Extras.Txt:  
OTL Logfile:   Code:  
 OTL Extras logfile created on: 13.06.2010 14:14:23 - Run 1 
OTL by OldTimer - Version 3.2.6.0     Folder = C:\Dokumente und Einstellungen\Internet\Eigene Dateien\Downloads 
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.6001.18702) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 77,00% Memory free 
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 86,00% Paging File free 
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme 
Drive C: | 244,14 Gb Total Space | 174,14 Gb Free Space | 71,33% Space Free | Partition Type: NTFS 
Drive D: | 687,37 Gb Total Space | 640,51 Gb Free Space | 93,18% Space Free | Partition Type: NTFS 
Drive E: | 5,40 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS 
F: Drive not present or media not loaded 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: COOLER_MASTER 
Current User Name: Niklas 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: All users 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
  
[HKEY_USERS\S-1-5-21-602162358-602609370-839522115-1005\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
  
[HKEY_USERS\S-1-5-21-602162358-602609370-839522115-1006\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
exefile [open] -- "%1" %* 
htmlfile [edit] -- "C:\Programme\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) 
http [open] -- Reg Error: Key error. 
https [open] -- Reg Error: Key error. 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) 
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) 
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"AntiVirusDisableNotify" = 0 
"FirewallDisableNotify" = 0 
"UpdatesDisableNotify" = 0 
"AntiVirusOverride" = 0 
"FirewallOverride" = 0 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] 
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP 
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"EnableFirewall" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] 
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP 
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP 
   ========== Authorized Applications List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] 
"E:\setup\hpznui01.exe" = E:\setup\hpznui01.exe:*:Enabled:hpznui01.exe -- File not found 
"C:\Programme\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Programme\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hposfx08.exe" = C:\Programme\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hposid01.exe" = C:\Programme\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Programme\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard) 
"C:\Programme\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Programme\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Programme\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard) 
"C:\Programme\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Programme\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe -- (Hewlett-Packard Development Co. L.P.) 
"C:\Programme\HP\Digital Imaging\bin\hpofxs08.exe" = C:\Programme\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hpqfxt08.exe" = C:\Programme\HP\Digital Imaging\bin\hpqfxt08.exe:*:Enabled:hpqfxt08.exe -- (TODO: <Company name>) 
"C:\Programme\HP\Digital Imaging\bin\hpqpse.exe" = C:\Programme\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe -- (Hewlett-Packard Development Co. L.P.) 
"C:\Programme\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Programme\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe -- (Hewlett-Packard Development Co. L.P.) 
"C:\Programme\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Programme\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.) 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 
"C:\Programme\Microsoft Office\Office12\ONENOTE.EXE" = C:\Programme\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation) 
"E:\setup\hpznui01.exe" = E:\setup\hpznui01.exe:*:Enabled:hpznui01.exe -- File not found 
"C:\Programme\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Programme\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hposfx08.exe" = C:\Programme\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hposid01.exe" = C:\Programme\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Programme\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard) 
"C:\Programme\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Programme\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Programme\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard) 
"C:\Programme\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Programme\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe -- (Hewlett-Packard Development Co. L.P.) 
"C:\Programme\HP\Digital Imaging\bin\hpofxs08.exe" = C:\Programme\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe -- (Hewlett-Packard Co.) 
"C:\Programme\HP\Digital Imaging\bin\hpqfxt08.exe" = C:\Programme\HP\Digital Imaging\bin\hpqfxt08.exe:*:Enabled:hpqfxt08.exe -- (TODO: <Company name>) 
"C:\Programme\HP\Digital Imaging\bin\hpqpse.exe" = C:\Programme\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe -- (Hewlett-Packard Development Co. L.P.) 
"C:\Programme\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Programme\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe -- (Hewlett-Packard Development Co. L.P.) 
"C:\Programme\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Programme\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.) 
