 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntjjVExydLstjVExy
[2012.08.30 16:34:30 | 000,016,896 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydLsAfoxqqdLtAfoGG
[2012.08.30 16:33:46 | 000,052,243 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntAAfExqdLstAVExq
[2012.08.25 20:31:04 | 000,172,477 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ysnVAxxEUqtLVAAGEU
[2012.08.25 20:30:14 | 000,164,793 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\tAfExxydLsjfoExqdLs
[2012.08.25 20:29:11 | 000,010,975 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\XODQTTrsJXgDuQaNs
[2012.08.25 20:26:23 | 000,106,494 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\geuXXNDJageuuXNDJ
[2012.08.25 20:24:24 | 000,188,697 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\toVqxLLUjsofyxxLdj
[2012.08.25 20:22:48 | 000,103,164 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\jxEdysnffAGEUys
[2012.08.25 20:19:10 | 000,119,223 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\oVqGLLUAsEVyxGLdAto
[2012.08.25 20:18:15 | 000,136,189 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\JTOsQXprDvTOsuQX
[2012.08.25 20:17:44 | 000,237,939 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\yUntAAVExydnttjVExq
[2012.08.25 20:15:34 | 000,138,218 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\LVjxodqttLVjGodqqt
[2012.08.25 20:14:23 | 000,003,540 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ndjtooVqxndAssoVyx
[2012.08.25 20:00:32 | 000,001,039 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\AVExxydntAfoEx
[2012.08.24 18:31:40 | 000,174,227 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\VqxndjtoVVqGLd
[2012.08.24 18:24:25 | 000,816,518 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\qxLdjttEVqxndjjtoVq
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.09.19 07:35:16 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012.09.19 07:35:12 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2012.09.19 07:27:25 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.09.19 07:27:25 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.09.19 07:27:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.09.19 07:27:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.09.19 07:27:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.09.18 16:22:35 | 000,000,512 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\MBR.dat
[2012.09.14 15:52:23 | 000,001,031 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox.lnk
[2012.09.13 07:41:38 | 000,000,021 | ---- | C] () -- C:\WINDOWS\S.dirmngr
[2012.09.13 07:22:00 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.04 12:00:30 | 000,001,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nitro Pro 7.lnk
[2012.09.04 12:00:28 | 000,001,888 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Nitro Pro 7.lnk
[2012.09.04 11:13:29 | 3747,573,760 | -HS- | C] () -- C:\hiberfil.sys
[2012.09.03 15:22:49 | 000,001,590 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.05.13 14:48:27 | 001,005,848 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.04.03 10:36:28 | 000,009,263 | ---- | C] () -- C:\WINDOWS\System32\UpdateAction_30032012.exe.dmp
[2012.03.19 17:14:38 | 000,000,646 | ---- | C] () -- C:\WINDOWS\wiso.ini
[2012.02.27 11:45:00 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.02.15 09:19:54 | 000,559,362 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-2172849378-3237517302-3047019274-1120-0.dat
[2012.02.15 07:51:19 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.02.14 11:24:10 | 000,270,318 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2012.01.31 19:15:44 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe
[2012.01.31 19:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012.01.31 19:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012.01.31 19:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012.01.31 19:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012.01.02 11:45:50 | 000,000,383 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2011.12.13 07:13:27 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI
[2011.11.30 06:29:41 | 000,007,494 | ---- | C] () -- C:\WINDOWS\System32\Upd20111125.exe.dmp
[2011.11.26 22:17:24 | 000,001,205 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini
[2011.11.25 20:24:20 | 000,000,143 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2011.11.25 20:12:08 | 000,000,163 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2011.11.25 20:11:38 | 000,000,690 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2011.11.25 19:56:23 | 000,127,878 | ---- | C] () -- C:\WINDOWS\hpoins11.dat
[2011.11.25 19:54:40 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2011.11.25 19:53:49 | 000,011,634 | ---- | C] () -- C:\WINDOWS\hpomdl11.dat
[2011.11.08 16:12:15 | 000,027,648 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.08 13:11:33 | 000,799,585 | ---- | C] () -- C:\WINDOWS\System32\sig.bin
[2011.11.03 07:58:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLev.DAT
[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT
[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLes.DAT
[2011.10.24 09:25:55 | 000,000,094 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft.SqlServer.Compact.351.32.bc
[1601.02.13 10:28:18 | 001,597,464 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\VAtndqGEEVAtnUq
[1601.02.13 10:28:18 | 000,078,022 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\GEUqsnnfAGodqts
[1601.02.13 10:28:18 | 000,004,211 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\QDrTJJsOpQDrTaJe
[1601.02.13 10:28:18 | 000,003,090 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\GqdLtjjfoxydnttjfo
[1601.02.13 10:28:18 | 000,001,601 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JeNTQDDOXJeNauulg
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\uyUaJlAVnsyUEvJ
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TujOXJxyfosjdpp
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\JTNlluXgevaNNDuXgsvaa
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JDNXuegaavlNXueggavlr
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\gsvTrllupgsJTrrl
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\DuXOeJvaNlupgeeJaNDu
 
========== ZeroAccess Check ==========
 
[2009.10.27 16:09:51 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

< End of report >


schrauber 19.09.2012 20:13

Fixen mit OTL
  • Starte die OTL.exe.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Kopiere folgendes Skript:
Code:

:OTL
O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\fjtLUyyxEfjsnd (Dropbox, Inc.)
[2012.09.05 07:28:20 | 000,093,696 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\lraJseOXQlrTJJsO
[2012.09.05 07:26:53 | 000,550,669 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\DrTvegXQuDNTvegXXQDr
[2012.08.30 16:35:10 | 000,019,418 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntjjVExydLstjVExy
[2012.08.30 16:34:30 | 000,016,896 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydLsAfoxqqdLtAfoGG
[2012.08.30 16:33:46 | 000,052,243 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntAAfExqdLstAVExq
[2012.08.25 20:31:04 | 000,172,477 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ysnVAxxEUqtLVAAGEU
[2012.08.25 20:30:14 | 000,164,793 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\tAfExxydLsjfoExqdLs
[2012.08.25 20:29:11 | 000,010,975 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\XODQTTrsJXgDuQaNs
[2012.08.25 20:26:23 | 000,106,494 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\geuXXNDJageuuXNDJ
[2012.08.25 20:24:24 | 000,188,697 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\toVqxLLUjsofyxxLdj
[2012.08.25 20:22:48 | 000,103,164 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\jxEdysnffAGEUys
[2012.08.25 20:19:10 | 000,119,223 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\oVqGLLUAsEVyxGLdAto
[2012.08.25 20:18:15 | 000,136,189 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\JTOsQXprDvTOsuQX
[2012.08.25 20:17:44 | 000,237,939 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\yUntAAVExydnttjVExq
[2012.08.25 20:15:34 | 000,138,218 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\LVjxodqttLVjGodqqt
[2012.08.25 20:14:23 | 000,003,540 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ndjtooVqxndAssoVyx
[2012.08.25 20:00:32 | 000,001,039 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\AVExxydntAfoEx
[2012.08.24 18:31:40 | 000,174,227 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\VqxndjtoVVqGLd
[1601.02.13 10:28:18 | 001,597,464 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\VAtndqGEEVAtnUq
[1601.02.13 10:28:18 | 000,078,022 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\GEUqsnnfAGodqts
[1601.02.13 10:28:18 | 000,004,211 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\QDrTJJsOpQDrTaJe
[1601.02.13 10:28:18 | 000,003,090 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\GqdLtjjfoxydnttjfo
[1601.02.13 10:28:18 | 000,001,601 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JeNTQDDOXJeNauulg
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\uyUaJlAVnsyUEvJ
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TujOXJxyfosjdpp
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\JTNlluXgevaNNDuXgsvaa
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JDNXuegaavlNXueggavlr
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\gsvTrllupgsJTrrl
[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\DuXOeJvaNlupgeeJaNDu
[2009.10.27 16:09:51 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
:Commands
[emptytemp]

[list][*]und füge es hier ein: http://image.hijackthis.eu/upload/hjt1-021.jpg[*] Schließe alle Programme.[*] Klicke auf den Fix Button.[*] Klick auf http://billy-oneal.com/Canned%20Spee.../OTL/btnOK.png.[*] OTL verlangt einen Neustart. Bitte zulassen.[*] Nach dem Neustart findest Du ein Textdokument.



