| 
 Oh, mensch... Das ist mir aber unangenehm... Dann hier der dritte Versuch der Otl. txt:  Code: 
 OTL logfile created on: 09.08.2011 10:19:50 - Run 2OTL by OldTimer - Version 3.2.26.1     Folder = C:\Users\Alli\Desktop
 Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
 Internet Explorer (Version = 7.0.6002.18005)
 Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
 2,00 Gb Total Physical Memory | 0,86 Gb Available Physical Memory | 43,24% Memory free
 4,24 Gb Paging File | 2,73 Gb Available in Paging File | 64,45% Paging File free
 Paging file location(s): ?:\pagefile.sys [binary data]
 
 %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
 Drive C: | 271,72 Gb Total Space | 80,13 Gb Free Space | 29,49% Space Free | Partition Type: NTFS
 Drive D: | 26,34 Gb Total Space | 18,12 Gb Free Space | 68,80% Space Free | Partition Type: FAT32
 
 Computer Name: ALLI-PC | User Name: Alli | Logged in as Administrator.
 Boot Mode: Normal | Scan Mode: Current user
 Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
 ========== Processes (SafeList) ==========
 
 PRC - C:\Users\Alli\Desktop\OTL.exe (OldTimer Tools)
 PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
 PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
 PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
 PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
 PRC - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
 PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
 PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
 PRC - C:\Users\Alli\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
 PRC - C:\Windows\explorer.exe (Microsoft Corporation)
 PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
 PRC - C:\Program Files\Stardock\MyColors\VistaSrv.exe (Stardock Corporation)
 PRC - C:\Program Files\Stardock\MyColors\WBVista.exe ()
 PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
 PRC - C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe ()
 PRC - C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe ()
 PRC - C:\Program Files\Home Cinema\TV Enhance\TVEService.exe (CyberLink Corp.)
 PRC - C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe (Buhl Data Service GmbH)
 PRC - C:\Program Files\Sceneo\Bonavista\Services\ODSBC\ODSBCApp.exe (ODSoft multimedia)
 PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
 PRC - C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
 PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
 PRC - C:\Program Files\Common Files\X10\Common\X10nets.exe (X10)
 
 
 ========== Modules (SafeList) ==========
 
 MOD - C:\Users\Alli\Desktop\OTL.exe (OldTimer Tools)
 MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
 
 
 ========== Win32 Services (SafeList) ==========
 
 SRV - (FirebirdServerMAGIXInstance) --  File not found
 SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
 SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
 SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
 SRV - (SearchAnonymizer) -- C:\Users\Alli\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
 SRV - (WindowBlinds) -- C:\Program Files\Stardock\MyColors\VistaSrv.exe (Stardock Corporation)
 SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
 SRV - (TVECapSvc) TVEnhance Background Capture Service (TBCS) -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe ()
 SRV - (TVESched) TVEnhance Task Scheduler (TTS)) -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe ()
 SRV - (srvcPVR) -- C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe (Buhl Data Service GmbH)
 SRV - (x10nets) -- C:\Program Files\Common Files\X10\Common\X10nets.exe (X10)
 
 
 ========== Driver Services (SafeList) ==========
 
 DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
 DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
 DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
 DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
 DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
 DRV - (ACEDRV07) -- C:\Windows\System32\drivers\ACEDRV07.sys (Protect Software GmbH)
 DRV - (netr73) -- C:\Windows\System32\drivers\netr73.sys (Ralink Technology Corp.)
 DRV - (Ph3xIB32) -- C:\Windows\System32\drivers\Ph3xIB32.sys (Philips Semiconductors GmbH)
 DRV - (3xHybrid) -- C:\Windows\System32\drivers\3xHybrid.sys (Philips Semiconductors GmbH)
 DRV - (PAC207) -- C:\Windows\System32\drivers\PFC027.SYS (PixArt Imaging Inc.)
 DRV - (XUIF) -- C:\Windows\System32\drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
 DRV - (X10Hid) -- C:\Windows\System32\drivers\x10hid.sys (X10 Wireless Technology, Inc.)
 DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
 DRV - (xfilt) -- C:\Windows\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
 DRV - (videX32) -- C:\Windows\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
 DRV - (speedfan) -- C:\Windows\system32\speedfan.sys (Windows (R) 2000 DDK provider)
 DRV - (giveio) -- C:\Windows\system32\giveio.sys ()
 