"C:\Dokumente und Einstellungen\Internet\Desktop\Hacking\4Story-Hack.exe" = C:\Dokumente und Einstellungen\Internet\Desktop\Hacking\4Story-Hack.exe:*:Enabled:4Story-Hack -- () 
"D:\EIGENE_Games\Games\BFBC2Updater.exe" = D:\EIGENE_Games\Games\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2 -- File not found 
"D:\EIGENE_Games\Games\Battlefield Bad Company 2\BFBC2Updater.exe" = D:\EIGENE_Games\Games\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2 -- (EA Digital Illusions CE AB) 
"C:\WINDOWS\system\taskmgr.exe" = C:\WINDOWS\system\taskmgr.exe:*:Enabled:Windows -- () 
  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 
"{03A7C57A-B2C8-409b-92E5-524A0DFD0DD3}" = Status 
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu 
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B8.1208.1  
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg 
"{2A329FB6-389D-4396-A974-29656D6864AE}" = MarketResearch 
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm 
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP 
"{38DAE5F5-EC70-4aa5-801B-D11CA0A33B41}" = BPDSoftware 
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2 
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer 
"{4D304678-738E-42a0-931A-2B022F49DEB8}" = TrayApp 
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport 
"{57F60D52-630B-43C5-BD20-176F5CD4EED6}" = bpd_scan 
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008 
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 
"{676981B7-A2D9-49D0-9F4C-03018F131DA9}" = DocProc 
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1 
"{6CC080F1-2E00-41D5-BE47-A3BC784E9DFB}" = BPDSoftware_Ini 
"{6EED4269-588D-45b8-A80C-26A9CA62EE4E}" = HPSSupply 
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update 
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 
"{800E784D-53E3-4948-B491-9E7FA5EACBDC}" = SmartWebPrinting 
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable 
"{83C57C58-FDD7-4d86-BFCC-9D31CC4EFA71}" = 6500_E709n 
"{87A9A9A9-FAB7-4224-9328-0FA2058C0FD5}" = Network 
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (German) 12 
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 
"{9129B46A-51F0-431b-9838-DF7272F3204E}" = ProductContext 
"{92DF2F1B-F63C-4D9A-B3E1-B2D11AE29790}" = Windows Presentation Foundation Language Pack (DEU) 
"{9603DE6D-4567-4b78-B941-849322373DE2}" = SolutionCenter 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{9CCCFD9C-248F-47FE-9496-1680E3E5C163}" = Scan 
"{9D1B99B7-DAD8-440d-B4FB-1915332FBCC2}" = HPProductAssistant 
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox 
"{AC76BA86-7AD7-1031-7B44-A92000000001}" = Adobe Reader 9.2 - Deutsch 
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation 
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 
"{C29C1940-CB85-4F3B-906C-33FEE0E67103}" = DocMgr 
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU 
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU 
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver 
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential 
"{DE13432E-F0C1-4842-A5BA-CC997DA72A70}" = 6500_E709_eDocs 
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility 
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax 
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component 
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver 
"{F185B35D-38E5-4D88-B275-15C8C7FC4357}" = 6500_E709_Help 
"{F2A7F421-1679-48D5-B918-96999014ED53}" = Microsoft .NET Framework 3.0 German Language Pack 
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 
"{F648FD09-7CEA-4257-BC68-A8389189FD51}" = GPBaseService2 
"{F769B78E-FF0E-4db5-95E2-9F4C8D6352FE}" = DeviceDiscovery 
"{FA0F0A01-4631-4161-A6C2-948BF694382E}" = HP Officejet 6500 E709 Series 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin 
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0 
"CHIP Update-Manager_is1" = CHIP Update-Manager 
"DivX Setup.divx.com" = DivX-Setup 
"DualCoreCenter_is1" = DualCoreCenter 
"F-Secure Product 444" = F-Secure Internet Security 2009 
"HOMESTUDENTR" = Microsoft Office Home and Student 2007 
"HP Document Manager" = HP Document Manager 2.0 
"HP Imaging Device Functions" = HP Imaging Device Functions 12.0 
"HP Photosmart Essential" = HP Photosmart Essential 3.5 
"HP Smart Web Printing" = HP Smart Web Printing 
"HP Solution Center & Imaging Support Tools" = HP Solution Center 12.0 
"HPExtendedCapabilities" = HP Customer Participation Program 12.0 
"HPOCR" = OCR Software by I.R.I.S. 12.0 
"ie8" = Windows Internet Explorer 8 
"Microsoft .NET Framework 3.0 German Language Pack" = Microsoft .NET Framework 3.0 German Language Pack 
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU 
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 
"Mozilla Firefox (3.5.6)" = Mozilla Firefox (3.5.6) 
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP 
"NVIDIA Drivers" = NVIDIA Drivers 
"PunkBusterSvc" = PunkBuster Services 
"RealPlayer 12.0" = RealPlayer 
"Shop for HP Supplies" = Shop for HP Supplies 
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 
"TeamSpeak 3 Client" = TeamSpeak 3 Client 
"VLC media player" = VLC media player 1.0.1 
"WIC" = Windows Imaging Component 
"Windows Media Format Runtime" = Windows Media Format 11 runtime 
"Windows Media Player" = Windows Media Player 11 
"Windows XP Service Pack" = Windows XP Service Pack 3 
"WinRAR archiver" = WinRAR 
"WMFDist11" = Windows Media Format 11 runtime 
"wmp11" = Windows Media Player 11 
"World of Warcraft" = World of Warcraft 
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 
   ========== HKEY_USERS Uninstall List ========== 
  