Bitte ein frisches OTL logfile. Wie läuft der Rechner?

klaus196 20.09.2012 06:55

neustart wurde nicht gefordert, hier das file:
Code:

Error: Unable to interpret <OTL Logfile:

       
Code:

       
OTL logfile created on: 19.09.2012 20:40:53 - Run 2> in the current context!
Error: Unable to interpret <OTL by OldTimer - Version 3.2.63.0     Folder = C:\Dokumente und Einstellungen\klaus.jama\Desktop> in the current context!
Error: Unable to interpret <Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation> in the current context!
Error: Unable to interpret <Internet Explorer (Version = 8.0.6001.18702)> in the current context!
Error: Unable to interpret <Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <3,49 Gb Total Physical Memory | 2,60 Gb Available Physical Memory | 74,56% Memory free> in the current context!
Error: Unable to interpret <5,33 Gb Paging File | 4,57 Gb Available in Paging File | 85,76% Paging File free> in the current context!
Error: Unable to interpret <Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme> in the current context!
Error: Unable to interpret <Drive C: | 74,53 Gb Total Space | 20,14 Gb Free Space | 27,02% Space Free | Partition Type: NTFS> in the current context!
Error: Unable to interpret <Drive E: | 698,46 Gb Total Space | 296,42 Gb Free Space | 42,44% Space Free | Partition Type: FAT32> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <Computer Name: NBKLAUSJAMA-1 | User Name: klaus.jama | Logged in as Administrator.> in the current context!
Error: Unable to interpret <Boot Mode: Normal | Scan Mode: Current user> in the current context!
Error: Unable to interpret <Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Processes (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <PRC - [2012.09.18 14:51:33 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe> in the current context!
Error: Unable to interpret <PRC - [2012.09.16 07:27:34 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe> in the current context!
Error: Unable to interpret <PRC - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe> in the current context!
Error: Unable to interpret <PRC - [2012.05.24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe> in the current context!
Error: Unable to interpret <PRC - [2012.04.12 05:56:08 | 000,175,624 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe> in the current context!
Error: Unable to interpret <PRC - [2012.04.11 23:07:38 | 000,175,632 | ---- | M] (Nitro PDF Software) -- C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe> in the current context!
Error: Unable to interpret <PRC - [2012.03.20 10:51:57 | 000,021,416 | ---- | M] () -- C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe> in the current context!
Error: Unable to interpret <PRC - [2012.02.29 18:29:02 | 000,459,784 | ---- | M] (G Data Software AG) -- C:\Programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe> in the current context!
Error: Unable to interpret <PRC - [2012.02.29 18:28:58 | 001,501,192 | ---- | M] (G Data Software AG) -- C:\Programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe> in the current context!
Error: Unable to interpret <PRC - [2012.02.28 04:40:50 | 001,800,696 | ---- | M] (G Data Software AG) -- C:\Programme\G Data\AVKClient\AVKCl.exe> in the current context!
Error: Unable to interpret <PRC - [2012.02.28 04:02:06 | 001,554,696 | ---- | M] (G Data Software AG) -- C:\Programme\G Data\AVKClient\AVKWCtl.exe> in the current context!
Error: Unable to interpret <PRC - [2012.01.18 15:02:04 | 000,508,136 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe> in the current context!
Error: Unable to interpret <PRC - [2012.01.18 15:02:04 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe> in the current context!
Error: Unable to interpret <PRC - [2012.01.04 14:32:36 | 000,718,888 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe> in the current context!
Error: Unable to interpret <PRC - [2012.01.04 14:32:18 | 000,173,096 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclUSBSrv.exe> in the current context!
Error: Unable to interpret <PRC - [2012.01.04 14:32:14 | 000,147,496 | ---- | M] (Nokia) -- C:\Programme\PC Connectivity Solution\Transports\NclToBTSrv.exe> in the current context!
Error: Unable to interpret <PRC - [2011.10.18 22:02:24 | 000,456,736 | ---- | M] (Soluto) -- C:\Programme\Soluto\SolutoService.exe> in the current context!
Error: Unable to interpret <PRC - [2011.08.24 10:00:42 | 000,409,600 | ---- | M] (Kaseya International Limited) -- C:\Programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe> in the current context!
Error: Unable to interpret <PRC - [2011.08.24 10:00:04 | 000,851,968 | ---- | M] (Kaseya International Limited) -- C:\Programme\Kaseya\0PTRCS41496284544875\AgentMon.exe> in the current context!
Error: Unable to interpret <PRC - [2011.06.22 03:41:20 | 000,029,552 | ---- | M] (Gladinet, INC) -- C:\Programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe> in the current context!
Error: Unable to interpret <PRC - [2011.06.22 03:14:36 | 000,145,264 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe> in the current context!
Error: Unable to interpret <PRC - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Programme\GNU\GnuPG\dirmngr.exe> in the current context!
Error: Unable to interpret <PRC - [2010.12.21 01:07:48 | 000,227,712 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE> in the current context!
Error: Unable to interpret <PRC - [2010.10.27 20:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe> in the current context!
Error: Unable to interpret <PRC - [2010.08.25 12:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ArcCon.ac> in the current context!
Error: Unable to interpret <PRC - [2010.06.30 10:56:22 | 001,118,288 | ---- | M] (NCP Engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\ncprwsnt.exe> in the current context!
Error: Unable to interpret <PRC - [2010.05.21 11:44:26 | 000,133,712 | ---- | M] (NCP engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\ncpclcfg.exe> in the current context!
Error: Unable to interpret <PRC - [2010.05.21 11:39:22 | 001,026,560 | ---- | M] (NCP engineering GmbH) -- C:\Programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe> in the current context!
Error: Unable to interpret <PRC - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE> in the current context!
Error: Unable to interpret <PRC - [2010.04.30 13:24:26 | 000,160,424 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\starter4g.exe> in the current context!
Error: Unable to interpret <PRC - [2010.04.30 13:24:18 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\service4g.exe> in the current context!
Error: Unable to interpret <PRC - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe> in the current context!
Error: Unable to interpret <PRC - [2010.03.18 12:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe> in the current context!
Error: Unable to interpret <PRC - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe> in the current context!
Error: Unable to interpret <PRC - [2008.08.20 17:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe> in the current context!
Error: Unable to interpret <PRC - [2008.08.20 17:28:34 | 000,348,160 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\WLKEEPER.exe> in the current context!
Error: Unable to interpret <PRC - [2008.08.20 17:27:36 | 001,368,064 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe> in the current context!
Error: Unable to interpret <PRC - [2008.08.20 17:18:34 | 000,905,216 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe> in the current context!
Error: Unable to interpret <PRC - [2008.08.20 17:09:12 | 001,191,936 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe> in the current context!
Error: Unable to interpret <PRC - [2008.08.20 17:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe> in the current context!
Error: Unable to interpret <PRC - [2008.04.14 08:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe> in the current context!
Error: Unable to interpret <PRC - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe> in the current context!
Error: Unable to interpret <PRC - [2007.07.02 14:29:22 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\Apoint.exe> in the current context!
Error: Unable to interpret <PRC - [2007.06.06 17:44:44 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApntEx.exe> in the current context!
Error: Unable to interpret <PRC - [2007.05.22 15:18:56 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\ApMsgFwd.exe> in the current context!
Error: Unable to interpret <PRC - [2007.05.10 11:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe> in the current context!
Error: Unable to interpret <PRC - [2007.05.10 11:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe> in the current context!
Error: Unable to interpret <PRC - [2006.09.08 16:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programme\DellTPad\hidfind.exe> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Modules (No Company Name) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <MOD - [2012.09.19 09:26:25 | 000,115,137 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\temp\6573b3c6-4299-4ce1-bc75-7f3a9cd9d739\CliSecureRT.dll> in the current context!