 
 ========== Standard Registry (SafeList) ==========
 
 
 ========== Internet Explorer ==========
 
 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
 IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 ========== FireFox ==========
 
 FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
 FF - prefs.js..browser.search.selectedEngine: "Google"
 FF - prefs.js..browser.search.useDBForOrder: true
 FF - prefs.js..browser.startup.homepage: "google.de"
 FF - prefs.js..extensions.enabledItems: {AA994882-F391-4d2e-806F-8908DA4814ED}:2.11.9
 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
 FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.6
 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
 FF - prefs.js..extensions.enabledItems: extension@virtusdesigns.com:3.6.6
 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 FF - prefs.js..extensions.enabledItems: {184AA5E6-741D-464a-820E-94B3ABC2F3B4}:1.0
 FF - prefs.js..extensions.enabledItems: {7694c49c-9fbd-11dc-8314-0800200c9a66}:3.6.6
 FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.6&q="
 
 
 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
 FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Users\Alli\Documents\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
 FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
 FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
 FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Users\Alli\components [2011.06.30 13:41:16 | 000,000,000 | ---D | M]
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Users\Alli\plugins [2011.06.23 20:19:47 | 000,000,000 | ---D | M]
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.08.08 19:33:58 | 000,000,000 | ---D | M]
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Users\Alli\AppData\Roaming\5015 [2011.04.09 19:14:37 | 000,000,000 | ---D | M]
 FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Users\Alli\components [2011.06.30 13:41:16 | 000,000,000 | ---D | M]
 FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Users\Alli\plugins [2011.06.23 20:19:47 | 000,000,000 | ---D | M]
 