[HKEY_USERS\S-1-5-21-602162358-602609370-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
   ========== HKEY_USERS Uninstall List ========== 
  
[HKEY_USERS\S-1-5-21-602162358-602609370-839522115-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"TeamSpeak 3 Client" = TeamSpeak 3 Client 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 12.06.2010 20:59:09 | Computer Name = COOLER_MASTER | Source = Application Error | ID = 1000 
Description = Fehlgeschlagene Anwendung realplay.exe, Version 12.0.0.658, fehlgeschlagenes 
 Modul rpmn3260.dll, Version 6.0.10.795, Fehleradresse 0x00031651. 
  
Error - 12.06.2010 20:59:09 | Computer Name = COOLER_MASTER | Source = Application Error | ID = 1000 
Description = Fehlgeschlagene Anwendung realplay.exe, Version 12.0.0.658, fehlgeschlagenes 
 Modul rpmn3260.dll, Version 6.0.10.795, Fehleradresse 0x00031651. 
  
Error - 12.06.2010 20:59:38 | Computer Name = COOLER_MASTER | Source = Application Error | ID = 1000 
Description = Fehlgeschlagene Anwendung realplay.exe, Version 12.0.0.658, fehlgeschlagenes 
 Modul rpmn3260.dll, Version 6.0.10.795, Fehleradresse 0x00031651. 
  
Error - 12.06.2010 21:35:31 | Computer Name = COOLER_MASTER | Source = Application Error | ID = 1000 
Description = Fehlgeschlagene Anwendung dualcorecenter.exe, Version 2.0.1.8, fehlgeschlagenes 
 Modul ntdll.dll, Version 5.1.2600.5755, Fehleradresse 0x0000100b. 
  
Error - 12.06.2010 22:28:37 | Computer Name = COOLER_MASTER | Source = MsiInstaller | ID = 1013 
Description = Programm: Kaspersky Anti-Virus 2011 -- Für die Installation der Komponente 
 sind ausreichende Rechte für die Arbeit mit der Systemregistrierung erforderlich. 
  
Error - 12.06.2010 22:50:21 | Computer Name = COOLER_MASTER | Source = Application Error | ID = 1000 
Description = Fehlgeschlagene Anwendung realplay.exe, Version 12.0.0.756, fehlgeschlagenes 
 Modul rpap3260.dll, Version 6.0.14.1672, Fehleradresse 0x00011deb. 
  
[ System Events ] 
Error - 12.06.2010 21:06:54 | Computer Name = COOLER_MASTER | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: 
   %%126 
  
Error - 12.06.2010 21:06:54 | Computer Name = COOLER_MASTER | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: 
   %%126 
  
Error - 12.06.2010 21:06:54 | Computer Name = COOLER_MASTER | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: 
   %%126 
  
Error - 12.06.2010 21:06:54 | Computer Name = COOLER_MASTER | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: 
   %%126 
  
Error - 12.06.2010 21:06:55 | Computer Name = COOLER_MASTER | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: 
   %%126 
  
Error - 12.06.2010 21:06:55 | Computer Name = COOLER_MASTER | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Anwendungsverwaltung" wurde mit folgendem Fehler beendet: 
   %%126 
  
Error - 13.06.2010 08:07:05 | Computer Name = COOLER_MASTER | Source = Dhcp | ID = 1002 
Description = Die IP-Adresslease 192.168.1.102 für die Netzwerkkarte mit der Netzwerkadresse 
 00241D22AA11 wurde durch  den DHCP-Server 192.168.1.1 abgelehnt (der DHCP-Server  
hat eine DHCPNACK-Meldung gesendet). 
  
