Hallo, 
habe die Farbar Scans ausgeführt, hier das Ergebnis:   
FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-10-2013 
Ran by ralf (administrator) on LAP on 28-10-2013 23:32:26 
Running from C:\Dokumente und Einstellungen\ralf\Eigene Dateien\Downloads XP 
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard 
Internet Explorer Version 6 
Boot Mode: Normal   
==================== Processes (Whitelisted) ===================   
(UPEK Inc.) C:\Programme\Gemeinsame Dateien\Virtual Token\vtserver.exe 
() C:\WINDOWS\system32\ibmpmsvc.exe 
(Microsoft Corporation) C:\WINDOWS\System32\SCardSvr.exe 
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe 
(Lenovo Ltd.) C:\WINDOWS\system32\IPSSVC.EXE 
(Atheros) C:\WINDOWS\system32\acs.exe 
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe 
(B.H.A Corporation) C:\WINDOWS\system32\bgsvcgen.exe 
(Broadcom Corporation.) C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe 
(Diskeeper Corporation) C:\Programme\Diskeeper Corporation\Diskeeper\DkService.exe 
() C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DatacardService\HWDeviceService.exe 
(Lenovo) C:\WINDOWS\System32\QCONSVC.EXE 
(Lenovo.) C:\WINDOWS\System32\TPHDEXLG.EXE 
() C:\WINDOWS\system32\TpKmpSVC.exe 
(IBM) C:\Programme\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe 
() C:\Programme\IBM ThinkVantage\Rescue and Recovery\rrservice.exe 
() C:\Programme\IBM ThinkVantage\Common\Scheduler\tvtsched.exe 
() C:\Programme\ThinkVantage\SystemUpdate\UCLauncherService.exe 
() C:\Programme\IBM ThinkVantage\Common\Logger\logmon.exe 
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe 
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE 
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPLpr.exe 
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPEnh.exe 
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe 
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe 
(Lenovo, Ltd. and IBM Corporation.) C:\WINDOWS\system32\TpShocks.exe 
(Lenovo Group Limited) C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe 
() C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe 
(Lenovo Group Limited) C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe 
(LENOVO) C:\Programme\ThinkVantage\AMSG\Amsg.exe 
(Sonic Solutions) C:\WINDOWS\system32\dla\tfswctrl.exe 
() C:\Programme\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe 
(IBM Corporation) C:\Programme\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe 
(InstallShield Software Corporation) C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe 
(Lenovo Group Limited) C:\Programme\IBM ThinkVantage\Client Security Solution\cssauth.exe 
(Utimaco Safeware AG) C:\Programme\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe 
(Lenovo) C:\Programme\ThinkPad\ConnectUtilities\QCWLICON.EXE 
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe 
(CANON INC.) C:\Programme\Canon\Quick Menu\CNQMMAIN.EXE 
(Lenovo Group Limited) C:\Programme\IBM ThinkVantage\Client Security Solution\pwmgr.exe 
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 
(CANON INC.) C:\Programme\Canon\Quick Menu\CNQMUPDT.EXE 
(CANON INC.) C:\Programme\Canon\Quick Menu\CNQMSWCS.exe 
(CANON INC.) C:\Programme\Canon\My Image Garden\cnmigmain.exe 
(Mozilla Corporation) C:\Programme\Mozilla Thunderbird\thunderbird.exe 
(Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe 
(Mozilla Corporation) C:\Programme\Mozilla Firefox\firefox.exe   
==================== Registry (Whitelisted) ==================   
HKLM\...\Run: [SynTPLpr] - C:\Programme\Synaptics\SynTP\SynTPLpr.exe [110592 2005-08-01] (Synaptics, Inc.) 
HKLM\...\Run: [SynTPEnh] - C:\Programme\Synaptics\SynTP\SynTPEnh.exe [512000 2005-08-01] (Synaptics, Inc.) 
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] () 
HKLM\...\Run: [TpShocks] - C:\WINDOWS\system32\TpShocks.exe [86016 2005-08-22] (Lenovo, Ltd. and IBM Corporation.) 
HKLM\...\Run: [TP4EX] - C:\WINDOWS\system32\TP4EX.exe [40960 2005-08-24] (Lenovo Group Limited) 
HKLM\...\Run: [EZEJMNAP] - C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE [237568 2005-08-31] (Lenovo Group Limited) 
HKLM\...\Run: [TPHOTKEY] - C:\Programme\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe [94208 2005-08-29] () 
HKLM\...\Run: [suScheduler] - C:\Programme\ThinkVantage\SystemUpdate\UCLauncher.exe [40960 2005-08-01] () 
HKLM\...\Run: [LPManager] - C:\Programme\ThinkVantage\PrdCtr\LPMGR.EXE [98304 2005-08-31] (Lenovo Group Limited) 
HKLM\...\Run: [AMSG] - C:\Programme\ThinkVantage\AMSG\Amsg.exe [475136 2005-08-01] (LENOVO) 
HKLM\...\Run: [dla] - C:\WINDOWS\system32\dla\tfswctrl.exe [127037 2005-05-19] (Sonic Solutions) 
HKLM\...\Run: [ISUSPM Startup] - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\ISUSPM.exe [221184 2004-07-27] (InstallShield Software Corporation) 
HKLM\...\Run: [ISUSScheduler] - C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe [81920 2004-07-27] (InstallShield Software Corporation) 
HKLM\...\Run: [cssauth] - C:\Programme\IBM ThinkVantage\Client Security Solution\cssauth.exe [1988144 2005-08-02] (Lenovo Group Limited) 
HKLM\...\Run: [PDService.exe] - C:\Programme\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe [49152 2005-07-07] (Utimaco Safeware AG) 
HKLM\...\Run: [DiskeeperSystray] - C:\Programme\Diskeeper Corporation\Diskeeper\DkIcon.exe [196696 2005-09-26] (Diskeeper Corporation) 
HKLM\...\Run: [QCWLICON] - C:\Programme\ThinkPad\ConnectUtilities\QCWLICON.EXE [86016 2005-08-10] (Lenovo) 
HKLM\...\Run: [PWRMGRTR] - rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor 
HKLM\...\Run: [BLOG] - rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog 
HKLM\...\Run: [TPKMAPHELPER] - C:\Programme\ThinkPad\Utilities\TpKmapAp.exe [864256 2005-08-23] (Lenovo) 
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [681032 2013-09-30] (Avira Operations GmbH & Co. KG) 
HKLM\...\Run: [CanonQuickMenu] - C:\Programme\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.) 
Winlogon\Notify\psfus: C:\Programme\ThinkVantage Fingerprint Software\psfus.dll (UPEK Inc.) 
Winlogon\Notify\QConGina: C:\Windows\system32\QConGina.dll (Lenovo) 
Winlogon\Notify\tpfnf2: C:\Windows\system32\notifyf2.dll () 
Winlogon\Notify\tphotkey: C:\Windows\system32\tphklock.dll () 
HKCU\...\Run: [amsg] - C:\Programme\ThinkVantage\AMSG\Amsg.exe [475136 2005-08-01] (LENOVO) 
HKCU\...\Run: [] - [x] 
MountPoints2: {1c139444-ffe2-11e1-9895-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {1c139446-ffe2-11e1-9895-0014a46b8d5e} - D:\AutoRun.exe 
MountPoints2: {20cc6a52-ff23-11e1-9892-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {20cc6a55-ff23-11e1-9892-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {36397d36-0193-11e2-989f-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {36397d38-0193-11e2-989f-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {4cff0bf6-cae0-11e1-984e-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {4cff0bf9-cae0-11e1-984e-0014a46b8d5e} - E:\AutoRun.exe 
MountPoints2: {6eda8c29-1177-11e3-99a2-0014a46b8d5e} - E:\Startme.exe 
MountPoints2: {c66d0e3c-009d-11e2-989a-0014a46b8d5e} - E:\AutoRun.exe 
HKU\Administrator\...\Run: [amsg] - C:\Programme\ThinkVantage\AMSG\Amsg.exe [ 2005-08-01] (LENOVO) 
HKU\Administrator\...\RunOnce: [configmsi] - C:\Config.Msi [ 2013-10-05] () 
HKU\Administrator\...\RunOnce: [supportdir] - cmd /c "rmdir /q /s "C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\{BF90215F-2D7B-4C84-8A24-A03BC41B95DD}"" 
Lsa: [Notification Packages] scecli csspwntfy   
==================== Internet (Whitelisted) ====================   
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome 
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch 
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home 
SearchScopes: HKLM - DefaultScope value is missing. 
BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx () 
BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions) 
Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) 
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation) 
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1347447074006 
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1347447698318 
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab 
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab 
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation) 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies) 
Winsock: Catalog9 01 C:\Programme\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 02 C:\Programme\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) 
Winsock: Catalog9 25 C:\Programme\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) 
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1   
FireFox: 
======== 
FF ProfilePath: C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default 
FF user.js: detected! => C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\user.js 
FF Homepage: hxxp://www.sueddeutsche.de/ 
FF NetworkProxy: "type", 0 
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () 
FF Plugin: @canon.com/EPPEX - C:\Programme\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.) 