 [2009.01.02 19:26:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Extensions
 [2011.08.09 10:16:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions
 [2010.04.27 20:31:47 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
 [2011.08.09 10:16:51 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
 [2010.08.12 20:11:51 | 000,000,000 | ---D | M] (Aquatint Black) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}
 [2010.07.30 23:01:05 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
 [2011.03.22 23:25:44 | 000,000,000 | ---D | M] (kikin plugin) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
 [2010.08.12 20:11:55 | 000,000,000 | ---D | M] (Virtus Search Opt-in) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com
 [2011.08.09 10:16:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\staged
 [2010.08.12 20:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com\__MACOSX
 [2010.08.12 20:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com\chrome
 [2010.08.12 20:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\extension@virtusdesigns.com\defaults
 [2010.08.12 20:11:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}\chrome\mac\mozapps\extensions
 [2010.08.12 20:11:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alli\AppData\Roaming\mozilla\Firefox\Profiles\h6z61i64.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
 [2011.08.08 09:57:51 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-1.xml
 [2011.03.23 21:00:06 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-10.xml
 [2011.05.01 17:27:58 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-11.xml
 [2011.06.23 20:20:19 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-12.xml
 [2011.06.23 20:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-13.xml
 [2010.07.29 23:10:36 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-2.xml
 [2010.09.10 21:50:37 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-3.xml
 [2010.09.10 21:53:02 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-4.xml
 [2010.10.22 13:29:12 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-5.xml
 [2010.10.29 16:38:34 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-6.xml
 [2010.12.11 11:10:05 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-7.xml
 [2010.12.11 12:12:16 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-8.xml
 [2011.03.06 17:39:51 | 000,000,950 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin-9.xml
 [2010.06.26 19:20:34 | 000,000,947 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\icqplugin.xml
 [2010.12.31 14:24:09 | 000,001,218 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\kikin-search.xml
 [2009.09.28 16:22:14 | 000,001,834 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\{4FD7DEE0-9C1A-4682-850D-0C2BAF2D1540}.xml
 [2009.09.28 16:22:14 | 000,002,041 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\{B64016E1-B873-4DE1-888B-6FA625E65466}.xml
 [2009.09.28 16:22:14 | 000,002,152 | ---- | M] () -- C:\Users\Alli\AppData\Roaming\Mozilla\Firefox\Profiles\h6z61i64.default\searchplugins\{CD745A81-B703-421E-8957-49F3D4F1D491}.xml
 [2011.08.08 19:33:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 File not found (No name found) --
 [2011.04.09 19:14:37 | 000,000,000 | ---D | M] (Java String Helper) -- C:\USERS\ALLI\APPDATA\ROAMING\5015
 [2011.07.08 09:31:38 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
 [2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
 [2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
 [2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
 [2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
 [2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
 [2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
 O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,736 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
 O1 - Hosts: ::1             localhost
 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
 O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
 O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
 O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll (kikin)
 O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
 O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
 O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
 O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
 O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
 O4 - HKLM..\Run: [InstantOn] C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe ()
 O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\Home Cinema\PowerDVD\Language\Language.exe ()
 O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
 O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
 O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
 O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
 O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
 O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
 O4 - HKLM..\Run: [Ocs_SM] C:\Users\Alli\AppData\Roaming\OCS\SM\SearchAnonymizer.exe ()
 O4 - HKLM..\Run: [RemoteControl] C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
 O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
 O4 - HKLM..\Run: [TVBroadcast] C:\Program Files\Sceneo\Bonavista\Services\ODSBC\ODSBCApp.exe (ODSoft multimedia)
 O4 - HKLM..\Run: [TVEService] C:\Program Files\Home Cinema\TV Enhance\TVEService.exe (CyberLink Corp.)
 O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
 O4 - HKCU..\Run: [EA Core]  File not found
 O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
 O4 - HKCU..\Run: [msnmsgr]  File not found
 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
 O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
 O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} -  File not found
 O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} -  File not found
 O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll (kikin)
 O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
 O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
 O13 - gopher Prefix: missing
 O15 - HKCU\..Trusted Domains: icq.com ([]http in Trusted sites)
 O15 - HKCU\..Trusted Domains: icq.com ([start] http in Trusted sites)
 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
 O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
 O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
 O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
 O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
 O24 - Desktop WallPaper: C:\Users\Alli\Pictures\2009\1.Winter\Schnee\CIMG0088.JPG
 O24 - Desktop BackupWallPaper: C:\Users\Alli\Pictures\2009\1.Winter\Schnee\CIMG0088.JPG
 O32 - HKLM CDRom: AutoRun - 1
 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
 O33 - MountPoints2\{5377d325-477d-11df-b516-0019db538ee6}\Shell - "" = AutoRun
 O33 - MountPoints2\{5377d325-477d-11df-b516-0019db538ee6}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
 O33 - MountPoints2\{59439e66-4cf2-11de-aef2-0019db538ee6}\Shell - "" = AutoRun
 O33 - MountPoints2\{59439e66-4cf2-11de-aef2-0019db538ee6}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
 O33 - MountPoints2\{d0d54177-cb7e-11dd-9bb4-0019db538ee6}\Shell\AutoRun\command - "" = G:\Menu.exe
 O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setupSNK.exe
 O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
 O35 - HKLM\..comfile [open] -- "%1" %*
 O35 - HKLM\..exefile [open] -- "%1" %*
 O37 - HKLM\...com [@ = comfile] -- "%1" %*
 O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 ========== Files/Folders - Created Within 30 Days ==========
 