Error - 13.06.2010 08:07:38 | Computer Name = COOLER_MASTER | Source = NetBT | ID = 4321 
Description = Der Name "MSHEIMNETZ     :1d" konnte nicht auf der Schnittstelle mit 
 IP-Adresse 192.168.1.101  registriert werden. Der Computer mit IP-Adresse 192.168.1.100 
 hat nicht  zugelassen, dass dieser Computer diesen Namen verwendet. 
  
Error - 13.06.2010 08:09:37 | Computer Name = COOLER_MASTER | Source = NetBT | ID = 4321 
Description = Der Name "MSHEIMNETZ     :1d" konnte nicht auf der Schnittstelle mit 
 IP-Adresse 192.168.1.101  registriert werden. Der Computer mit IP-Adresse 192.168.1.100 
 hat nicht  zugelassen, dass dieser Computer diesen Namen verwendet. 
  
Error - 13.06.2010 08:14:47 | Computer Name = COOLER_MASTER | Source = NetBT | ID = 4321 
Description = Der Name "MSHEIMNETZ     :1d" konnte nicht auf der Schnittstelle mit 
 IP-Adresse 192.168.1.101  registriert werden. Der Computer mit IP-Adresse 192.168.1.100 
 hat nicht  zugelassen, dass dieser Computer diesen Namen verwendet. 
  
  
< End of report >   --- --- ---    
OTL.Txt:  
OTL Logfile:   Code:  
 OTL logfile created on: 13.06.2010 14:14:23 - Run 1 
OTL by OldTimer - Version 3.2.6.0     Folder = C:\Dokumente und Einstellungen\Internet\Eigene Dateien\Downloads 
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.6001.18702) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 77,00% Memory free 
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 86,00% Paging File free 
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme 
Drive C: | 244,14 Gb Total Space | 174,14 Gb Free Space | 71,33% Space Free | Partition Type: NTFS 
Drive D: | 687,37 Gb Total Space | 640,51 Gb Free Space | 93,18% Space Free | Partition Type: NTFS 
Drive E: | 5,40 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS 
F: Drive not present or media not loaded 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: COOLER_MASTER 
Current User Name: Niklas 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: All users 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Dokumente und Einstellungen\Internet\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools) 
PRC - C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.) 
PRC - C:\Dokumente und Einstellungen\Internet\Lokale Einstellungen\Temp\Ide.exe () 
PRC - C:\Dokumente und Einstellungen\Internet\Lokale Einstellungen\Temp\Idd.exe () 
PRC - C:\Programme\F-Secure Internet Security\Anti-Virus\fssm32.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Anti-Virus\fsgk32.exe (F-Secure Corporation) 
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
PRC - C:\Programme\Gigabyte\EasySaver\essvr.exe () 
PRC - C:\Programme\F-Secure Internet Security\FSAUA\program\fsus.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\ORSP Client\fsorsp.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\FSPC\fspc.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Common\FSMB32.EXE (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Common\FSMA32.EXE (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Common\FSM32.EXE (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Common\FAMEH32.EXE (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Common\FCH32.EXE (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\FSGUI\scanwizard.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\FSGUI\fsguidll.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\FWES\program\fsdfwd.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Anti-Virus\fsqh.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\Anti-Virus\fsav32.exe (F-Secure Corporation) 
PRC - C:\Programme\F-Secure Internet Security\FSAUA\program\fsaua.exe (F-Secure Corporation) 
PRC - C:\Programme\MSI\DualCoreCenter\DualCoreCenter.exe () 
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) 
PRC - C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) 
  