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Programme\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) 
FF Plugin: @nokia.com/EnablerPlugin - C:\Programme\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) 
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Programme\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) 
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF SearchPlugin: C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\searchplugins\11-suche.xml 
FF SearchPlugin: C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\searchplugins\englische-ergebnisse.xml 
FF SearchPlugin: C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\searchplugins\gmx-suche.xml 
FF SearchPlugin: C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\searchplugins\lastminute.xml 
FF SearchPlugin: C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\searchplugins\webde-suche.xml 
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml 
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml 
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml 
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml 
FF Extension: DownloadHelper - C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} 
FF Extension: toolbar_AVIRA-V7 - C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi 
FF Extension: Adblock Plus - C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Mozilla\Firefox\Profiles\5mv5e8c8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi   
Chrome:  
======= 
CHR RestoreOnStartup: "", "https://kunde.comdirect.de/lp/wt/login" 
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} 
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} 
CHR Plugin: (Shockwave Flash) - C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll () 
CHR Plugin: (Shockwave Flash) - C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.76\gcswf32.dll No File 
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll No File 
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer 
CHR Plugin: (Native Client) - C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll () 
CHR Plugin: (Chrome PDF Viewer) - C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.76\pdf.dll () 
CHR Plugin: (Microsoft\u00AE DRM) - C:\Programme\Windows Media Player\npdrmv2.dll (Microsoft Corporation) 
CHR Plugin: (Microsoft\u00AE DRM) - C:\Programme\Windows Media Player\npwmsdrm.dll (Microsoft Corporation) 
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Programme\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.)) 
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Programme\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) 
CHR Plugin: (PDF-XChange Viewer) - C:\Programme\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)   
========================== Services (Whitelisted) =================   
R2 acs; C:\WINDOWS\system32\acs.exe [475220 2009-09-24] (Atheros) 
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [440392 2013-09-30] (Avira Operations GmbH & Co. KG) 
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [440392 2013-09-30] (Avira Operations GmbH & Co. KG) 
R2 AntiVirWebService; C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-09-30] (Avira Operations GmbH & Co. KG) 
R2 bgsvcgen; C:\WINDOWS\system32\bgsvcgen.exe [86016 2005-04-30] (B.H.A Corporation) 
R2 btwdins; C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe [258103 2005-07-21] (Broadcom Corporation.) 
R2 Diskeeper; C:\Programme\Diskeeper Corporation\Diskeeper\DkService.exe [622700 2005-09-27] (Diskeeper Corporation) 
R2 HWDeviceService.exe; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DatacardService\HWDeviceService.exe [271712 2011-03-14] () 
R2 IBMPMSVC; C:\Windows\system32\ibmpmsvc.exe [57344 2005-06-16] () 
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) 
R2 IPSSVC; C:\Windows\system32\IPSSVC.EXE [73728 2005-10-05] (Lenovo Ltd.) 
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [118680 2013-10-04] (Mozilla Foundation) 
R2 QCONSVC; C:\Windows\System32\QCONSVC.EXE [81920 2005-08-10] (Lenovo) 
S3 ServiceLayer; C:\Programme\PC Connectivity Solution\ServiceLayer.exe [732648 2012-12-19] (Nokia) 
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [162408 2013-06-21] (Skype Technologies) 
S3 Sony PC Companion; C:\Programme\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) 
R2 TpKmpSVC; C:\WINDOWS\system32\TpKmpSVC.exe [32768 2005-06-06] () 
R2 TSSCoreService; C:\Programme\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe [722480 2005-08-02] (IBM) 
R2 TVT Backup Service; C:\Programme\IBM ThinkVantage\Rescue and Recovery\rrservice.exe [1372160 2005-08-02] () 
R2 TVT Scheduler; C:\Programme\IBM ThinkVantage\Common\Scheduler\tvtsched.exe [77824 2005-08-02] () 
R2 UCLauncherService; C:\Programme\ThinkVantage\SystemUpdate\UCLauncherService.exe [40960 2005-08-01] () 
R2 vtserver; C:\Programme\Gemeinsame Dateien\Virtual Token\vtserver.exe [40551 2005-07-12] (UPEK Inc.) 
S3 WmcCds; c:\programme\windows media connect\mswmccds.exe [483328 2004-08-10] (Microsoft Corporation) 
S3 WmcCdsLs; C:\Programme\Windows Media Connect\mswmcls.exe [28160 2004-08-10] (Microsoft Corporation) 
S2 Mobile Partner. RunOuc; C:\Programme\Mobile Partner\UpdateDog\ouc.exe [x] 
S3 PsaSrv; C:\WINDOWS\system32\PsaSrv.exe [x]   
==================== Drivers (Whitelisted) ====================   
S4 abp480n5; C:\Windows\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation) 
S3 ac97intc; C:\Windows\System32\drivers\ac97intc.sys [96256 2001-08-17] (Intel Corporation) 
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [17801 2012-07-02] (Meetinghouse Data Communications) 
R1 ANC; C:\Windows\System32\drivers\ANC.SYS [11520 2005-08-10] (IBM Corp.) 
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1347168 2009-04-03] (Atheros Communications, Inc.) 
R3 atmeltpm; C:\Windows\System32\DRIVERS\atmeltpm.sys [15872 2005-02-23] (Atmel, Inc.) 
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-09-30] (Avira Operations GmbH & Co. KG) 
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-09-30] (Avira Operations GmbH & Co. KG) 
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-09-30] (Avira Operations GmbH & Co. KG) 
R3 b57w2k; C:\Windows\System32\DRIVERS\b57xp32.sys [132608 2005-03-17] (Broadcom Corporation) 
R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [1341466 2005-07-21] (Broadcom Corporation.) 
S3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [56648 2005-07-21] (Broadcom Corporation.) 
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [32256 2005-05-10] (B.H.A Corporation) 
R2 drvnddm; C:\Windows\System32\drivers\drvnddm.sys [40544 2005-03-24] (Sonic Solutions) 
R2 EGATHDRV; C:\WINDOWS\SYSTEM32\EGATHDRV.SYS [5427 2013-10-27] (IBM Corporation) 
R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [178048 2005-05-12] (Conexant Systems, Inc.) 
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [1034752 2005-05-12] (Conexant Systems, Inc.) 
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [69504 2010-04-09] (Huawei Technologies Co., Ltd.) 
R3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [1050300 2005-09-09] (Intel Corporation) 
R2 ibmfilter; C:\WINDOWS\system32\drivers\ibmfilter.sys [13184 2005-08-02] (IBM) 
R1 IBMTPCHK; C:\Windows\System32\drivers\IBMBLDID.SYS [2432 2005-08-10] () 
R3 Iviaspi; C:\Windows\System32\drivers\iviaspi.sys [21060 2003-09-10] (InterVideo, Inc.) 
R1 Ndisprot; C:\Windows\System32\DRIVERS\ndisprot.sys [21504 2009-12-17] (Windows (R) 2000 DDK provider) 
S3 PcdrNdisuio; C:\Windows\System32\DRIVERS\pcdrndisuio.sys [12416 2005-02-01] (Windows (R) 2000 DDK provider) 
R3 Pfc; C:\Windows\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) 
R2 pmem; C:\WINDOWS\System32\drivers\pmemnt.sys [7012 2000-05-31] (Microsoft Corporation) 
R2 PrivateDisk; C:\Programme\IBM ThinkVantage\SafeGuard PrivateDisk\PrivateDiskM.sys [46142 2005-06-28] (Utimaco Safeware AG) 
R2 PROCDD; C:\Windows\System32\DRIVERS\PROCDD.SYS [5120 2005-10-05] (Lenovo Ltd.) 
S3 QCNDISIF; C:\Windows\System32\drivers\qcndisif.SYS [12288 2005-08-10] (IBM Corporation.) 
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation) 
R1 ShockMgr; C:\Windows\System32\Drivers\ShockMgr.sys [4736 2005-06-06] (Lenovo.) 
R0 Shockprf; C:\Windows\System32\Drivers\Shockprf.sys [59904 2005-06-06] (Lenovo.) 
R1 Smapint; C:\Windows\System32\drivers\Smapint.sys [14848 2005-08-31] (Microsoft Corporation) 
R2 smi2; C:\Programme\SMI2\smi2.sys [3968 2005-08-02] (IBM Corp.) 
R2 SmiHlp; C:\Programme\ThinkVantage Fingerprint Software\smihlp.sys [3328 2005-07-12] (UPEK Inc.) 
R1 sscdbhk5; C:\Windows\System32\drivers\sscdbhk5.sys [5627 2004-12-02] (Sonic Solutions) 
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-30] (Avira GmbH) 
R1 ssrtln; C:\Windows\System32\drivers\ssrtln.sys [23545 2004-12-02] (Sonic Solutions) 
R1 TDSMAPI; C:\Windows\System32\drivers\TDSMAPI.SYS [9340 2005-08-31] () 
R2 tfsnboio; C:\Windows\System32\dla\tfsnboio.sys [25725 2005-05-19] (Sonic Solutions) 
R2 tfsncofs; C:\Windows\System32\dla\tfsncofs.sys [34845 2005-05-19] (Sonic Solutions) 
R2 tfsndrct; C:\Windows\System32\dla\tfsndrct.sys [4125 2005-05-19] (Sonic Solutions) 
R2 tfsndres; C:\Windows\System32\dla\tfsndres.sys [2273 2005-05-19] (Sonic Solutions) 
R2 tfsnifs; C:\Windows\System32\dla\tfsnifs.sys [86940 2005-05-19] (Sonic Solutions) 
R2 tfsnopio; C:\Windows\System32\dla\tfsnopio.sys [14909 2005-05-19] (Sonic Solutions) 
R2 tfsnpool; C:\Windows\System32\dla\tfsnpool.sys [6365 2005-05-19] (Sonic Solutions) 
R2 tfsnudf; C:\Windows\System32\dla\tfsnudf.sys [98716 2005-05-19] (Sonic Solutions) 
R2 tfsnudfa; C:\Windows\System32\dla\tfsnudfa.sys [100605 2005-05-19] (Sonic Solutions) 
R1 TPHKDRV; C:\Windows\System32\Drivers\TPHKDRV.sys [17699 2005-07-05] (IBM Corporation) 
R1 TPPWRIF; C:\Windows\System32\drivers\Tppwrif.sys [4442 2005-08-31] () 
R1 TSMAPIP; C:\Windows\System32\drivers\TSMAPIP.SYS [7168 2005-08-31] () 
R3 WSIMD; C:\Windows\System32\DRIVERS\wsimd.sys [57408 2008-02-08] (Atheros Communications, Inc.) 