Error: Unable to interpret <MOD - [2012.09.16 07:27:32 | 002,244,064 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:36:33 | 000,677,376 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SolutoCleanup\416942261ca1cef810b97e1ff4b646c4\SolutoCleanup.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:36:30 | 000,766,464 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDataAggregation\1ae6c9da0192c81b6702f234030fdb0a\PCGDataAggregation.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:36:28 | 000,808,960 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGBrowsersProbe\457d07f5efcfcaf3c6a69b8a845eb8bb\PCGBrowsersProbe.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:36:26 | 000,891,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGClientCommunicat#\fb1de359a3660f8ce5acb29d0d1ef7ad\PCGClientCommunication.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:35:56 | 003,686,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGClientCommon\047ad9e06a7f33e5883975e0a0491a99\PCGClientCommon.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:35:48 | 001,260,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCommunication\134247d6cb313b02f7e3dc9912b6861b\PCGCommunication.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:35:38 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:35:15 | 002,414,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGFramework\597ce6ba7e6b43910b3489497566491d\PCGFramework.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:21:09 | 013,197,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\54d61af44b1dedee6aea0d1bbc46b13a\System.Windows.Forms.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:12:20 | 017,998,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\5d585d5428ce69abc28238ffa9f4d3a2\PresentationFramework.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:11:56 | 011,451,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\fe068ba4be8f6cb7d6a58bccff05c75e\PresentationCore.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:11:39 | 003,856,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\62f103f9e662d263ec2ecacc49d4525b\WindowsBase.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.06.14 09:11:34 | 001,666,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4a668799513e369a54fdab8b3f74de92\System.Drawing.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.30 20:06:48 | 000,087,912 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\zlib1.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.30 20:06:30 | 001,242,512 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\libxml2.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:36:26 | 001,218,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\1409dc3832b37f850569c69a795f834b\System.Management.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:33:50 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\082473bbeed448eb13a7f348cf33e98f\System.Runtime.Remoting.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:32:51 | 001,781,760 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\9b6f1bcb2cf4e6ad429cd721b942f30f\System.Xaml.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:24 | 000,410,112 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGBootVisualizingC#\e98fa80e84af386b9c8cac5409c5ce5c\PCGBootVisualizingCore.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:23 | 000,362,496 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCatalogItemFootp#\77f31da58740fa6bf132aaf7008c74fb\PCGCatalogItemFootprint.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:20 | 000,328,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGSAProbe\d94f98bb221e4e55bc87a82055eb3319\PCGSAProbe.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:20 | 000,117,248 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGCatalogItemCache\c7744b2daff6165f4fb68ef306ae50fc\PCGCatalogItemCache.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:19 | 000,047,616 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGEntities\6c5bd792147c582d24809c83053f9823\PCGEntities.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:16 | 000,137,216 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGUpgrader\a38513a2d17566a09459486a527f5cbd\PCGUpgrader.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:15 | 001,482,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SolutoService\efc6c3aa2eea52533b93724b1dc3a8b8\SolutoService.ni.exe> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:30:00 | 000,202,240 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGWuInfo\95f6f2f79188d4d7c16319829ccc4072\PCGWuInfo.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:56 | 002,327,552 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Community.CsharpSql#\fee1c62db73c777cf9b4401574c461ac\Community.CsharpSqlite.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:54 | 000,100,864 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Interop.IWshRuntime#\3d79ecc1212228d8074cceb00e268e77\Interop.IWshRuntimeLibrary.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:54 | 000,065,024 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGUsersCenter\169e956824c3d1b9c608f4ab0f3e7500\PCGUsersCenter.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:48 | 000,063,488 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGConfiguration\526fbf85e96ccdb425022f1cfacf3252\PCGConfiguration.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:45 | 003,789,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDatabase\077460da9e9554c6ed4cab08a4fc3db4\PCGDatabase.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:42 | 000,045,568 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGAzureEntityFrame#\4ecd770531f97e2c8fb9dcfc13fd61d7\PCGAzureEntityFramework.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:41 | 001,038,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGAzureShared\182032e709f493400f410def8d3bd919\PCGAzureShared.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:39 | 000,172,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGDriverProbe\43298aa25a92112b59d8a97682c83b37\PCGDriverProbe.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:37 | 002,845,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGPreCompiled\1b77418a303d83913aa96fe6ee4559d3\PCGPreCompiled.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:35 | 000,186,880 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PCGPrestoSerializer\56885fe9df4ee8bcfaef60d441c52432\PCGPrestoSerializer.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:29:34 | 000,596,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Ionic.Zip.Reduced\8e581a164c74acf7f2e5aab4989edee6\Ionic.Zip.Reduced.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:03:42 | 002,295,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\38d07a5ac34b99d94fd14f42e779f625\System.Core.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:02:26 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 12:02:12 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 11:57:17 | 000,755,712 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\190e1740c9b998105a47ec31df0b6f11\PresentationFramework.Luna.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 11:48:37 | 007,052,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\14ba6251d6ec84c9579ed3d3e10b30c1\System.Core.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 11:48:36 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5ee8bf77e7b3e25cdbff6e1c299574fe\System.Xml.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 11:48:22 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\6f399163bb35597da7141ccdb7f39d16\System.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.05.13 11:48:09 | 014,412,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll> in the current context!
Error: Unable to interpret <MOD - [2012.03.20 10:51:57 | 000,021,416 | ---- | M] () -- C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe> in the current context!
Error: Unable to interpret <MOD - [2011.08.24 09:59:24 | 000,135,168 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\LogParser.dll> in the current context!
Error: Unable to interpret <MOD - [2011.08.24 09:59:18 | 000,131,072 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\KEventLog.dll> in the current context!
Error: Unable to interpret <MOD - [2011.08.24 09:58:24 | 000,131,072 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\KAgentExt.dll> in the current context!
Error: Unable to interpret <MOD - [2011.08.23 16:32:42 | 000,446,464 | ---- | M] () -- C:\Programme\Kaseya\0PTRCS41496284544875\libkacm.dll> in the current context!
Error: Unable to interpret <MOD - [2011.06.22 03:14:36 | 000,145,264 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSVSSSvrXP32.exe> in the current context!
Error: Unable to interpret <MOD - [2011.06.22 03:02:16 | 000,015,216 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\WOSMui.dll> in the current context!
Error: Unable to interpret <MOD - [2011.06.22 03:02:12 | 000,079,728 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\zlib125.dll> in the current context!
Error: Unable to interpret <MOD - [2011.06.22 03:02:00 | 000,292,720 | ---- | M] () -- C:\Programme\Nuance\Nuance Cloud Connector\sqlite3.dll> in the current context!
Error: Unable to interpret <MOD - [2011.05.28 23:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll> in the current context!
Error: Unable to interpret <MOD - [2011.05.17 11:58:44 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll> in the current context!
Error: Unable to interpret <MOD - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () -- C:\Programme\GNU\GnuPG\dirmngr.exe> in the current context!
Error: Unable to interpret <MOD - [2011.03.02 17:17:18 | 000,603,136 | ---- | M] () -- C:\Programme\GNU\GnuPG\libgcrypt-11.dll> in the current context!
Error: Unable to interpret <MOD - [2011.03.02 17:16:20 | 000,208,384 | ---- | M] () -- C:\Programme\GNU\GnuPG\libksba-8.dll> in the current context!
Error: Unable to interpret <MOD - [2011.03.02 17:16:08 | 000,073,216 | ---- | M] () -- C:\Programme\GNU\GnuPG\libassuan-0.dll> in the current context!
Error: Unable to interpret <MOD - [2011.03.02 17:13:52 | 000,048,640 | ---- | M] () -- C:\Programme\GNU\GnuPG\libgpg-error-0.dll> in the current context!
Error: Unable to interpret <MOD - [2011.03.02 17:11:52 | 000,038,400 | ---- | M] () -- C:\Programme\GNU\GnuPG\libw32pth-0.dll> in the current context!
Error: Unable to interpret <MOD - [2010.06.24 11:03:30 | 001,578,496 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\ncpgacc.dll> in the current context!
Error: Unable to interpret <MOD - [2010.06.09 12:45:54 | 000,097,792 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPMIF32.DLL> in the current context!
Error: Unable to interpret <MOD - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE> in the current context!
Error: Unable to interpret <MOD - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe> in the current context!