   ========== Modules (SafeList) ========== 
  
MOD - C:\Dokumente und Einstellungen\Internet\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools) 
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software GmbH) 
SRV - (ES lite Service) -- C:\Programme\Gigabyte\EasySaver\ESSVR.EXE () 
SRV - (FSORSPClient) -- C:\Programme\F-Secure Internet Security\ORSP Client\fsorsp.exe (F-Secure Corporation) 
SRV - (FSMA) -- C:\Programme\F-Secure Internet Security\Common\FSMA32.EXE (F-Secure Corporation) 
SRV - (FSDFWD) -- C:\Programme\F-Secure Internet Security\FWES\Program\fsdfwd.exe (F-Secure Corporation) 
SRV - (F-Secure Gatekeeper Handler Starter) -- C:\Programme\F-Secure Internet Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation) 
SRV - (FSAUA) -- C:\Programme\F-Secure Internet Security\FSAUA\program\fsaua.exe (F-Secure Corporation) 
SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH) 
SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) 
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows (R) 2000 DDK provider) 
DRV - (PnkBstrK) -- C:\WINDOWS\system32\drivers\PnkBstrK.sys () 
DRV - (F-Secure Gatekeeper) -- C:\Programme\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys () 
DRV - (fsbts) -- C:\WINDOWS\system32\Drivers\fsbts.sys () 
DRV - (IlvMoneyDRIVER53) -- C:\Dokumente und Einstellungen\Internet\Desktop\Moonlight Engine\MLE1365.sys () 
DRV - (MSICPL) -- C:\WINDOWS\system32\msicpl.dll (MSI) 
DRV - (F-Secure HIPS) -- C:\Programme\F-Secure Internet Security\HIPS\drivers\fshs.sys (F-Secure Corporation) 
DRV - (FSFW) -- C:\WINDOWS\System32\drivers\fsdfw.sys (F-Secure Corporation) 
DRV - (F-Secure Filter) -- C:\Programme\F-Secure Internet Security\Anti-Virus\win2k\fsfilter.sys () 
DRV - (F-Secure Recognizer) -- C:\Programme\F-Secure Internet Security\Anti-Virus\win2k\fsrec.sys () 
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation) 
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) 
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation                           ) 
DRV - (DualCoreCenter) -- C:\Programme\MSI\DualCoreCenter\NTGLM7X.sys (MICRO-STAR INT'L CO., LTD.) 
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows (R) Server 2003 DDK provider) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
  
  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-21-602162358-602609370-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-21-602162358-602609370-839522115-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
   ========== FireFox ========== 
  
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4 
FF - prefs.js..extensions.enabledItems: martin@hoerandl.com:2.1 
  
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Programme\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2010.02.17 18:32:10 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.06.13 03:11:43 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.06.13 03:11:38 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.06.13 03:11:47 | 000,000,000 | ---D | M] 
  
[2009.12.24 21:42:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\Mozilla\Extensions 
[2010.03.18 16:24:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\Mozilla\Firefox\Profiles\iaaf4w2c.default\extensions 
[2009.12.26 16:25:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\Mozilla\Firefox\Profiles\iaaf4w2c.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} 
[2009.12.26 16:57:02 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\Mozilla\Firefox\Profiles\iaaf4w2c.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} 
[2009.12.26 16:56:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\Mozilla\Firefox\Profiles\iaaf4w2c.default\extensions\martin@hoerandl.com 
[2010.03.18 16:25:22 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions 
[2009.11.03 04:14:39 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml 
[2009.11.03 04:14:39 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml 
[2009.11.03 04:14:39 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml 
[2009.11.03 04:14:39 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml 
[2009.11.03 04:14:39 | 000,000,801 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml 
  