S3 AR5211; system32\DRIVERS\ar5211.sys [x] 
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [117504 2010-03-20] (Huawei Technologies Co., Ltd.) 
S3 massfilter; system32\drivers\massfilter.sys [x] 
S3 massfilter_hs; system32\drivers\massfilter_hs.sys [x] 
S3 PCDRSRVC; system32\drivers\PCDRSRVC.pkms [x] 
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) 
U1 WS2IFSL;  
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x] 
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x] 
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]   
==================== NetSvcs (Whitelisted) ===================     
==================== One Month Created Files and Folders ========   
2013-10-28 23:31 - 2013-10-28 23:31 - 00000000 ____D C:\FRST 
2013-10-27 18:53 - 2013-10-27 18:53 - 00010559 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\hijackthis271013.txt 
2013-10-08 21:07 - 2013-10-08 21:07 - 00001919 _____ C:\WINDOWS\epplauncher.mif 
2013-10-08 20:05 - 2013-08-05 15:00 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 
2013-10-07 09:59 - 2013-10-28 00:02 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat 
2013-10-06 18:47 - 2013-10-06 18:47 - 00090112 _____ C:\WINDOWS\Minidump\Mini100613-02.dmp 
2013-10-06 17:56 - 2013-10-28 00:17 - 00287124 _____ C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-1227714819-2850605812-517804598-1005-0.dat 
2013-10-06 17:56 - 2013-10-28 00:17 - 00126774 _____ C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat 
2013-10-06 15:18 - 2013-10-06 15:19 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJScan 
2013-10-06 14:56 - 2013-10-06 15:00 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMIG 
2013-10-06 14:37 - 2013-10-06 14:37 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJEGV 
2013-10-06 10:42 - 2013-10-06 10:42 - 00090112 _____ C:\WINDOWS\Minidump\Mini100613-01.dmp 
2013-10-06 10:38 - 2013-10-27 18:18 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Canon 
2013-10-06 10:31 - 2013-10-06 10:31 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJFAX 
2013-10-06 10:31 - 2012-05-25 08:21 - 00103936 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BLU.dll 
2013-10-06 10:29 - 2012-09-21 08:33 - 00321024 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BLL.dll 
2013-10-06 10:29 - 2012-05-25 08:20 - 00263168 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BLC.dll 
2013-10-06 10:29 - 2012-05-25 08:20 - 00096768 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BLI.dll 
2013-10-06 10:29 - 2012-05-15 14:58 - 00098048 _____ C:\WINDOWS\system32\CNC176BD.TBL 
2013-10-06 10:29 - 2008-08-25 17:02 - 00015872 _____ (CANON INC.) C:\WINDOWS\system32\CNHMCA.dll 
2013-10-06 10:27 - 2013-10-06 10:27 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon MX920 series Benutzerregistrierung 
2013-10-06 10:26 - 2013-10-06 10:26 - 00001637 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Canon Quick Menu.lnk 
2013-10-06 10:26 - 2013-10-06 10:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJWSpt 
2013-10-06 10:17 - 2013-10-06 10:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon Utilities 
2013-10-06 10:16 - 2013-10-06 10:16 - 00001940 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Canon MX920 series On-Screen-Handbuch.lnk 
2013-10-06 10:16 - 2013-10-06 10:16 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon MX920 series Manual 
2013-10-06 10:15 - 2012-09-21 04:00 - 00258560 _____ (CANON INC.) C:\WINDOWS\system32\CNCALBL.DLL 
2013-10-06 10:15 - 2012-09-20 04:00 - 00315904 _____ (CANON INC.) C:\WINDOWS\system32\CNMLMBL.DLL 
2013-10-05 18:23 - 2013-10-05 18:34 - 00000000 ____D C:\WINDOWS\pss 
2013-10-05 16:55 - 2013-10-05 16:55 - 00000000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\APNSetup2.exe 
2013-10-05 16:55 - 2013-10-05 16:55 - 00000000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\APNSetup.exe 
2013-10-05 16:49 - 2013-10-05 16:49 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Avira 
2013-10-05 16:41 - 2013-10-05 16:41 - 00001682 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk 
2013-10-05 16:40 - 2013-10-05 16:40 - 00000000 ____D C:\Programme\Avira 
2013-10-05 16:40 - 2013-09-30 10:01 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 
2013-10-05 16:40 - 2013-09-30 10:01 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 
2013-10-05 16:40 - 2013-09-30 10:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 
2013-10-05 16:40 - 2013-09-30 10:01 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys 
2013-10-05 15:53 - 2013-10-06 10:15 - 00000000 ___HD C:\Programme\CanonBJ 
2013-10-05 15:53 - 2013-10-05 15:53 - 00000000 ____D C:\WINDOWS\system32\STRING 
2013-10-05 15:52 - 2013-10-06 10:31 - 00000000 ____D C:\Programme\Canon 
2013-10-05 15:52 - 2013-10-05 15:52 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJETV 
2013-10-05 15:00 - 2012-07-31 10:17 - 00366592 _____ (CANON INC.) C:\WINDOWS\system32\CNMNPPM.DLL 
2013-10-05 15:00 - 2012-07-31 10:17 - 00035840 _____ (CANON INC.) C:\WINDOWS\system32\CNMNPUI.DLL 
2013-10-05 14:28 - 2013-10-05 14:28 - 00000000 ____D C:\Programme\Microsoft.NET 
2013-10-04 09:57 - 2013-10-04 09:57 - 00000000 ___RD C:\Dokumente und Einstellungen\ralf\Startmenü\Programme\Verwaltung 
2013-10-04 09:11 - 2013-10-04 09:14 - 00000000 ____D C:\Programme\Mozilla Firefox 
2013-10-03 23:31 - 2013-10-03 23:34 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\Agentur-Berichte+Sonderprojekte 
2013-10-03 23:26 - 2013-10-03 23:28 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\gören2013 
2013-10-02 21:29 - 2013-10-02 21:29 - 00000000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\APNSetup1.exe 
2013-10-02 21:22 - 2013-10-05 16:40 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira 
2013-10-02 17:57 - 2013-10-02 17:57 - 00000758 _____ C:\Dokumente und Einstellungen\ralf\Startmenü\Programme\Internet Explorer.lnk 
2013-10-02 17:49 - 2008-04-14 06:53 - 00073796 ____N (Smart Link) C:\WINDOWS\system32\slserv.exe 
2013-10-02 17:49 - 2008-04-14 06:53 - 00060416 ____N (Microsoft Corporation) C:\WINDOWS\system32\tzchange.exe 
2013-10-02 17:49 - 2008-04-14 06:53 - 00032866 ____N (Smart Link) C:\WINDOWS\system32\slrundll.exe 
2013-10-02 17:49 - 2008-04-14 06:53 - 00032768 ____N (Microsoft Corporation) C:\WINDOWS\system32\setupn.exe 
2013-10-02 17:49 - 2008-04-14 06:53 - 00028672 ____N (Microsoft Corporation) C:\WINDOWS\system32\vidcap.ax 
2013-10-02 17:49 - 2008-04-14 06:53 - 00028672 ____N (Microsoft Corporation) C:\WINDOWS\system32\verclsid.exe 
2013-10-02 17:49 - 2008-04-14 06:53 - 00023040 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ativmvxx.ax 
2013-10-02 17:49 - 2008-04-14 06:53 - 00009728 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ativdaxx.ax 
2013-10-02 17:49 - 2008-04-14 06:52 - 01888992 ____N (ATI Technologies Inc. ) C:\WINDOWS\system32\ati3duag.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 01737856 ____N (Matrox Graphics Inc.) C:\WINDOWS\system32\mtxparhd.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 01306624 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msxml6.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00870784 ____N (ATI Technologies Inc. ) C:\WINDOWS\system32\ati3d1ag.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00712704 ____N (Microsoft Corporation) C:\WINDOWS\system32\windowscodecs.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00651264 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00516768 ____N (ATI Technologies Inc. ) C:\WINDOWS\system32\ativvaxx.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00412160 ____N (Microsoft Corporation) C:\WINDOWS\system32\photometadatahandler.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00397312 ____N (Microsoft Corporation) C:\WINDOWS\system32\mmcex.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00397056 ____N (S3 Graphics, Inc.) C:\WINDOWS\system32\s3gnb.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00377984 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ati2dvaa.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00346112 ____N (Microsoft Corporation) C:\WINDOWS\system32\windowscodecsext.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00294400 ____N (Microsoft Corporation) C:\WINDOWS\system32\qagentrt.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00290304 ____N (Microsoft Corporation) C:\WINDOWS\system32\rhttpaa.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00286792 ____N (Smart Link) C:\WINDOWS\system32\slextspk.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00276992 ____N (Microsoft Corporation) C:\WINDOWS\system32\wmphoto.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00233472 ____N (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00229376 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ati2cqag.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00201728 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ati2dvag.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00198656 ____N (Microsoft Corporation) C:\WINDOWS\system32\napmontr.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00188508 ____N (Smart Link) C:\WINDOWS\system32\slgen.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00184832 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00184320 ____N (Microsoft Corporation) C:\WINDOWS\system32\microsoft.managementconsole.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00182272 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00177664 ____N (Microsoft Corporation) C:\WINDOWS\system32\napstat.exe 