Error: Unable to interpret <MOD - [2009.10.21 13:29:20 | 000,139,264 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPDLG.DLL> in the current context!
Error: Unable to interpret <MOD - [2009.09.23 15:35:06 | 000,129,536 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NcpBudget2008.dll> in the current context!
Error: Unable to interpret <MOD - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe> in the current context!
Error: Unable to interpret <MOD - [2008.08.20 17:10:50 | 000,200,704 | ---- | M] () -- C:\Programme\Intel\WiFi\bin\iWMSProv.dll> in the current context!
Error: Unable to interpret <MOD - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe> in the current context!
Error: Unable to interpret <MOD - [2007.09.02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.dll> in the current context!
Error: Unable to interpret <MOD - [2004.07.20 18:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll> in the current context!
Error: Unable to interpret <MOD - [2002.06.28 11:16:42 | 000,151,552 | ---- | M] () -- C:\Programme\LANCOM\Advanced VPN Client\NCPCFG.DLL> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Services (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <SRV - [2012.09.16 07:27:33 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)> in the current context!
Error: Unable to interpret <SRV - [2012.09.07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)> in the current context!
Error: Unable to interpret <SRV - [2012.09.07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)> in the current context!
Error: Unable to interpret <SRV - [2012.09.05 08:50:31 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)> in the current context!
Error: Unable to interpret <SRV - [2012.05.24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)> in the current context!
Error: Unable to interpret <SRV - [2012.04.12 05:56:08 | 000,175,624 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Professional 7\NitroPDFDriverService2.exe -- (NitroDriverReadSpool2)> in the current context!
Error: Unable to interpret <SRV - [2012.04.11 23:07:38 | 000,175,632 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe -- (NitroReaderDriverReadSpool2)> in the current context!
Error: Unable to interpret <SRV - [2012.02.29 18:29:02 | 000,459,784 | ---- | M] (G Data Software AG) [On_Demand | Running] -- C:\Programme\Gemeinsame Dateien\G Data\GDScan\GDScan.exe -- (GDScan)> in the current context!
Error: Unable to interpret <SRV - [2012.02.29 18:28:58 | 001,501,192 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\G Data\AVKProxy\AVKProxy.exe -- (AVKProxy)> in the current context!
Error: Unable to interpret <SRV - [2012.02.28 04:40:50 | 001,800,696 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\G Data\AVKClient\AVKCl.exe -- (AntiVirusKit Client)> in the current context!
Error: Unable to interpret <SRV - [2012.02.28 04:02:06 | 001,554,696 | ---- | M] (G Data Software AG) [Auto | Running] -- C:\Programme\G Data\AVKClient\AVKWCtl.exe -- (AVKWCtl)> in the current context!
Error: Unable to interpret <SRV - [2012.02.28 03:59:06 | 001,498,616 | ---- | M] (G Data Software AG) [On_Demand | Stopped] -- C:\Programme\G Data\AVKClient\AVKBackupService.exe -- (GDBackupSvc)> in the current context!
Error: Unable to interpret <SRV - [2012.01.04 14:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)> in the current context!
Error: Unable to interpret <SRV - [2011.10.18 22:02:24 | 000,456,736 | ---- | M] (Soluto) [Auto | Running] -- C:\Programme\Soluto\SolutoService.exe -- (SolutoService)> in the current context!
Error: Unable to interpret <SRV - [2011.08.24 10:00:04 | 000,851,968 | ---- | M] (Kaseya International Limited) [Auto | Running] -- C:\Programme\Kaseya\0PTRCS41496284544875\AgentMon.exe -- (KA0PTRCS41496284544875)> in the current context!
Error: Unable to interpret <SRV - [2011.06.22 03:41:20 | 000,029,552 | ---- | M] (Gladinet, INC) [Auto | Running] -- C:\Programme\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe -- (GladFileMonSvc)> in the current context!
Error: Unable to interpret <SRV - [2011.03.02 17:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Programme\GNU\GnuPG\dirmngr.exe -- (DirMngr)> in the current context!
Error: Unable to interpret <SRV - [2010.06.30 10:56:22 | 001,118,288 | ---- | M] (NCP Engineering GmbH) [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\ncprwsnt.exe -- (ncprwsnt)> in the current context!
Error: Unable to interpret <SRV - [2010.05.21 11:44:26 | 000,133,712 | ---- | M] (NCP engineering GmbH) [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\ncpclcfg.exe -- (ncpclcfg)> in the current context!
Error: Unable to interpret <SRV - [2010.05.07 12:08:38 | 000,093,184 | ---- | M] () [Auto | Running] -- C:\Programme\LANCOM\Advanced VPN Client\NCPSEC.EXE -- (NcpSec)> in the current context!
Error: Unable to interpret <SRV - [2010.04.30 13:24:18 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\WINDOWS\service4g.exe -- (XS Stick Service)> in the current context!
Error: Unable to interpret <SRV - [2010.04.12 19:03:44 | 000,329,168 | ---- | M] () [Auto | Running] -- C:\Programme\XSManager\WTGService.exe -- (WTGService)> in the current context!
Error: Unable to interpret <SRV - [2010.03.18 12:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)> in the current context!
Error: Unable to interpret <SRV - [2010.01.09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)> in the current context!
Error: Unable to interpret <SRV - [2010.01.09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)> in the current context!
Error: Unable to interpret <SRV - [2009.09.06 14:38:06 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)> in the current context!
Error: Unable to interpret <SRV - [2008.08.20 17:38:30 | 000,860,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)> in the current context!
Error: Unable to interpret <SRV - [2008.08.20 17:28:34 | 000,348,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\WLKEEPER.exe -- (WLANKEEPER)> in the current context!
Error: Unable to interpret <SRV - [2008.08.20 17:18:34 | 000,905,216 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor)> in the current context!
Error: Unable to interpret <SRV - [2008.08.20 17:08:02 | 000,466,944 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)> in the current context!
Error: Unable to interpret <SRV - [2007.05.10 11:23:50 | 000,094,208 | ---- | M] (SigmaTel, Inc.) [Auto | Running] -- C:\Programme\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe -- (STacSV)> in the current context!
Error: Unable to interpret <SRV - [2006.03.03 22:03:10 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)> in the current context!
Error: Unable to interpret <SRV - [2005.04.04 01:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Driver Services (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOKUME~1\KLAUS~1.JAM\LOKALE~1\Temp\mbr.sys -- (mbr)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | System | Stopped] --  -- (Changer)> in the current context!
Error: Unable to interpret <DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)> in the current context!
Error: Unable to interpret <DRV - [2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)> in the current context!
Error: Unable to interpret <DRV - [2012.06.18 14:29:25 | 000,052,216 | ---- | M] (G Data Software AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\GDTdiIcpt.sys -- (GDTdiInterceptor)> in the current context!
Error: Unable to interpret <DRV - [2012.06.18 14:29:21 | 000,079,992 | ---- | M] (G Data Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MiniIcpt.sys -- (GDMnIcpt)> in the current context!
Error: Unable to interpret <DRV - [2012.06.18 14:29:21 | 000,040,568 | ---- | M] (G Data Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\HookCentre.sys -- (HookCentre)> in the current context!
Error: Unable to interpret <DRV - [2012.06.18 14:29:21 | 000,040,440 | ---- | M] (G Data Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\GDBehave.sys -- (GDBehave)> in the current context!
Error: Unable to interpret <DRV - [2012.06.18 14:29:11 | 000,069,272 | ---- | M] (G Data Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\GRD.sys -- (GRD)> in the current context!
Error: Unable to interpret <DRV - [2012.05.11 07:53:22 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)> in the current context!
Error: Unable to interpret <DRV - [2011.12.08 06:22:26 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)> in the current context!
Error: Unable to interpret <DRV - [2011.12.08 06:22:26 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)> in the current context!
Error: Unable to interpret <DRV - [2011.12.08 06:22:26 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)> in the current context!
Error: Unable to interpret <DRV - [2011.11.02 18:10:32 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmnsusbser.sys -- (cmnsusbser)> in the current context!
Error: Unable to interpret <DRV - [2011.11.01 11:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)> in the current context!
Error: Unable to interpret <DRV - [2011.11.01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)> in the current context!
Error: Unable to interpret <DRV - [2011.11.01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)> in the current context!
Error: Unable to interpret <DRV - [2011.11.01 11:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)> in the current context!
Error: Unable to interpret <DRV - [2011.10.18 21:50:18 | 000,051,144 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\Soluto.sys -- (Soluto)> in the current context!
Error: Unable to interpret <DRV - [2011.06.23 11:09:02 | 000,017,920 | ---- | M] (Kaseya) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KAPFA.sys -- (KAPFA)> in the current context!
Error: Unable to interpret <DRV - [2010.08.04 06:33:28 | 000,061,696 | ---- | M] (ASIX Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ax88772.sys -- (AX88772)> in the current context!
Error: Unable to interpret <DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (ncpvaxp)> in the current context!
Error: Unable to interpret <DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (NcpFiltMP)> in the current context!