O1 HOSTS File: ([2003.04.02 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts 
O1 - Hosts: 127.0.0.1       localhost 
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) 
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) 
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) 
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) 
O4 - HKLM..\Run: [aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa]  File not found 
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) 
O4 - HKLM..\Run: [DelReg] C:\Programme\MSI\DualCoreCenter\DelReg.exe () 
O4 - HKLM..\Run: [F-Secure Manager] C:\Programme\F-Secure Internet Security\Common\FSM32.EXE (F-Secure Corporation) 
O4 - HKLM..\Run: [F-Secure TNB] C:\Programme\F-Secure Internet Security\FSGUI\TNBUtil.exe (F-Secure Corporation) 
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) 
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) 
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () 
O4 - HKLM..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe (RealNetworks, Inc.) 
O4 - HKLM..\Run: [Windows] C:\WINDOWS\system\taskmgr.exe () 
O4 - HKU\S-1-5-21-602162358-602609370-839522115-1006..\Run: [M5T8QL3YW3] C:\Dokumente und Einstellungen\Internet\Lokale Einstellungen\Temp\Ide.exe () 
O4 - HKU\S-1-5-21-602162358-602609370-839522115-1006..\Run: [V71IQL7HI7] C:\Dokumente und Einstellungen\Internet\Lokale Einstellungen\Temp\Idd.exe () 
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\DualCoreCenter.lnk = C:\Programme\MSI\DualCoreCenter\StartUpDualCoreCenter.exe () 
O4 - Startup: C:\Dokumente und Einstellungen\Internet\Startmenü\Programme\Autostart\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-21-602162358-602609370-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-21-602162358-602609370-839522115-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) 
O9 - Extra Button: Erwachsene... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\F-Secure Internet Security\FSPC\fspcmsie.dll (F-Secure Corporation) 
O9 - Extra 'Tools' menuitem : Erwachsene... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\F-Secure Internet Security\FSPC\fspcmsie.dll (F-Secure Corporation) 
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) 
O9 - Extra Button: HP Intelligente Auswahl - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programme\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\F-Secure Internet Security\FSPS\program\FSLSP.DLL (F-Secure Corporation) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\F-Secure Internet Security\FSPS\program\FSLSP.DLL (F-Secure Corporation) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Programme\F-Secure Internet Security\FSPS\program\FSLSP.DLL (F-Secure Corporation) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Programme\F-Secure Internet Security\FSPS\program\FSLSP.DLL (F-Secure Corporation) 
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} hxxp://download.gigabyte.com.tw/object/Dldrv.ocx (Dldrv2 Control) 
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 83.169.184.161 83.169.184.225 
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) 
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies) 
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) 
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home 
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp 
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp 
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation) 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2009.12.24 17:16:22 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] 
O32 - AutoRun File - [2010.02.10 03:55:59 | 000,423,304 | R--- | M] (Electronic Arts) - E:\AutoRun.exe -- [ CDFS ] 
O32 - AutoRun File - [2010.02.10 08:21:09 | 000,000,000 | R--D | M] - E:\Autorun -- [ CDFS ] 
O32 - AutoRun File - [2010.01.31 10:21:13 | 000,367,686 | R--- | M] () - E:\Autorun.ico -- [ CDFS ] 
O32 - AutoRun File - [2010.02.10 04:55:03 | 009,965,568 | R--- | M] () - E:\autorun.dat -- [ CDFS ] 
O32 - AutoRun File - [2010.02.10 04:54:55 | 000,000,155 | R--- | M] () - E:\autorun.inf -- [ CDFS ] 
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
  
NetSvcs: 6to4 -  File not found 
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009.12.24 17:59:26 | 000,000,000 | ---D | M] 
NetSvcs: Iprip -  File not found 
NetSvcs: Irmon -  File not found 
NetSvcs: NWCWorkstation -  File not found 
NetSvcs: Nwsapagent -  File not found 
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH) 
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation) 
NetSvcs: WmdmPmSp -  File not found 
  
  
SafeBootMin: Base - Driver Group 
SafeBootMin: Boot Bus Extender - Driver Group 
SafeBootMin: Boot file system - Driver Group 
SafeBootMin: File system - Driver Group 
SafeBootMin: Filter - Driver Group 
SafeBootMin: PCI Configuration - Driver Group 
SafeBootMin: PNP Filter - Driver Group 
SafeBootMin: Primary disk - Driver Group 
SafeBootMin: SCSI Class - Driver Group 
SafeBootMin: sermouse.sys - Driver 
SafeBootMin: System Bus Extender - Driver Group 
SafeBootMin: vds - Service 
SafeBootMin: vga.sys - Driver 
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
  
SafeBootNet: Base - Driver Group 
SafeBootNet: Boot Bus Extender - Driver Group 
SafeBootNet: Boot file system - Driver Group 
SafeBootNet: File system - Driver Group 
SafeBootNet: Filter - Driver Group 
SafeBootNet: NDIS Wrapper - Driver Group 
SafeBootNet: NetBIOSGroup - Driver Group 
SafeBootNet: NetDDEGroup - Driver Group 
SafeBootNet: Network - Driver Group 
SafeBootNet: NetworkProvider - Driver Group 
SafeBootNet: PCI Configuration - Driver Group 
SafeBootNet: PNP Filter - Driver Group 
SafeBootNet: PNP_TDI - Driver Group 
SafeBootNet: Primary disk - Driver Group 
SafeBootNet: SCSI Class - Driver Group 
SafeBootNet: sermouse.sys - Driver 
SafeBootNet: Streams Drivers - Driver Group 
SafeBootNet: System Bus Extender - Driver Group 
SafeBootNet: TDI - Driver Group 
SafeBootNet: UploadMgr - Service 
SafeBootNet: vga.sys - Driver 
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
  
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML) 
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation 
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java 
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe 
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring 
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install 
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT 
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes 
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser 
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW 
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework 
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders 
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install 
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings 
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install 
ActiveX: {9309DD7E-EBFE-3C95-8B47-30D3A012F606} - .NET Framework 
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework 
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework 
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework 
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner 
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player 
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate 
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe 
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP 
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig 
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP 
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP 
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE 
ActiveX: Microsoft Base Smart Card Crypto Provider Package -  
  