2013-10-02 17:49 - 2008-04-14 06:52 - 00155136 ____N (Microsoft Corporation) C:\WINDOWS\system32\mssha.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00151040 ____N (Microsoft Corporation) C:\WINDOWS\system32\qagent.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00145408 ____N (Microsoft Corporation) C:\WINDOWS\system32\onex.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00136192 ____N (Microsoft Corporation) C:\WINDOWS\system32\aaclient.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00133120 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00126976 ____N (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00106496 ____N (Microsoft Corporation) C:\WINDOWS\system32\mmcfxcommon.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00095232 ____N (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00076800 ____N (Microsoft Corporation) C:\WINDOWS\system32\qutil.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00073832 ____N (Smart Link) C:\WINDOWS\system32\slcoinst.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00069120 ____N (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00062976 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3cfg.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00062464 ____N (Microsoft Corporation) C:\WINDOWS\system32\qcliprov.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00061952 ____N (Microsoft Corporation) C:\WINDOWS\system32\rasqec.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00061440 ____N (Microsoft Corporation) C:\WINDOWS\system32\kmsvc.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00059392 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapqec.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00056832 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00053248 ____N (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00050688 ____N (Microsoft Corporation) C:\WINDOWS\system32\tspkg.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00048640 ____N (Microsoft Corporation) C:\WINDOWS\system32\dhcpqec.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00040960 ____N (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00039936 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3gpclnt.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00039936 ____N (Microsoft Corporation) C:\WINDOWS\system32\dimsroam.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00037376 ____N (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00033792 ____N (Microsoft Corporation) C:\WINDOWS\system32\mmcperf.exe 
2013-10-02 17:49 - 2008-04-14 06:52 - 00033792 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapsvc.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00032768 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ativtmxx.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00032285 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\hsfcisp2.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00030720 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapolqec.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00030208 ____N (Microsoft Corporation) C:\WINDOWS\system32\napipsec.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00026112 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00019456 ____N (Microsoft Corporation) C:\WINDOWS\system32\dimsntfy.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00012800 ____N (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00010752 ____N (Microsoft Corporation) C:\WINDOWS\system32\smtpapi.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00009728 ____N (Microsoft Corporation) C:\WINDOWS\system32\rwnh.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00009216 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3dlg.dll 
2013-10-02 17:49 - 2008-04-14 06:52 - 00007168 ____N (Microsoft Corporation) C:\WINDOWS\system32\bitsprx4.dll 
2013-10-02 17:49 - 2008-04-14 06:50 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdpash.dll 
2013-10-02 17:49 - 2008-04-14 06:50 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdnepr.dll 
2013-10-02 17:49 - 2008-04-14 06:50 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdiultn.dll 
2013-10-02 17:49 - 2008-04-14 06:50 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdbhc.dll 
2013-10-02 17:49 - 2008-04-14 06:27 - 00093184 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msxml6r.dll 
2013-10-02 17:49 - 2008-04-14 06:26 - 00081408 ____N (Microsoft Corporation) C:\WINDOWS\system32\msshavmsg.dll 
2013-10-02 17:49 - 2008-04-13 23:15 - 00046592 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\irbus.sys 
2013-10-02 17:49 - 2008-04-13 23:13 - 00009728 ____N (Microsoft Corporation) C:\WINDOWS\system32\comsdupd.exe 
2013-10-02 17:48 - 2013-10-02 17:48 - 00000000 ____D C:\WINDOWS\system32\de 
2013-10-02 17:48 - 2013-10-02 17:48 - 00000000 ____D C:\WINDOWS\system32\bits 
2013-10-02 17:48 - 2008-04-14 06:53 - 00032866 ____N (Smart Link) C:\WINDOWS\slrundll.exe 
2013-10-02 17:48 - 2008-04-14 06:52 - 00121856 ____N (Microsoft Corporation) C:\WINDOWS\system32\xmllite.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00025471 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv04nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00021183 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv01nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00017279 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv10nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00015423 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\ch7xxnt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00014143 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv06nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00011359 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv02nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00011325 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\vchnt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00004255 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv01nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003967 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv02nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003901 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\siint5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003775 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv11nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003711 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv09nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003647 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv07nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003615 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv05nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:52 - 00003135 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv08nt5.dll 
2013-10-02 17:44 - 2008-04-14 06:24 - 00025856 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys 
2013-10-02 17:44 - 2008-04-14 06:22 - 00273920 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 
2013-10-02 17:44 - 2008-04-14 06:21 - 00701952 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati2mtag.sys 
2013-10-02 17:44 - 2008-04-14 06:21 - 00327168 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati2mtaa.sys 
2013-10-02 17:44 - 2008-04-13 23:21 - 00101120 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys 
2013-10-02 17:44 - 2008-04-13 23:16 - 00121984 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys 
2013-10-02 17:44 - 2008-04-13 23:16 - 00059136 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys 
2013-10-02 17:44 - 2008-04-13 23:16 - 00037888 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthmodem.sys 
2013-10-02 17:44 - 2008-04-13 23:16 - 00036480 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthprint.sys 
2013-10-02 17:44 - 2008-04-13 23:16 - 00018944 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthusb.sys 
2013-10-02 17:44 - 2008-04-13 23:16 - 00017024 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys 
2013-10-02 17:44 - 2008-04-13 23:15 - 00019200 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidir.sys 
2013-10-02 17:44 - 2008-04-13 23:13 - 00014208 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wacompen.sys 
2013-10-02 17:44 - 2008-04-13 23:13 - 00012672 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mutohpen.sys 
2013-10-02 17:44 - 2008-04-13 23:10 - 00010240 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sffp_mmc.sys 
2013-10-02 17:44 - 2008-04-13 23:06 - 00046464 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\gagp30kx.sys 
2013-10-02 17:44 - 2008-04-13 23:06 - 00044672 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uagp35.sys 
2013-10-02 17:44 - 2008-04-13 23:06 - 00005888 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\smbali.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 01309184 ____N (Smart Link) C:\WINDOWS\system32\Drivers\mtlstrm.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 01041536 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\Drivers\hsfdpsp2.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00685056 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\Drivers\hsfcxts2.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00404990 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slntamr.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00220032 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\Drivers\hsfbs2s2.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00180360 ____N (Smart Link) C:\WINDOWS\system32\Drivers\ntmtlfax.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00129535 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slnt7554.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00126686 ____N (Smart Link) C:\WINDOWS\system32\Drivers\mtlmnt5.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00095424 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slnthal.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00013776 ____N (Smart Link) C:\WINDOWS\system32\Drivers\recagent.sys 