Error: Unable to interpret <DRV - [2010.07.02 13:19:14 | 000,081,392 | ---- | M] (NCP Engineering GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ncpvaxp.sys -- (NcpFilt)> in the current context!
Error: Unable to interpret <DRV - [2009.09.28 22:57:28 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)> in the current context!
Error: Unable to interpret <DRV - [2008.08.29 00:34:30 | 003,632,384 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32)> in the current context!
Error: Unable to interpret <DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)> in the current context!
Error: Unable to interpret <DRV - [2008.08.04 12:32:26 | 000,011,904 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)> in the current context!
Error: Unable to interpret <DRV - [2007.12.23 18:18:48 | 000,068,696 | ---- | M] (O2Micro) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\oz776.sys -- (guardian2)> in the current context!
Error: Unable to interpret <DRV - [2007.08.02 18:35:12 | 000,989,952 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)> in the current context!
Error: Unable to interpret <DRV - [2007.08.02 18:34:30 | 000,211,200 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)> in the current context!
Error: Unable to interpret <DRV - [2007.08.02 18:34:26 | 000,731,136 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)> in the current context!
Error: Unable to interpret <DRV - [2007.06.25 19:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)> in the current context!
Error: Unable to interpret <DRV - [2007.05.10 11:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)> in the current context!
Error: Unable to interpret <DRV - [2007.04.23 17:39:00 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (tosrfbd)> in the current context!
Error: Unable to interpret <DRV - [2007.04.10 21:29:42 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)> in the current context!
Error: Unable to interpret <DRV - [2007.02.16 16:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)> in the current context!
Error: Unable to interpret <DRV - [2007.01.16 11:22:00 | 000,031,744 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\csrbcxp.sys -- (CSRBC)> in the current context!
Error: Unable to interpret <DRV - [2006.11.22 17:09:22 | 000,053,504 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TosRfSnd.sys -- (TosRfSnd)> in the current context!
Error: Unable to interpret <DRV - [2006.11.20 18:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (tosrfbnp)> in the current context!
Error: Unable to interpret <DRV - [2006.10.10 20:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)> in the current context!
Error: Unable to interpret <DRV - [2006.10.05 17:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tosrfhid.sys -- (Tosrfhid)> in the current context!
Error: Unable to interpret <DRV - [2005.08.01 17:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)> in the current context!
Error: Unable to interpret <DRV - [2005.01.06 14:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Standard Registry (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Internet Explorer ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com> in the current context!
Error: Unable to interpret <IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}> in the current context!
Error: Unable to interpret <IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com> in the current context!
Error: Unable to interpret <IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de> in the current context!
Error: Unable to interpret <IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C4 91 C0 0B E1 05 CD 01  [binary data]> in the current context!
Error: Unable to interpret <IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}> in the current context!
Error: Unable to interpret <IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC> in the current context!
Error: Unable to interpret <IE - HKCU\..\SearchScopes\{B56635D2-7485-49B6-85F3-9EAB0E0DAF4F}: "URL" = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:{language}:{referrer:source}&amp;ie={inputEncoding?}&oe={outputEncoding?}> in the current context!
Error: Unable to interpret <IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0> in the current context!
Error: Unable to interpret <IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== FireFox ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <FF - user.js - File not found> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Programme\Nitro PDF\Professional 7\npnitromozilla.dll ( )> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_8.0@nokia.com: C:\Programme\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_8.0 [2012.02.14 10:14:34 | 000,000,000 | ---D | M]> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.09.16 07:27:36 | 000,000,000 | ---D | M]> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.09.03 15:23:18 | 000,000,000 | ---D | M]> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_11.0@nokia.com: C:\Programme\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_11.0> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2011.11.02 17:24:57 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Extensions> in the current context!
Error: Unable to interpret <[2012.09.13 07:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\extensions> in the current context!
Error: Unable to interpret <[2012.04.30 13:52:40 | 000,003,941 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\searchplugins\gXverNTuDgXvssrJsNTu> in the current context!
Error: Unable to interpret <[2012.07.16 09:12:42 | 000,000,925 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Mozilla\Firefox\Profiles\rfc3p0vw.default\searchplugins\oGjfLssqUoGjVn> in the current context!
Error: Unable to interpret <[2012.07.31 12:45:35 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions> in the current context!
Error: Unable to interpret <[2012.09.16 07:27:35 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll> in the current context!
Error: Unable to interpret <[2012.07.14 02:45:08 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml> in the current context!
Error: Unable to interpret <[2012.09.16 07:27:28 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml> in the current context!
Error: Unable to interpret <[2012.07.14 02:45:08 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml> in the current context!
Error: Unable to interpret <[2012.07.14 02:45:08 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml> in the current context!
Error: Unable to interpret <[2012.07.14 02:45:08 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml> in the current context!
Error: Unable to interpret <[2012.07.14 02:45:07 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <O1 HOSTS File: ([2012.09.19 09:23:53 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts> in the current context!
Error: Unable to interpret <O1 - Hosts: 127.0.0.1       localhost> in the current context!
Error: Unable to interpret <O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)> in the current context!
Error: Unable to interpret <O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)> in the current context!
Error: Unable to interpret <O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [Apoint] C:\Programme\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [AVK Client] C:\Programme\G Data\AVKClient\AVKCl.exe (G Data Software AG)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [IntelWireless] C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [IntelZeroConfig] C:\Programme\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [KASH0PTRCS41496284544875] C:\Programme\Kaseya\0PTRCS41496284544875\KaUsrTsk.exe (Kaseya International Limited)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [NcpBudgetGui] C:\Programme\LANCOM\Advanced VPN Client\NcpBudgetGui.exe (NCP engineering GmbH)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [NcpPopup] C:\Programme\LANCOM\Advanced VPN Client\ncppopup.exe (NCP engineering GmbH)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Programme\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [starter4g] C:\WINDOWS\starter4g.exe (4G Systems GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [1und1Dispatcher] C:\Programme\1und1Softwareaktualisierung\SchedDispatcher.exe (1&1 Mail & Media GmbH)> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [KiesHelper] C:\Programme\Samsung\Kies\KiesHelper.exe (Samsung)> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [KiesPDLR] C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [RocketDock] C:\Programme\RocketDock\RocketDock.exe ()> in the current context!
Error: Unable to interpret <O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\fjtLUyyxEfjsnd (Dropbox, Inc.)> in the current context!
Error: Unable to interpret <O4 - Startup: C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0> in the current context!
Error: Unable to interpret <O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present> in the current context!
Error: Unable to interpret <O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323> in the current context!
Error: Unable to interpret <O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863> in the current context!
Error: Unable to interpret <O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0> in the current context!
Error: Unable to interpret <O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O8 - Extra context menu item: Web-Suche - C:\Programme\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found> in the current context!
Error: Unable to interpret <O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)> in the current context!
Error: Unable to interpret <O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256658069250 (WUWebControl Class)> in the current context!
Error: Unable to interpret <O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)> in the current context!
Error: Unable to interpret <O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)> in the current context!
Error: Unable to interpret <O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)> in the current context!