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation) 
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) 
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) 
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) 
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () 
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () 
  
CREATERESTOREPOINT 
Restore point Set: OTL Restore Point (16902109354000384) 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2010.06.13 04:28:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files 
[2010.06.13 03:18:35 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8 
[2010.06.13 03:11:37 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll 
[2010.06.13 03:11:20 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll 
[2010.06.13 03:11:20 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll 
[2010.06.13 03:11:13 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\xing shared 
[2010.06.13 03:10:40 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll 
[2010.06.10 12:10:23 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll 
[2010.05.26 00:28:51 | 000,000,000 | ---D | C] -- C:\Programme\thriXXX 
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] 
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] 
   ========== Files - Modified Within 30 Days ========== 
  
[2010.06.13 14:13:00 | 000,000,294 | -H-- | M] () -- C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job 
[2010.06.13 14:11:21 | 000,480,422 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat 
[2010.06.13 14:11:21 | 000,439,484 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat 
[2010.06.13 14:11:21 | 000,092,960 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat 
[2010.06.13 14:11:21 | 000,070,556 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat 
[2010.06.13 14:11:20 | 001,099,556 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI 
[2010.06.13 14:10:17 | 000,000,294 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job 
[2010.06.13 14:10:09 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-602162358-602609370-839522115-1006.job 
[2010.06.13 14:10:08 | 000,201,026 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml 
[2010.06.13 14:10:06 | 000,000,492 | ---- | M] () -- C:\WINDOWS\tasks\1-Klick-Wartung.job 
[2010.06.13 14:10:06 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-602162358-602609370-839522115-1005.job 
[2010.06.13 14:07:16 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys 
[2010.06.13 14:07:09 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT 
[2010.06.13 14:07:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat 
[2010.06.13 14:07:02 | 3488,075,776 | -HS- | M] () -- C:\hiberfil.sys 
[2010.06.13 04:51:08 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-602162358-602609370-839522115-1006.job 
[2010.06.13 04:30:09 | 002,621,440 | -H-- | M] () -- C:\Dokumente und Einstellungen\Niklas\NTUSER.DAT 
[2010.06.13 04:30:09 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\Niklas\ntuser.ini 
[2010.06.13 03:33:57 | 003,776,216 | -H-- | M] () -- C:\Dokumente und Einstellungen\Niklas\Lokale Einstellungen\Anwendungsdaten\IconCache.db 
[2010.06.13 03:33:51 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-602162358-602609370-839522115-1005.job 
[2010.06.13 03:20:26 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK 
[2010.06.13 03:11:37 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll 
[2010.06.13 03:11:20 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll 
[2010.06.13 03:11:20 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll 
[2010.06.13 03:10:40 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll 
[2010.06.13 03:10:40 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll 
[2010.06.13 03:10:40 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll 
[2010.06.12 23:30:04 | 000,218,808 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr 
[2010.06.12 22:44:43 | 000,137,256 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys 
[2010.06.12 15:36:23 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl 
[2010.06.10 15:56:34 | 000,148,400 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT 
[2010.06.10 15:35:33 | 000,138,056 | ---- | M] () -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\PnkBstrK.sys 
[2010.06.10 15:35:06 | 002,434,856 | ---- | M] () -- C:\WINDOWS\System32\pbsvc_bc2.exe 
[2010.06.10 15:34:21 | 000,001,700 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Battlefield Bad Company 2.lnk 
[2010.05.14 16:04:05 | 000,028,272 | ---- | M] () -- C:\Dokumente und Einstellungen\Niklas\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT 
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] 
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] 
   ========== Files Created - No Company Name ========== 
  