2013-10-02 17:44 - 2008-04-13 22:53 - 00013240 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slwdmsup.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00452736 ____N (Matrox Graphics Inc.) C:\WINDOWS\system32\Drivers\mtxparhm.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00166912 ____N (S3 Graphics, Inc.) C:\WINDOWS\system32\Drivers\s3gnbm.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00104960 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinrvxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00073216 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atintuxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00063663 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1rvxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00063488 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinxsxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00057856 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinbtxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00056623 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1btxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00052224 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinraxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00036463 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1tuxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00034735 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1xsxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00031744 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinxbxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00030671 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1raxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00029455 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1xbxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00028672 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinsnxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00026367 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1snxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00025471 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\watv10nt.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00022271 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\watv06nt.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00021343 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1ttxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00014336 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinpdxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00013824 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinttxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00013824 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinmdxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00012047 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1pdxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00011935 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv11nt.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00011871 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv09nt.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00011807 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv07nt.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00011615 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1mdxx.sys 
2013-10-02 17:44 - 2008-04-13 21:04 - 00011295 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv08nt.sys 
2013-10-02 17:44 - 2007-04-02 20:36 - 00129045 ____N C:\WINDOWS\system32\Drivers\cxthsfs2.cty 
2013-10-02 17:43 - 2006-12-28 23:31 - 00019569 _____ C:\WINDOWS\005185_.tmp 
2013-10-02 16:44 - 2013-10-02 16:44 - 00000000 ____D C:\604d5c27ffae41829a 
2013-10-02 16:43 - 2013-10-02 16:43 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira 
2013-10-02 09:21 - 2013-10-02 09:21 - 00000000 ____D C:\Programme\AskPartnerNetwork 
2013-10-02 09:21 - 2013-10-02 09:21 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AskPartnerNetwork   
==================== One Month Modified Files and Folders =======   
2013-10-28 23:31 - 2013-10-28 23:31 - 00000000 ____D C:\FRST 
2013-10-28 23:28 - 2012-07-03 21:40 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Eigene Dateien\Downloads XP 
2013-10-28 23:24 - 2013-04-04 13:22 - 00000000 ____D C:\Programme\Mozilla Thunderbird 
2013-10-28 23:15 - 2004-08-10 12:34 - 00032570 _____ C:\WINDOWS\SchedLgU.Txt 
2013-10-28 23:15 - 2004-08-10 12:34 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 
2013-10-28 22:55 - 2012-07-02 23:02 - 2097152000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\SecureDrive.vol 
2013-10-28 22:53 - 2012-07-02 03:10 - 00000316 _____ C:\WINDOWS\Tasks\PMTask.job 
2013-10-28 22:51 - 2012-07-02 02:53 - 00451968 _____ C:\WINDOWS\system32\TPAPSLOG.LOG 
2013-10-28 22:51 - 2004-08-10 12:25 - 00878397 _____ C:\WINDOWS\WindowsUpdate.log 
2013-10-28 22:50 - 2012-07-02 03:08 - 00000000 _RSHD C:\RRbackups 
2013-10-28 22:41 - 2004-08-10 12:20 - 00000157 _____ C:\WINDOWS\wiadebug.log 
2013-10-28 22:41 - 2004-08-10 12:20 - 00000050 _____ C:\WINDOWS\wiaservc.log 
2013-10-28 22:41 - 1979-12-31 23:00 - 00002278 _____ C:\WINDOWS\system32\wpa.dbl 
2013-10-28 00:17 - 2013-10-06 17:56 - 00287124 _____ C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-1227714819-2850605812-517804598-1005-0.dat 
2013-10-28 00:17 - 2013-10-06 17:56 - 00126774 _____ C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat 
2013-10-28 00:17 - 2012-12-06 16:43 - 00393216 _____ C:\WINDOWS\system32\config\ACS.evt 
2013-10-28 00:17 - 2012-07-02 04:12 - 00000190 ___SH C:\Dokumente und Einstellungen\ralf\ntuser.ini 
2013-10-28 00:17 - 2012-07-02 04:12 - 00000000 ____D C:\Dokumente und Einstellungen\ralf 
2013-10-28 00:02 - 2013-10-07 09:59 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat 
2013-10-27 18:53 - 2013-10-27 18:53 - 00010559 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\hijackthis271013.txt 
2013-10-27 18:21 - 2012-07-02 03:08 - 00000000 ____D C:\IBMSHARE 
2013-10-27 18:18 - 2013-10-06 10:38 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Canon 
2013-10-27 18:16 - 2004-08-10 12:18 - 01007778 _____ C:\WINDOWS\system32\PerfStringBackup.INI 
2013-10-27 18:11 - 2012-07-02 03:08 - 00005427 _____ (IBM Corporation) C:\WINDOWS\system32\EGATHDRV.SYS 
2013-10-08 21:07 - 2013-10-08 21:07 - 00001919 _____ C:\WINDOWS\epplauncher.mif 
2013-10-08 07:13 - 2012-07-03 00:42 - 00097792 _____ C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
2013-10-06 18:47 - 2013-10-06 18:47 - 00090112 _____ C:\WINDOWS\Minidump\Mini100613-02.dmp 
2013-10-06 16:39 - 2013-08-18 00:49 - 00000000 ___RD C:\Dokumente und Einstellungen\ralf\Eigene Dateien\Eigene Bilder 
2013-10-06 15:19 - 2013-10-06 15:18 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJScan 
2013-10-06 15:00 - 2013-10-06 14:56 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJMIG 
2013-10-06 14:37 - 2013-10-06 14:37 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJEGV 
2013-10-06 10:42 - 2013-10-06 10:42 - 00090112 _____ C:\WINDOWS\Minidump\Mini100613-01.dmp 
2013-10-06 10:42 - 2012-08-15 13:33 - 00000000 ____D C:\WINDOWS\Minidump 
2013-10-06 10:31 - 2013-10-06 10:31 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJFAX 
2013-10-06 10:31 - 2013-10-05 15:52 - 00000000 ____D C:\Programme\Canon 
2013-10-06 10:31 - 2013-05-08 22:29 - 00318211 _____ C:\WINDOWS\setupapi.log 
2013-10-06 10:31 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\twain_32 
2013-10-06 10:31 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\Media 
2013-10-06 10:27 - 2013-10-06 10:27 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon MX920 series Benutzerregistrierung 
2013-10-06 10:27 - 2004-08-10 12:17 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü\Programme 
2013-10-06 10:26 - 2013-10-06 10:26 - 00001637 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Canon Quick Menu.lnk 
2013-10-06 10:26 - 2013-10-06 10:26 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJWSpt 
2013-10-06 10:26 - 2013-10-06 10:17 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon Utilities 
2013-10-06 10:16 - 2013-10-06 10:16 - 00001940 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Canon MX920 series On-Screen-Handbuch.lnk 
2013-10-06 10:16 - 2013-10-06 10:16 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Canon MX920 series Manual 
2013-10-06 10:15 - 2013-10-05 15:53 - 00000000 ___HD C:\Programme\CanonBJ 
2013-10-06 09:58 - 2012-07-02 10:32 - 00002483 _____ C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Microsoft Word.lnk 
2013-10-05 21:32 - 2004-08-10 12:34 - 00000000 __SHD C:\Dokumente und Einstellungen\LocalService 
2013-10-05 20:54 - 2012-07-30 11:50 - 00000000 ____D C:\WINDOWS\system32\NtmsData 
2013-10-05 19:45 - 2012-07-02 02:26 - 00000000 ____D C:\WINDOWS\Microsoft.NET 
2013-10-05 18:34 - 2013-10-05 18:23 - 00000000 ____D C:\WINDOWS\pss 
2013-10-05 18:34 - 2001-09-17 12:02 - 00000194 __RSH C:\BOOT.INI 
2013-10-05 18:34 - 1979-12-31 23:00 - 00000603 _____ C:\WINDOWS\win.ini 
2013-10-05 18:34 - 1979-12-31 23:00 - 00000227 _____ C:\WINDOWS\system.ini 
2013-10-05 18:22 - 2004-08-10 12:23 - 00000000 ____D C:\WINDOWS\Registration 
2013-10-05 17:32 - 2013-09-12 18:41 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\9 13 
2013-10-05 17:27 - 2013-03-15 00:08 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\KIRCHHEIM 
2013-10-05 16:55 - 2013-10-05 16:55 - 00000000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\APNSetup2.exe 
2013-10-05 16:55 - 2013-10-05 16:55 - 00000000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\APNSetup.exe 
2013-10-05 16:49 - 2013-10-05 16:49 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\Avira 
2013-10-05 16:41 - 2013-10-05 16:41 - 00001682 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Avira Control Center.lnk 
2013-10-05 16:40 - 2013-10-05 16:40 - 00000000 ____D C:\Programme\Avira 
2013-10-05 16:40 - 2013-10-02 21:22 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira 
2013-10-05 16:40 - 2004-08-10 12:18 - 00000000 ____D C:\Programme 
2013-10-05 15:53 - 2013-10-05 15:53 - 00000000 ____D C:\WINDOWS\system32\STRING 
2013-10-05 15:52 - 2013-10-05 15:52 - 00000000 ___HD C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonIJETV 
2013-10-05 14:28 - 2013-10-05 14:28 - 00000000 ____D C:\Programme\Microsoft.NET 
2013-10-05 13:43 - 2013-04-11 23:55 - 00001206 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1227714819-2850605812-517804598-1005UA.job 