Error: Unable to interpret <O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ild-group.local> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4693966C-F27A-4969-BADC-BA0232CFA337}: DhcpNameServer = 192.168.178.1> in the current context!
Error: Unable to interpret <O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O24 - Desktop Components:0 () - file:///C:/DOKUME~1/KLAUS~1.JAM/LOKALE~1/Temp/msohtmlclip1/01/clip_image001.gif> in the current context!
Error: Unable to interpret <O24 - Desktop Components:1 (Die derzeitige Homepage) - About:Home> in the current context!
Error: Unable to interpret <O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp> in the current context!
Error: Unable to interpret <O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp> in the current context!
Error: Unable to interpret <O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O32 - HKLM CDRom: AutoRun - 1> in the current context!
Error: Unable to interpret <O32 - AutoRun File - [2009.10.26 18:47:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]> in the current context!
Error: Unable to interpret <O34 - HKLM BootExecute: (autocheck autochk *)> in the current context!
Error: Unable to interpret <O35 - HKLM\..comfile [open] -- "%1" %*> in the current context!
Error: Unable to interpret <O35 - HKLM\..exefile [open] -- "%1" %*> in the current context!
Error: Unable to interpret <O37 - HKLM\...com [@ = ComFile] -- "%1" %*> in the current context!
Error: Unable to interpret <O37 - HKLM\...exe [@ = exefile] -- "%1" %*> in the current context!
Error: Unable to interpret <O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)> in the current context!
Error: Unable to interpret <O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Files/Folders - Created Within 30 Days ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.09.19 10:19:14 | 000,000,000 | ---D | C] -- C:\Programme\ESET> in the current context!
Error: Unable to interpret <[2012.09.19 10:18:37 | 002,322,184 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\esetsmartinstaller_enu.exe> in the current context!
Error: Unable to interpret <[2012.09.19 09:25:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER> in the current context!
Error: Unable to interpret <[2012.09.19 08:12:18 | 004,752,754 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ComboFix.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:35:09 | 000,000,000 | RHSD | C] -- C:\cmdcons> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:08 | 000,000,000 | ---D | C] -- C:\Qoobox> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:05 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Verwaltung> in the current context!
Error: Unable to interpret <[2012.09.19 07:26:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt> in the current context!
Error: Unable to interpret <[2012.09.18 16:19:09 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\aswMBR.exe> in the current context!
Error: Unable to interpret <[2012.09.18 14:51:30 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe> in the current context!
Error: Unable to interpret <[2012.09.14 15:52:23 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox> in the current context!
Error: Unable to interpret <[2012.09.14 15:51:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Eigene Dateien\Neuer Ordner> in the current context!
Error: Unable to interpret <[2012.09.14 14:45:40 | 000,448,816 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\rannohdecryptor.exe> in the current context!
Error: Unable to interpret <[2012.09.13 07:22:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Malwarebytes> in the current context!
Error: Unable to interpret <[2012.09.13 07:22:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware> in the current context!
Error: Unable to interpret <[2012.09.13 07:21:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes> in the current context!
Error: Unable to interpret <[2012.09.13 07:21:56 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys> in the current context!
Error: Unable to interpret <[2012.09.13 07:21:56 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware> in the current context!
Error: Unable to interpret <[2012.09.12 13:11:45 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0> in the current context!
Error: Unable to interpret <[2012.09.04 10:29:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\UseNeXT> in the current context!
Error: Unable to interpret <[2012.09.03 15:22:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\QuickTime> in the current context!
Error: Unable to interpret <[2012.09.03 15:22:23 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime> in the current context!
Error: Unable to interpret <[2012.09.03 10:30:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Apple> in the current context!
Error: Unable to interpret <[2012.08.29 14:39:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\eggebrecht anton safkow> in the current context!
Error: Unable to interpret <[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]> in the current context!
Error: Unable to interpret <[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Files - Modified Within 30 Days ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.09.19 20:45:00 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0FC1045D-8DAD-4D1A-A132-D01B23212E6A}.job> in the current context!
Error: Unable to interpret <[2012.09.19 20:44:00 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A375F577-6969-4115-956F-4E4771D9E2A5}.job> in the current context!
Error: Unable to interpret <[2012.09.19 20:43:02 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{CE0BAAD5-A1CD-49A5-8CAA-0C04D1C52B7F}.job> in the current context!
Error: Unable to interpret <[2012.09.19 20:43:00 | 000,000,416 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0CDD7E22-5E6A-45B2-B31C-8D7446D529A1}.job> in the current context!
Error: Unable to interpret <[2012.09.19 17:56:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job> in the current context!
Error: Unable to interpret <[2012.09.19 12:10:12 | 000,799,585 | ---- | M] () -- C:\WINDOWS\System32\sig.bin> in the current context!
Error: Unable to interpret <[2012.09.19 12:10:12 | 000,044,197 | ---- | M] () -- C:\WINDOWS\System32\nmp.map> in the current context!
Error: Unable to interpret <[2012.09.19 10:18:45 | 002,322,184 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\esetsmartinstaller_enu.exe> in the current context!
Error: Unable to interpret <[2012.09.19 09:23:53 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts> in the current context!
Error: Unable to interpret <[2012.09.19 09:23:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl> in the current context!
Error: Unable to interpret <[2012.09.19 09:21:05 | 000,000,021 | ---- | M] () -- C:\WINDOWS\S.dirmngr> in the current context!
Error: Unable to interpret <[2012.09.19 09:20:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat> in the current context!
Error: Unable to interpret <[2012.09.19 09:20:43 | 3747,573,760 | -HS- | M] () -- C:\hiberfil.sys> in the current context!
Error: Unable to interpret <[2012.09.19 08:12:09 | 004,752,754 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ComboFix.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:35:16 | 000,000,327 | RHS- | M] () -- C:\boot.ini> in the current context!
Error: Unable to interpret <[2012.09.18 16:31:55 | 000,000,512 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\MBR.dat> in the current context!
Error: Unable to interpret <[2012.09.18 14:59:30 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\aswMBR.exe> in the current context!
Error: Unable to interpret <[2012.09.18 14:51:33 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\OTL.exe> in the current context!
Error: Unable to interpret <[2012.09.18 14:49:08 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat> in the current context!
Error: Unable to interpret <[2012.09.18 09:08:55 | 000,001,479 | ---- | M] () -- C:\WINDOWS\System32\.lck> in the current context!
Error: Unable to interpret <[2012.09.18 09:08:54 | 000,019,320 | ---- | M] () -- C:\WINDOWS\System32\.rsp> in the current context!
Error: Unable to interpret <[2012.09.14 15:52:23 | 000,001,031 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox.lnk> in the current context!
Error: Unable to interpret <[2012.09.13 07:22:00 | 000,000,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk> in the current context!
Error: Unable to interpret <[2012.09.12 11:16:26 | 000,448,816 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\rannohdecryptor.exe> in the current context!
Error: Unable to interpret <[2012.09.12 07:59:21 | 000,001,074 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk> in the current context!
Error: Unable to interpret <[2012.09.07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys> in the current context!
Error: Unable to interpret <[2012.09.05 09:15:47 | 000,027,648 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini> in the current context!
Error: Unable to interpret <[2012.09.05 08:50:30 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe> in the current context!
Error: Unable to interpret <[2012.09.05 08:50:29 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl> in the current context!
Error: Unable to interpret <[2012.09.05 07:28:20 | 000,093,696 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\lraJseOXQlrTJJsO> in the current context!
Error: Unable to interpret <[2012.09.05 07:26:53 | 000,550,669 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\DrTvegXQuDNTvegXXQDr> in the current context!
Error: Unable to interpret <[2012.09.04 12:00:30 | 000,001,762 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nitro Pro 7.lnk> in the current context!
Error: Unable to interpret <[2012.09.03 15:22:49 | 000,001,590 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk> in the current context!
Error: Unable to interpret <[2012.09.03 10:30:06 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job> in the current context!
Error: Unable to interpret <[2012.09.03 08:25:12 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLev.DAT> in the current context!