[2010.06.10 15:34:21 | 000,001,700 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Battlefield Bad Company 2.lnk 
[2010.06.08 16:16:13 | 000,000,294 | -H-- | C] () -- C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job 
[2010.06.08 16:16:11 | 000,000,294 | -H-- | C] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job 
[2010.04.03 19:36:54 | 000,137,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys 
[2009.12.25 18:31:36 | 000,033,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\fsbts.sys 
[2009.12.24 18:09:46 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll 
[2009.12.24 17:56:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\msicpl.ini 
[2009.12.24 17:51:52 | 000,131,072 | R--- | C] () -- C:\WINDOWS\System32\smdll.dll 
[2009.12.24 17:51:51 | 000,032,768 | R--- | C] () -- C:\WINDOWS\System32\Auxiliary.dll 
[2008.10.07 07:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll 
[2008.10.07 07:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll 
[2008.10.07 07:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll 
[2008.10.07 07:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll 
[2008.10.07 07:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll 
[2008.05.26 23:23:36 | 000,016,834 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini 
[2008.05.26 23:23:34 | 000,024,188 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini 
[2008.05.26 23:23:32 | 000,016,568 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini 
   ========== LOP Check ========== 
  
[2009.12.25 18:24:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\f-secure 
[2009.12.25 18:23:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\fssg 
[2009.12.25 17:58:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software 
[2010.05.05 13:44:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ubisoft 
[2010.01.01 14:40:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Internet\Anwendungsdaten\F-Secure 
[2010.05.04 14:01:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Internet\Anwendungsdaten\TS3Client 
[2009.12.26 16:09:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Internet\Anwendungsdaten\TuneUp Software 
[2010.05.05 13:44:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Internet\Anwendungsdaten\Ubisoft 
[2010.05.06 12:25:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Internet\Anwendungsdaten\Windows Desktop Search 
[2010.01.21 14:16:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Internet\Anwendungsdaten\Windows Search 
[2010.02.02 17:28:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\gtk-2.0 
[2010.05.04 14:24:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\TS3Client 
[2009.12.26 17:18:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\TuneUp Software 
[2010.05.04 14:18:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Niklas\Anwendungsdaten\Windows Search 
[2010.06.13 14:10:06 | 000,000,492 | ---- | M] () -- C:\WINDOWS\Tasks\1-Klick-Wartung.job 
[2010.06.13 14:10:17 | 000,000,294 | -H-- | M] () -- C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job 
[2010.06.13 14:13:00 | 000,000,294 | -H-- | M] () -- C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job 
   ========== Purity Check ========== 
  
  
   ========== Custom Scans ========== 
  
   < %ALLUSERSPROFILE%\Application Data\*. > 
   < %ALLUSERSPROFILE%\Application Data\*.exe /s > 
  
Invalid Environment Variable: APPDATA 
  
Invalid Environment Variable: APPDATA 
   < %SYSTEMDRIVE%\*.exe > 
  
   < MD5 for: AGP440.SYS  > 
[2004.08.04 02:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys 
[2008.04.14 09:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys 
[2004.08.04 02:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys 
[2008.04.14 09:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys 
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys 
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys 
[2004.08.04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys 
   < MD5 for: ATAPI.SYS  > 
[2003.04.02 14:00:00 | 010,180,476 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys 
[2004.08.04 02:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys 
[2008.04.14 09:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys 
[2004.08.04 02:10:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys 
[2008.04.14 09:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys 
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys 
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys 
[2004.08.03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys 
   < MD5 for: EVENTLOG.DLL  > 
[2008.04.14 08:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll 
[2008.04.14 08:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll 
[2004.08.04 01:57:20 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll 
   < MD5 for: NETLOGON.DLL  > 
[2008.04.14 08:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll 
[2008.04.14 08:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll 
[2004.08.04 01:57:32 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll 
   < MD5 for: SCECLI.DLL  > 
[2008.04.14 08:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll 
[2008.04.14 08:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll 
[2004.08.04 01:57:34 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll 
   < MD5 for: USERINIT.EXE  > 
[2008.04.14 08:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe 
[2008.04.14 08:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe 
[2004.08.04 01:58:18 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe 
   < MD5 for: WS2IFSL.SYS  > 
[2003.04.02 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys 
[2003.04.02 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys 
   < %systemroot%\system32\drivers\*.sys /lockedfiles > 
   < %systemroot%\System32\config\*.sav > 
[2009.12.24 18:01:55 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav 
[2009.12.24 18:01:55 | 000,606,208 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav 
[2009.12.24 18:01:55 | 000,434,176 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav 
   < %systemroot%\*. /mp /s > 
   < %systemroot%\system32\*.dll /lockedfiles > 
[2009.03.08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll 
[2009.03.08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll 
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] 
< End of report >   --- --- ---    
Das müsstens sein hoffe ich.    |