2013-10-05 13:43 - 2013-04-11 23:55 - 00001154 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1227714819-2850605812-517804598-1005Core.job 
2013-10-05 13:42 - 2012-07-04 21:07 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 
2013-10-05 13:30 - 2013-03-10 22:34 - 00000000 ____D C:\Programme\IrfanView 
2013-10-04 20:00 - 2012-07-02 09:21 - 00022288 _____ C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT 
2013-10-04 13:25 - 2013-08-26 23:37 - 00001376 _____ C:\WINDOWS\setupact.log 
2013-10-04 10:51 - 2012-08-13 17:59 - 00000000 ____D C:\Programme\Mozilla Maintenance Service 
2013-10-04 09:57 - 2013-10-04 09:57 - 00000000 ___RD C:\Dokumente und Einstellungen\ralf\Startmenü\Programme\Verwaltung 
2013-10-04 09:57 - 2012-07-02 04:12 - 00000000 ___RD C:\Dokumente und Einstellungen\ralf\Startmenü\Programme 
2013-10-04 09:14 - 2013-10-04 09:11 - 00000000 ____D C:\Programme\Mozilla Firefox 
2013-10-03 23:42 - 2012-07-03 00:36 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\DAZ 
2013-10-03 23:34 - 2013-10-03 23:31 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\Agentur-Berichte+Sonderprojekte 
2013-10-03 23:32 - 2013-07-23 21:52 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\Arzt&Wirtschaft 
2013-10-03 23:31 - 2013-04-16 11:20 - 00063488 ___SH C:\Dokumente und Einstellungen\ralf\Desktop\Thumbs.db 
2013-10-03 23:28 - 2013-10-03 23:26 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Desktop\gören2013 
2013-10-02 21:29 - 2013-10-02 21:29 - 00000000 _____ C:\Dokumente und Einstellungen\ralf\Eigene Dateien\APNSetup1.exe 
2013-10-02 18:09 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\Help 
2013-10-02 17:57 - 2013-10-02 17:57 - 00000758 _____ C:\Dokumente und Einstellungen\ralf\Startmenü\Programme\Internet Explorer.lnk 
2013-10-02 17:57 - 2012-07-02 04:12 - 00000729 _____ C:\Dokumente und Einstellungen\ralf\Startmenü\Programme\Outlook Express.lnk 
2013-10-02 17:57 - 2012-07-02 04:12 - 00000000 ___SD C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Verlauf 
2013-10-02 17:57 - 2012-07-02 04:12 - 00000000 ___RD C:\Dokumente und Einstellungen\ralf\Eigene Dateien\Eigene Musik 
2013-10-02 17:56 - 2013-09-26 18:21 - 00000452 _____ C:\WINDOWS\DtcInstall.log 
2013-10-02 17:56 - 2013-09-26 18:19 - 00000352 _____ C:\WINDOWS\spupdsvc.log.1.log 
2013-10-02 17:56 - 2013-09-26 18:19 - 00000090 _____ C:\WINDOWS\system32\spupdwxp.log 
2013-10-02 17:56 - 2013-09-26 18:09 - 00062946 _____ C:\WINDOWS\spupdsvc.log 
2013-10-02 17:56 - 2013-09-26 17:59 - 00001556 _____ C:\WINDOWS\tabletoc.log 
2013-10-02 17:56 - 2013-09-26 17:56 - 00005250 _____ C:\WINDOWS\medctroc.Log 
2013-10-02 17:56 - 2013-05-09 07:13 - 00008809 _____ C:\WINDOWS\wmsetup.log 
2013-10-02 17:55 - 2004-08-10 12:17 - 00131688 _____ C:\WINDOWS\system32\FNTCACHE.DAT 
2013-10-02 17:53 - 2013-09-26 17:59 - 00012162 _____ C:\WINDOWS\iis6.log 
2013-10-02 17:53 - 2013-09-26 17:59 - 00009400 _____ C:\WINDOWS\tsoc.log 
2013-10-02 17:53 - 2013-09-26 17:59 - 00007126 _____ C:\WINDOWS\comsetup.log 
2013-10-02 17:53 - 2013-09-26 17:59 - 00003792 _____ C:\WINDOWS\ntdtcsetup.log 
2013-10-02 17:53 - 2013-09-26 17:59 - 00002675 _____ C:\WINDOWS\imsins.log 
2013-10-02 17:53 - 2013-09-26 17:59 - 00001006 _____ C:\WINDOWS\ocmsn.log 
2013-10-02 17:53 - 2013-09-26 17:36 - 00952689 _____ C:\WINDOWS\svcpack.log 
2013-10-02 17:51 - 2013-09-26 17:59 - 00024733 _____ C:\WINDOWS\FaxSetup.log 
2013-10-02 17:51 - 2013-09-26 17:59 - 00011642 _____ C:\WINDOWS\ocgen.log 
2013-10-02 17:51 - 2013-09-26 17:59 - 00007378 _____ C:\WINDOWS\msmqinst.log 
2013-10-02 17:51 - 2013-09-26 17:59 - 00003680 _____ C:\WINDOWS\netfxocm.log 
2013-10-02 17:51 - 2013-09-26 17:59 - 00000924 _____ C:\WINDOWS\msgsocm.log 
2013-10-02 17:51 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\security 
2013-10-02 17:50 - 2013-09-26 18:09 - 00000346 _____ C:\WINDOWS\cmsetacl.log 
2013-10-02 17:49 - 2013-09-26 18:09 - 00000622 _____ C:\WINDOWS\sessmgr.setup.log 
2013-10-02 17:49 - 2013-09-26 18:01 - 00192201 _____ C:\WINDOWS\updspapi.log 
2013-10-02 17:49 - 2004-08-10 12:27 - 00001574 _____ C:\Dokumente und Einstellungen\All Users\Startmenü\Programmzugriff und -standards.lnk 
2013-10-02 17:49 - 2004-08-10 12:23 - 00000000 ____D C:\Programme\Messenger 
2013-10-02 17:49 - 2004-08-10 12:22 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Zubehör 
2013-10-02 17:49 - 2004-08-10 12:17 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü 
2013-10-02 17:49 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\system32\inetsrv 
2013-10-02 17:49 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\ime 
2013-10-02 17:48 - 2013-10-02 17:48 - 00000000 ____D C:\WINDOWS\system32\de 
2013-10-02 17:48 - 2013-10-02 17:48 - 00000000 ____D C:\WINDOWS\system32\bits 
2013-10-02 17:48 - 2004-08-10 12:24 - 00000000 ____D C:\Programme\Movie Maker 
2013-10-02 17:48 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\system32\usmt 
2013-10-02 17:48 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\PeerNet 
2013-10-02 17:47 - 2004-08-10 12:24 - 00000000 ____D C:\WINDOWS\system32\Restore 
2013-10-02 17:47 - 2004-08-10 12:24 - 00000000 ____D C:\WINDOWS\srchasst 
2013-10-02 17:47 - 2004-08-10 12:24 - 00000000 ____D C:\Programme\NetMeeting 
2013-10-02 17:47 - 2004-08-10 12:22 - 00000000 ____D C:\WINDOWS\system32\Com 
2013-10-02 17:47 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\system32\npp 
2013-10-02 17:47 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\msagent 
2013-10-02 17:46 - 2004-08-10 12:24 - 00000000 ____D C:\Programme\Outlook Express 
2013-10-02 17:46 - 2004-08-10 12:24 - 00000000 ____D C:\Programme\Gemeinsame Dateien\System 
2013-10-02 17:46 - 2004-08-10 12:22 - 00000000 ____D C:\Programme\Windows NT 
2013-10-02 17:46 - 2004-08-10 12:11 - 00000000 ____D C:\WINDOWS\system 
2013-10-02 17:43 - 2012-07-02 02:33 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups 
2013-10-02 17:42 - 2013-09-26 17:56 - 00000000 __HDC C:\WINDOWS\$NtServicePackUninstall$ 
2013-10-02 17:09 - 2012-07-03 22:08 - 00000900 _____ C:\Dokumente und Einstellungen\ralf\Desktop\Revo Uninstaller.lnk 
2013-10-02 17:09 - 2012-07-03 22:08 - 00000000 ____D C:\Programme\VS Revo Group 
2013-10-02 17:00 - 2013-07-29 16:30 - 00000000 ____D C:\Programme\EPSON 
2013-10-02 17:00 - 2012-07-02 02:31 - 00000000 ___HD C:\Programme\InstallShield Installation Information 
2013-10-02 16:58 - 2012-11-25 15:52 - 00000000 ____D C:\Dokumente und Einstellungen\ralf\Anwendungsdaten\DRPSu 
2013-10-02 16:48 - 2012-07-02 04:10 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\ThinkVantage 
2013-10-02 16:47 - 2004-08-10 12:35 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator 
2013-10-02 16:47 - 2004-08-10 12:34 - 00000000 __SHD C:\Dokumente und Einstellungen\NetworkService 
2013-10-02 16:44 - 2013-10-02 16:44 - 00000000 ____D C:\604d5c27ffae41829a 
2013-10-02 16:43 - 2013-10-02 16:43 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira 
2013-10-02 09:42 - 2013-07-29 16:29 - 00000000 ____D C:\EPSON 
2013-10-02 09:21 - 2013-10-02 09:21 - 00000000 ____D C:\Programme\AskPartnerNetwork 
2013-10-02 09:21 - 2013-10-02 09:21 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AskPartnerNetwork 
2013-09-30 10:01 - 2013-10-05 16:40 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 
2013-09-30 10:01 - 2013-10-05 16:40 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 
2013-09-30 10:01 - 2013-10-05 16:40 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 
2013-09-30 10:01 - 2013-10-05 16:40 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys   
Some content of TEMP: 
==================== 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\APNSetup1.exe 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\AskSLib.dll 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\avgnt.exe 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\card_setup.exe 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\fp_pl_pfs_installer.exe 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\iv_uninstall.exe 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\MSETUP4.EXE 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\NEventMessages.dll 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\NOSEventMessages.dll 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\setup_wm.exe 
C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Temp\uninstall.exe     
==================== Bamital & volsnap Check =================   
C:\Windows\explorer.exe 
[1979-12-31 23:00] - [2008-04-14 06:52] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e    
C:\Windows\System32\winlogon.exe 
[1979-12-31 23:00] - [2008-04-14 06:53] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a    
C:\Windows\System32\svchost.exe 
[1979-12-31 23:00] - [2008-04-14 06:53] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366    
C:\Windows\System32\services.exe 
[1979-12-31 23:00] - [2008-04-14 06:53] - 0109056 ____A (Microsoft Corporation) 4bb6a83640f1d1792ad21ce767b621c6    
C:\Windows\System32\User32.dll 
[1979-12-31 23:00] - [2008-04-14 06:52] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd    
C:\Windows\System32\userinit.exe 
[1979-12-31 23:00] - [2008-04-14 06:53] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106    
C:\Windows\System32\Drivers\volsnap.sys 
[1979-12-31 23:00] - [2008-04-14 06:22] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d      
==================== End Of Log ============================   --- --- ---  
--- --- ---          
und der Addition scan   Code:  
 Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-10-2013 
Ran by ralf at 2013-10-28 23:43:39 
Running from C:\Dokumente und Einstellungen\ralf\Eigene Dateien\Downloads XP 
Boot Mode: Normal 
==========================================================     
==================== Security Center ========================   
AV: Avira Desktop (Disabled - Up to date) {AD166499-45F9-482A-A743-FDD3350758C7} 
Could not list Security Center items. Check WMI.     