Error: Unable to interpret <[2012.09.03 08:24:18 | 000,000,020 | -H-- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT> in the current context!
Error: Unable to interpret <[2012.08.30 16:35:10 | 000,019,418 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntjjVExydLstjVExy> in the current context!
Error: Unable to interpret <[2012.08.30 16:34:30 | 000,016,896 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydLsAfoxqqdLtAfoGG> in the current context!
Error: Unable to interpret <[2012.08.30 16:33:46 | 000,052,243 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntAAfExqdLstAVExq> in the current context!
Error: Unable to interpret <[2012.08.25 20:31:04 | 000,172,477 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ysnVAxxEUqtLVAAGEU> in the current context!
Error: Unable to interpret <[2012.08.25 20:30:14 | 000,164,793 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\tAfExxydLsjfoExqdLs> in the current context!
Error: Unable to interpret <[2012.08.25 20:29:11 | 000,010,975 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\XODQTTrsJXgDuQaNs> in the current context!
Error: Unable to interpret <[2012.08.25 20:26:23 | 000,106,494 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\geuXXNDJageuuXNDJ> in the current context!
Error: Unable to interpret <[2012.08.25 20:24:24 | 000,188,697 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\toVqxLLUjsofyxxLdj> in the current context!
Error: Unable to interpret <[2012.08.25 20:22:48 | 000,103,164 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\jxEdysnffAGEUys> in the current context!
Error: Unable to interpret <[2012.08.25 20:19:10 | 000,119,223 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\oVqGLLUAsEVyxGLdAto> in the current context!
Error: Unable to interpret <[2012.08.25 20:18:15 | 000,136,189 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\JTOsQXprDvTOsuQX> in the current context!
Error: Unable to interpret <[2012.08.25 20:17:44 | 000,237,939 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\yUntAAVExydnttjVExq> in the current context!
Error: Unable to interpret <[2012.08.25 20:15:34 | 000,138,218 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\LVjxodqttLVjGodqqt> in the current context!
Error: Unable to interpret <[2012.08.25 20:14:23 | 000,003,540 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\ndjtooVqxndAssoVyx> in the current context!
Error: Unable to interpret <[2012.08.25 20:00:32 | 000,001,039 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\AVExxydntAfoEx> in the current context!
Error: Unable to interpret <[2012.08.24 18:31:40 | 000,174,227 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\VqxndjtoVVqGLd> in the current context!
Error: Unable to interpret <[2012.08.24 18:24:25 | 000,816,518 | ---- | M] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\qxLdjttEVqxndjjtoVq> in the current context!
Error: Unable to interpret <[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]> in the current context!
Error: Unable to interpret <[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Files Created - No Company Name ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.09.19 07:35:16 | 000,000,211 | ---- | C] () -- C:\Boot.bak> in the current context!
Error: Unable to interpret <[2012.09.19 07:35:12 | 000,262,448 | RHS- | C] () -- C:\cmldr> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe> in the current context!
Error: Unable to interpret <[2012.09.19 07:27:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe> in the current context!
Error: Unable to interpret <[2012.09.18 16:22:35 | 000,000,512 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\MBR.dat> in the current context!
Error: Unable to interpret <[2012.09.14 15:52:23 | 000,001,031 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Desktop\Dropbox.lnk> in the current context!
Error: Unable to interpret <[2012.09.13 07:41:38 | 000,000,021 | ---- | C] () -- C:\WINDOWS\S.dirmngr> in the current context!
Error: Unable to interpret <[2012.09.13 07:22:00 | 000,000,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk> in the current context!
Error: Unable to interpret <[2012.09.04 12:00:30 | 000,001,762 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nitro Pro 7.lnk> in the current context!
Error: Unable to interpret <[2012.09.04 12:00:28 | 000,001,888 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Nitro Pro 7.lnk> in the current context!
Error: Unable to interpret <[2012.09.04 11:13:29 | 3747,573,760 | -HS- | C] () -- C:\hiberfil.sys> in the current context!
Error: Unable to interpret <[2012.09.03 15:22:49 | 000,001,590 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk> in the current context!
Error: Unable to interpret <[2012.05.13 14:48:27 | 001,005,848 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat> in the current context!
Error: Unable to interpret <[2012.04.03 10:36:28 | 000,009,263 | ---- | C] () -- C:\WINDOWS\System32\UpdateAction_30032012.exe.dmp> in the current context!
Error: Unable to interpret <[2012.03.19 17:14:38 | 000,000,646 | ---- | C] () -- C:\WINDOWS\wiso.ini> in the current context!
Error: Unable to interpret <[2012.02.27 11:45:00 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat> in the current context!
Error: Unable to interpret <[2012.02.15 09:19:54 | 000,559,362 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-2172849378-3237517302-3047019274-1120-0.dat> in the current context!
Error: Unable to interpret <[2012.02.15 07:51:19 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll> in the current context!
Error: Unable to interpret <[2012.02.14 11:24:10 | 000,270,318 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat> in the current context!
Error: Unable to interpret <[2012.01.31 19:15:44 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe> in the current context!
Error: Unable to interpret <[2012.01.31 19:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll> in the current context!
Error: Unable to interpret <[2012.01.31 19:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll> in the current context!
Error: Unable to interpret <[2012.01.31 19:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll> in the current context!
Error: Unable to interpret <[2012.01.31 19:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll> in the current context!
Error: Unable to interpret <[2012.01.02 11:45:50 | 000,000,383 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI> in the current context!
Error: Unable to interpret <[2011.12.13 07:13:27 | 000,000,098 | ---- | C] () -- C:\WINDOWS\WirelessFTP.INI> in the current context!
Error: Unable to interpret <[2011.11.30 06:29:41 | 000,007,494 | ---- | C] () -- C:\WINDOWS\System32\Upd20111125.exe.dmp> in the current context!
Error: Unable to interpret <[2011.11.26 22:17:24 | 000,001,205 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini> in the current context!
Error: Unable to interpret <[2011.11.25 20:24:20 | 000,000,143 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat> in the current context!
Error: Unable to interpret <[2011.11.25 20:12:08 | 000,000,163 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini> in the current context!
Error: Unable to interpret <[2011.11.25 20:11:38 | 000,000,690 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini> in the current context!
Error: Unable to interpret <[2011.11.25 19:56:23 | 000,127,878 | ---- | C] () -- C:\WINDOWS\hpoins11.dat> in the current context!
Error: Unable to interpret <[2011.11.25 19:54:40 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll> in the current context!
Error: Unable to interpret <[2011.11.25 19:53:49 | 000,011,634 | ---- | C] () -- C:\WINDOWS\hpomdl11.dat> in the current context!
Error: Unable to interpret <[2011.11.08 16:12:15 | 000,027,648 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini> in the current context!
Error: Unable to interpret <[2011.11.08 13:11:33 | 000,799,585 | ---- | C] () -- C:\WINDOWS\System32\sig.bin> in the current context!
Error: Unable to interpret <[2011.11.03 07:58:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI> in the current context!
Error: Unable to interpret <[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLev.DAT> in the current context!
Error: Unable to interpret <[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLet.DAT> in the current context!
Error: Unable to interpret <[2011.11.03 07:09:31 | 000,000,020 | -H-- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PKP_DLes.DAT> in the current context!
Error: Unable to interpret <[2011.10.24 09:25:55 | 000,000,094 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft.SqlServer.Compact.351.32.bc> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 001,597,464 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\VAtndqGEEVAtnUq> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,078,022 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\GEUqsnnfAGodqts> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,004,211 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\QDrTJJsOpQDrTaJe> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,003,090 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\GqdLtjjfoxydnttjfo> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,001,601 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JeNTQDDOXJeNauulg> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\uyUaJlAVnsyUEvJ> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TujOXJxyfosjdpp> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\JTNlluXgevaNNDuXgsvaa> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JDNXuegaavlNXueggavlr> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\gsvTrllupgsJTrrl> in the current context!
Error: Unable to interpret <[1601.02.13 10:28:18 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\DuXOeJvaNlupgeeJaNDu> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== ZeroAccess Check ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2009.10.27 16:09:51 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini> in the current context!
Error: Unable to interpret << End of report >


--- --- ---
> in the current context!
 
OTL by OldTimer - Version 3.2.63.0 log created on 09202012_074933


schrauber 20.09.2012 06:58

Du hast en Fehler beim kopieren gemacht, bitte nochmal. Kopiere den Text in der Box, ab :OTL, inklusive dem :

klaus196 20.09.2012 07:51

jetzt hats geklappt...
Code:

All processes killed
========== OTL ==========
C:\Dokumente und Einstellungen\klaus.jama\Startmenü\Programme\Autostart\Dropbox.lnk moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\Dropbox\bin\fjtLUyyxEfjsnd moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\lraJseOXQlrTJJsO moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\DrTvegXQuDNTvegXXQDr moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntjjVExydLstjVExy moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydLsAfoxqqdLtAfoGG moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\ydntAAfExqdLstAVExq moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\ysnVAxxEUqtLVAAGEU moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\tAfExxydLsjfoExqdLs moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\XODQTTrsJXgDuQaNs moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\geuXXNDJageuuXNDJ moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\toVqxLLUjsofyxxLdj moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\jxEdysnffAGEUys moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\oVqGLLUAsEVyxGLdAto moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\JTOsQXprDvTOsuQX moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\yUntAAVExydnttjVExq moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\LVjxodqttLVjGodqqt moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\ndjtooVqxndAssoVyx moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\AVExxydntAfoEx moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Desktop\VqxndjtoVVqGLd moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\VAtndqGEEVAtnUq moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\GEUqsnnfAGodqts moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\QDrTJJsOpQDrTaJe moved successfully.
C:\Dokumente und Einstellungen\All Users\GqdLtjjfoxydnttjfo moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JeNTQDDOXJeNauulg moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\uyUaJlAVnsyUEvJ moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TujOXJxyfosjdpp moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\JTNlluXgevaNNDuXgsvaa moved successfully.
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\JDNXuegaavlNXueggavlr moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\gsvTrllupgsJTrrl moved successfully.
C:\Dokumente und Einstellungen\klaus.jama\Anwendungsdaten\DuXOeJvaNlupgeeJaNDu moved successfully.
C:\WINDOWS\assembly\Desktop.ini moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5537862 bytes
->Flash cache emptied: 456 bytes
 
User: administrator.ILD-GROUP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5537862 bytes
->Flash cache emptied: 456 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: klaus.jama
->Temp folder emptied: 116233 bytes
->Temporary Internet Files folder emptied: 49089783 bytes
->Java cache emptied: 1839819 bytes
->FireFox cache emptied: 125075414 bytes
->Flash cache emptied: 6663 bytes
 
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32969 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
 
User: user
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5537862 bytes
->Flash cache emptied: 291 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2134333 bytes
%systemroot%\System32 .tmp files removed: 2951 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 511 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 186,00 mb
 
 
OTL by OldTimer - Version 3.2.63.0 log created on 09202012_083442

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


schrauber 20.09.2012 07:59

Dann jetzt bitte ein frisches OTL logfile. Wie läuft die Kiste?


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:57 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55