==================== Installed Programs ======================   
Access Help (Version: 1.00) 
Adobe Acrobat 5.0 (Version: 5.0) 
Adobe Flash Player 11 Plugin (Version: 11.8.800.168) 
ArcSoft PhotoImpression 
Avira Free Antivirus (Version: 14.0.0.383) 
Canon i250 
Canon IJ Scan Utility 
Canon Kurzwahlprogramm (Version: 1.3.0) 
Canon MX920 series Benutzerregistrierung 
Canon MX920 series MP Drivers (Version: 1.00) 
Canon MX920 series On-screen Manual (Version: 7.6.0) 
Canon My Image Garden (Version: 1.1.0) 
Canon My Image Garden Design Files (Version: 1.0.1) 
Canon My Printer (Version: 3.1.0) 
Canon Quick Menu (Version: 2.1.0) 
CCleaner (Version: 4.00) 
Compatibility Pack für 2007 Office System (Version: 12.0.6514.5001) 
ConvertHelper 2.2 
Dienstprogramm 'ThinkPad-Tastaturanpassung' (Version: 1.3.02.0b) 
Diskeeper Lite (Version: 9.0.533) 
DLA (Version: 4.97) 
EPSON Copy Utility 
EPSON Photo Print 
EPSON TWAIN 5 
Ergänzung zu Productivity Center für ThinkPad (Version: 1.00b) 
Fingerabdruk-Lernprogramm (Version: 5.2.0.2276) 
Funktion "TrackPoint-Eingabehilfen" (Version: 1.10.0.0) 
Google Chrome (HKCU Version: 29.0.1547.76) 
Help Center (Version: 1.00b) 
High Definition Audio - KB888111 (Version: 20040219.000000) 
HUAWEI DataCard Driver 4.05.00.00 (Version: 4.05.00.00) 
IBM 32-bit Runtime Environment for Java 2, v1.4.2 (Version: 1.4.2) 
Intel(R) Graphics Media Accelerator Driver for Mobile (Version: 6.14.10.4391) 
InterVideo WinDVD (Version: 5.0-B11.289) 
InterVideo WinDVD Creator (Version: 2.5.14.503) 
IrfanView (remove only) (Version: 4.35) 
LiveReg (Symantec Corporation) (Version: 2.4.2.2295) 
LiveUpdate 2.6 (Symantec Corporation) (Version: 2.6.18.0) 
Message Center (Version: 1.00b) 
Microsoft .NET Framework 1.1 
Microsoft .NET Framework 1.1 (Version: 1.1.4322) 
Microsoft .NET Framework 1.1 German Language Pack (Version: 1.1.4322) 
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) 
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 
Microsoft Office 2000 Premium (Version: 9.00.2816) 
Microsoft User-Mode Driver Framework Feature Pack 1.9 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) 
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219) 
Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1) 
MotionSD STUDIO 1.1E 
Mozilla Firefox 24.0 (x86 de) (Version: 24.0) 
Mozilla Maintenance Service (Version: 24.0) 
Mozilla Thunderbird 17.0.5 (x86 de) (Version: 17.0.5) 
MSVC80_x86_v2 (Version: 1.0.3.0) 
MSVC90_x86 (Version: 1.0.1.2) 
MSXML 6.0 Parser (Version: 6.10.1129.0) 
Nokia Connectivity Cable Driver (Version: 7.1.101.0) 
Nokia Suite (Version: 3.7.22.0) 
PC Connectivity Solution (Version: 12.0.76.0) 
PC-Doctor for Windows (Version: 1.06.007) 
PDF-Viewer (Version: 2.5.203.0) 
RecordNow Audio (Version: 2.0.1) 
RecordNow Copy (Version: 2.0.1) 
RecordNow Data (Version: 2.0.1) 
Remove Multimedia Center 
Rescue and Recovery - Client Security Solution (Version: 3.00.0027.00) 
Revo Uninstaller 1.95 (Version: 1.95) 
ScanToWeb 
Sicherheitsupdate für Step by Step Interactive Training (KB898458) (Version: 20050502.101010) 
Skype™ 6.6 (Version: 6.6.106) 
Software Installer (Version: 3.13.0507) 
Sonic Express Labeler (Version: 2.0.0) 
Sonic Update Manager (Version: 3.0.0) 
Sony PC Companion 2.10.174 (Version: 2.10.174) 
SoundMAX (Version: 5.10.01.4230) 
System Migration Assistant 5.0 (Version: 5.00.0048) 
ThinkPad 11a/b/g/n Wireless LAN Mini-PCI Express Adapter (Version: 7.6.1.260b) 
ThinkPad Bluetooth with Enhanced Data Rate Software (Version: 4.0.1.2302) 
ThinkPad Energie-Manager (Version: 1.10b) 
ThinkPad FullScreen Magnifier (Version: 1.15) 
ThinkPad Modem (Version: 7.27.00.50) 
ThinkPad PC Card Power Policy (Version: 1.02) 
ThinkPad Power Management Driver (Version: 1.31) 
ThinkPad UltraNav Driver (Version: 7.5.17.17) 
ThinkPad-Dienstprogramm 'EasyEject' (Version: 2.20b) 
ThinkPad-Konfiguration (Version: 1.50b) 
ThinkPad-Präsentationsdirektor (Version: 2.40b) 
ThinkPad-UltraNav-Assistent (Version: 3.02) 
ThinkVantage Access Connections (Version: 3.80b) 
ThinkVantage Away Manager 
ThinkVantage Fingerprint Software 4.6.0 (Version: 4.6.0.1153) 
ThinkVantage Productivity Center (Version: 1.00b) 
ThinkVantage System für aktiven Festplattenschutz (Version: 1.33b) 
ThinkVantage System Update (Version: 1.00.120) 
ThinkVantage Technologies Welcome Message (Version: 1.10b) 
Wallpapers (Version: 2.0) 
WebFldrs XP (Version: 9.50.7523) 
Windows Media Connect 
Windows Media Connect (Version: 1.0.0.0) 
Windows Media Format 11 runtime 
Windows Media Player 10 
Windows XP Service Pack 3 (Version: 20080414.031514) 
Windows-Treiberpaket - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0) 
XP Themes (Version: 1.00.0000)   
==================== Restore Points  =========================   
23-07-2013 21:33:28 Systemprüfpunkt 
25-07-2013 08:48:06 Systemprüfpunkt 
29-07-2013 15:29:47 Installiert EPSON TWAIN 5 
29-07-2013 15:30:20 Installiert Smart Panel 
29-07-2013 15:30:57 Installiert Smart Panel 
29-07-2013 15:31:09 Installiert Applet_Pim 
29-07-2013 15:31:20 Installiert Applet_Pda 
29-07-2013 15:31:31 Installiert Applet_Web 
29-07-2013 15:31:39 Installed ScanToWeb 
29-07-2013 15:31:52 Installiert Applet_Epp 
29-07-2013 15:32:19 Installiert Applet_Creativity 
29-07-2013 15:32:31 Installiert Applet_File 
29-07-2013 15:32:42 Installiert Applet_Copy 
29-07-2013 15:32:50 Installiert EPSON Copy Utility 
29-07-2013 15:33:08 Installiert Applet_Ocr 
29-07-2013 15:33:19 Installiert Applet_Email 
29-07-2013 15:33:30 Installiert Applet_App 
29-07-2013 15:33:41 Installiert Python 
31-07-2013 22:21:18 Systemprüfpunkt 
01-08-2013 22:54:49 Systemprüfpunkt 
06-08-2013 15:01:54 Systemprüfpunkt 
16-08-2013 21:41:00 Systemprüfpunkt 
17-08-2013 22:56:07 Systemprüfpunkt 
29-08-2013 16:14:27 Systemprüfpunkt 
29-08-2013 16:57:29 Sony PC Companion 
02-09-2013 10:50:30 Sony PC Companion 
11-09-2013 17:16:27 Systemprüfpunkt 
13-09-2013 16:24:18 Systemprüfpunkt 
21-09-2013 10:30:01 Systemprüfpunkt 
26-09-2013 11:42:01 Sony PC Companion 
26-09-2013 16:59:54 Windows XP Service Pack 3 wurde installiert. 
02-10-2013 08:49:06 Installed EPSON TWAIN 5 
02-10-2013 09:50:29 Installed EPSON TWAIN 5 
02-10-2013 15:41:24 Wiederherstellungsvorgang 
02-10-2013 15:58:58 Entfernt Python 
02-10-2013 15:59:09 Entfernt Applet_Pim 
02-10-2013 15:59:17 Entfernt Applet_Pda 
02-10-2013 15:59:25 Entfernt Applet_Web 
02-10-2013 15:59:34 Entfernt Applet_Epp 
02-10-2013 15:59:41 Entfernt Applet_Creativity 
02-10-2013 15:59:49 Entfernt Applet_App 
02-10-2013 15:59:57 Entfernt Applet_Copy 
02-10-2013 16:00:05 Entfernt Applet_Ocr 
02-10-2013 16:00:12 Entfernt Applet_Email 
02-10-2013 16:00:20 Entfernt Applet_File 
02-10-2013 16:00:29 Entfernt Smart Panel 
02-10-2013 16:00:43 Entfernt Smart Panel 
02-10-2013 16:10:05 Revo Uninstaller's restore point - Avira AntiVir Personal - Free Antivirus 
02-10-2013 16:43:26 Windows XP Service Pack 3 wurde installiert. 
03-10-2013 22:06:10 Systemprüfpunkt 
04-10-2013 09:35:08 Revo Uninstaller's restore point - Avira Free Antivirus 
04-10-2013 09:39:39 Revo Uninstaller's restore point - Avira Free Antivirus 
04-10-2013 10:01:35 Revo Uninstaller's restore point - Avira Free Antivirus 
05-10-2013 14:23:41 Wiederherstellungsvorgang 
05-10-2013 14:32:35 Wiederherstellungsvorgang 
05-10-2013 14:48:18 Wiederherstellungsvorgang 
05-10-2013 15:17:26 Wiederherstellungsvorgang 
05-10-2013 15:25:01 Wiederherstellungsvorgang 
05-10-2013 15:31:25 Wiederherstellungsvorgang   
==================== Hosts content: ==========================   
1979-12-31 23:00 - 2004-08-04 04:00 - 00000820 ____A C:\WINDOWS\system32\Drivers\etc\hosts 
127.0.0.1       localhost   
==================== Scheduled Tasks (whitelisted) =============   
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1227714819-2850605812-517804598-1005Core.job => C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe 
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1227714819-2850605812-517804598-1005UA.job => C:\Dokumente und Einstellungen\ralf\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe 
Task: C:\WINDOWS\Tasks\PMTask.job => C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE 
Task: C:\WINDOWS\Tasks\Symantec NetDetect.job => C:\Programme\Symantec\LiveUpdate\NDETECT.EXE   
==================== Loaded Modules (whitelisted) =============   
2012-07-02 01:52 - 2005-06-16 21:23 - 00024576 _____ () C:\WINDOWS\system32\tphklock.dll 
2013-10-05 16:40 - 2013-09-30 10:01 - 00394824 _____ () C:\Programme\Avira\AntiVir Desktop\sqlite3.dll 
2012-07-02 01:49 - 2005-10-05 00:00 - 00131072 ____N () C:\Programme\Lenovo\AwayTask\AwayDB.DLL 
2005-08-02 17:58 - 2005-08-02 17:58 - 00671744 ____N () C:\Programme\IBM ThinkVantage\Rescue and Recovery\rr_res.dll 
2005-08-02 18:01 - 2005-08-02 18:01 - 00155648 ____N () C:\Programme\IBM ThinkVantage\Rescue and Recovery\ui.dll 
2005-08-02 18:03 - 2005-08-02 18:03 - 00139264 ____N () C:\Programme\IBM ThinkVantage\Rescue and Recovery\CDRecord.dll 
2005-08-02 18:00 - 2005-08-02 18:00 - 00069632 ____N () C:\Programme\IBM ThinkVantage\Rescue and Recovery\zlib.dll 
2005-08-01 16:32 - 2005-08-01 16:32 - 00147456 ____N () C:\Programme\ThinkVantage\SystemUpdate\UCLauncherCommon.dll 
2012-07-02 03:10 - 2005-08-31 00:10 - 00040960 ____N () C:\Programme\ThinkPad\Utilities\GR\PWRMGRRT.DLL 
2012-07-02 03:10 - 2005-08-31 00:10 - 00073728 ____N () C:\Programme\ThinkPad\Utilities\PWRMGRIF.DLL 
2013-03-10 21:12 - 2001-03-02 12:02 - 00037808 ____N () C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx 
2012-07-02 02:33 - 2005-08-05 20:22 - 00081920 ____N () C:\Programme\ThinkPad\TpShocks\MUI\0407\TpShocks.dll 
2012-07-02 02:50 - 2005-08-31 01:20 - 00057344 ____N () C:\Programme\ThinkPad\Utilities\GR\EZMAPRES.DLL 
2012-07-02 01:52 - 2005-07-12 09:53 - 00208896 ____N () C:\Programme\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll 
2012-07-02 02:58 - 2005-08-31 00:00 - 00057344 ____N () C:\Programme\ThinkVantage\PrdCtr\GR\LPRESMGR.DLL 
2012-07-02 03:09 - 2005-08-08 20:21 - 00057344 ____N () C:\Programme\ThinkPad\ConnectUtilities\Res\GR\QconRes.dll 
2012-07-02 02:58 - 2005-07-20 02:34 - 00126976 ____N () C:\Programme\ThinkVantage\AMSG\AHLPRUNL.dll 
2012-07-02 02:58 - 2005-06-30 02:54 - 00180224 ____N () C:\Programme\ThinkVantage\AMSG\AcpPollingEngine.dll 
2012-07-02 03:09 - 2005-08-10 02:08 - 00114688 ____N () C:\Programme\ThinkPad\ConnectUtilities\atheroswrap.dll 
2012-07-02 03:09 - 2005-08-08 20:21 - 00028672 ____N () C:\Programme\ThinkPad\ConnectUtilities\Res\GR\IconRes.dll 
2013-04-04 13:22 - 2013-04-04 13:22 - 02243480 _____ () C:\Programme\Mozilla Thunderbird\mozjs.dll 
2013-04-04 13:22 - 2013-04-04 13:22 - 00158104 _____ () C:\Programme\Mozilla Thunderbird\NSLDAP32V60.dll 
2013-04-04 13:22 - 2013-04-04 13:22 - 00022424 _____ () C:\Programme\Mozilla Thunderbird\NSLDAPPR32V60.dll 
2013-10-04 09:11 - 2013-10-04 09:12 - 03279768 _____ () C:\Programme\Mozilla Firefox\mozjs.dll   
==================== Alternate Data Streams (whitelisted) =========     
==================== Safe Mode (whitelisted) ===================   
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"   
==================== Faulty Device Manager Devices =============   
Name: 6210 Navigator 
Description: 6210 Navigator 
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} 
Manufacturer: Nokia 
Service: WUDFRd 
Problem: : This device is disabled. (Code 22) 
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.     
==================== Event log errors: =========================   
Application errors: 
================== 
Error: (10/08/2013 09:07:09 PM) (Source: Microsoft Security Client Setup) (User: ) 
Description: HRESULT:0x8004FF0A 
Description:.  0x8004FF0A.   
Error: (10/08/2013 00:19:57 AM) (Source: Application Error) (User: ) 
Description: Fehlgeschlagene Anwendung i_view32.exe, Version 4.3.5.0, fehlgeschlagenes Modul video.dll, Version 4.3.5.0, Fehleradresse 0x000035f3. 
Das medienspezifische Ereignis für [i_view32.exe!ws!] wird verarbeitet.   
Error: (10/06/2013 09:59:10 AM) (Source: Application Hang) (User: ) 
Description: Stillstehende Anwendung WINWORD.EXE, Version 9.0.0.2823, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.   
Error: (10/06/2013 09:26:49 AM) (Source: WmiAdapter) (User: VORDEFINIERT) 
Description: Dienst konnte nicht geöffnet werden.   
Error: (10/06/2013 00:01:12 AM) (Source: WmiAdapter) (User: VORDEFINIERT) 
Description: Dienst konnte nicht geöffnet werden.   
Error: (10/05/2013 06:14:35 PM) (Source: WmiAdapter) (User: VORDEFINIERT) 
Description: Dienst konnte nicht geöffnet werden.   
Error: (10/05/2013 05:13:25 PM) (Source: Application Hang) (User: ) 
Description: Stillstehende Anwendung WINWORD.EXE, Version 9.0.0.2823, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.   
Error: (10/05/2013 03:10:40 PM) (Source: Application Hang) (User: ) 
Description: Stillstehende Anwendung SETUP.exe, Version 2.3.0.50, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.   
Error: (10/04/2013 07:44:48 PM) (Source: Application Hang) (User: ) 
Description: Stillstehende Anwendung WINWORD.EXE, Version 9.0.0.2823, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.   
Error: (10/04/2013 07:43:31 PM) (Source: Application Hang) (User: ) 
Description: Stillstehende Anwendung WINWORD.EXE, Version 9.0.0.2823, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.     
System errors: 
============= 
Error: (10/28/2013 10:41:32 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (10/28/2013 00:03:14 AM) (Source: Service Control Manager) (User: ) 
Description: Zeitüberschreitung (30000 ms) beim Warten auf eine Transaktionsrückmeldung von Dienst stisvc.   
Error: (10/28/2013 00:02:44 AM) (Source: Service Control Manager) (User: ) 
Description: Zeitüberschreitung (30000 ms) beim Warten auf eine Transaktionsrückmeldung von Dienst stisvc.   
Error: (10/27/2013 06:11:03 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (10/10/2013 10:44:32 AM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (10/08/2013 09:31:17 PM) (Source: Service Control Manager) (User: ) 
Description: Dienst "Windows-Bilderfassung (WIA)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.   
Error: (10/08/2013 09:23:12 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (10/08/2013 07:43:38 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (10/08/2013 10:02:48 AM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (10/08/2013 07:07:36 AM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "Mobile Partner. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2     
Microsoft Office Sessions: 
========================= 
Error: (10/08/2013 09:07:09 PM) (Source: Microsoft Security Client Setup)(User: ) 
Description: HRESULT:0x8004FF0A 
Description:.  0x8004FF0A.   
Error: (10/08/2013 00:19:57 AM) (Source: Application Error)(User: ) 
Description: i_view32.exe4.3.5.0video.dll4.3.5.0000035f3   
Error: (10/06/2013 09:59:10 AM) (Source: Application Hang)(User: ) 
Description: WINWORD.EXE9.0.0.2823hungapp0.0.0.000000000   
Error: (10/06/2013 09:26:49 AM) (Source: WmiAdapter)(User: VORDEFINIERT) 
Description:    
Error: (10/06/2013 00:01:12 AM) (Source: WmiAdapter)(User: VORDEFINIERT) 
Description:    
Error: (10/05/2013 06:14:35 PM) (Source: WmiAdapter)(User: VORDEFINIERT) 
Description:    
Error: (10/05/2013 05:13:25 PM) (Source: Application Hang)(User: ) 
Description: WINWORD.EXE9.0.0.2823hungapp0.0.0.000000000   
Error: (10/05/2013 03:10:40 PM) (Source: Application Hang)(User: ) 
Description: SETUP.exe2.3.0.50hungapp0.0.0.000000000   
Error: (10/04/2013 07:44:48 PM) (Source: Application Hang)(User: ) 
Description: WINWORD.EXE9.0.0.2823hungapp0.0.0.000000000   
Error: (10/04/2013 07:43:31 PM) (Source: Application Hang)(User: ) 
Description: WINWORD.EXE9.0.0.2823hungapp0.0.0.000000000     
==================== Memory info ===========================    
Percentage of memory in use: 79% 
Total physical RAM: 1526.36 MB 
Available physical RAM: 311.56 MB 
Total Pagefile: 3422.58 MB 
Available Pagefile: 2054.93 MB 
Total Virtual: 2047.88 MB 
Available Virtual: 1963.8 MB   
==================== Drives ================================   
Drive c: (IBM_PRELOAD) (Fixed) (Total:293.91 GB) (Free:178.73 GB) NTFS ==>[Drive with boot components (Windows XP)] 
Drive d: (com1113_DVD) (CDROM) (Total:5.79 GB) (Free:0 GB) UDF1.02 
Drive r: (Securedrive) (Removable) (Total:1.95 GB) (Free:0.02 GB) NTFS   
==================== MBR & Partition Table ==================   
======================================================== 
Disk: 0 (Size: 298 GB) (Disk ID: CCCDCCCD) 
Partition 1: (Active) - (Size=294 GB) - (Type=07 NTFS) 
Partition 2: (Not Active) - (Size=4 GB) - (Type=12)   
==================== End Of Log ============================      |