 [2011.08.08 14:02:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
 [2011.08.08 14:02:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
 [2011.08.08 14:01:13 | 003,447,576 | ---- | C] (Piriform Ltd) -- C:\Users\Alli\Desktop\ccsetup309.exe
 [2011.08.08 13:05:11 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Alli\Desktop\OTL.exe
 [2011.08.08 10:23:29 | 000,000,000 | ---D | C] -- C:\Users\Alli\AppData\Roaming\Malwarebytes
 [2011.08.08 10:23:11 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
 [2011.08.08 10:23:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
 [2011.08.08 10:23:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
 [2011.08.08 10:23:07 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
 [2011.08.08 10:23:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
 [2011.08.07 15:19:01 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
 [2011.07.13 20:59:44 | 002,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
 [2011.07.13 20:59:05 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
 [2011.07.13 20:59:05 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
 [1 C:\Users\Alli\AppData\Roaming\*.tmp files -> C:\Users\Alli\AppData\Roaming\*.tmp -> ]
 
 ========== Files - Modified Within 30 Days ==========
 
 [2011.08.09 09:25:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
 [2011.08.09 00:19:28 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
 [2011.08.09 00:19:28 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
 [2011.08.09 00:18:20 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{3B71DEDA-8EF0-4F1A-8789-F75916A1D24D}.job
 [2011.08.08 19:33:58 | 000,000,810 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
 [2011.08.08 14:05:32 | 000,000,768 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
 [2011.08.08 14:01:18 | 003,447,576 | ---- | M] (Piriform Ltd) -- C:\Users\Alli\Desktop\ccsetup309.exe
 [2011.08.08 13:05:19 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Alli\Desktop\OTL.exe
 [2011.08.08 10:23:11 | 000,000,870 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
 [2011.08.07 13:46:43 | 000,628,504 | ---- | M] () -- C:\Windows\System32\perfh007.dat
 [2011.08.07 13:46:43 | 000,595,798 | ---- | M] () -- C:\Windows\System32\perfh009.dat
 [2011.08.07 13:46:43 | 000,126,054 | ---- | M] () -- C:\Windows\System32\perfc007.dat
 [2011.08.07 13:46:43 | 000,103,872 | ---- | M] () -- C:\Windows\System32\perfc009.dat
 [2011.07.20 15:37:05 | 000,096,768 | ---- | M] () -- C:\Users\Alli\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 [2011.07.14 03:22:29 | 000,403,776 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
 [1 C:\Users\Alli\AppData\Roaming\*.tmp files -> C:\Users\Alli\AppData\Roaming\*.tmp -> ]
 
 ========== Files Created - No Company Name ==========
 
 [2011.08.08 19:33:58 | 000,000,822 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
 [2011.08.08 19:33:58 | 000,000,810 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
 [2011.08.08 14:02:18 | 000,000,768 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
 [2011.08.08 10:23:11 | 000,000,870 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
 [2011.04.09 20:08:50 | 000,000,024 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\urhtps.dat
 [2009.09.11 20:37:06 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
 [2009.09.11 20:37:05 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
 [2009.06.11 11:09:38 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
 [2009.03.21 18:39:06 | 000,025,343 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\UserTile.png
 [2008.10.21 16:26:11 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
 [2008.10.21 16:24:27 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
 [2008.08.25 10:19:53 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
 [2008.02.01 22:21:39 | 000,192,512 | ---- | C] () -- C:\Windows\System32\srkey.exe
 [2008.02.01 20:55:17 | 000,001,000 | ---- | C] () -- C:\Windows\registry.ini
 [2008.02.01 20:55:17 | 000,000,438 | ---- | C] () -- C:\Windows\registry-oem.ini
 [2008.02.01 13:55:10 | 000,058,792 | ---- | C] () -- C:\Windows\System32\wbload.dll
 [2008.01.23 16:48:11 | 000,399,360 | ---- | C] () -- C:\Windows\System32\Smab.dll
 [2008.01.23 16:48:10 | 000,502,784 | ---- | C] () -- C:\Windows\x2.64.exe
 [2008.01.23 16:48:10 | 000,240,128 | ---- | C] () -- C:\Windows\System32\x.264.exe
 [2008.01.23 16:48:10 | 000,217,073 | ---- | C] () -- C:\Windows\meta4.exe
 [2008.01.23 16:48:10 | 000,066,560 | ---- | C] () -- C:\Windows\MOTA113.exe
 [2008.01.23 16:48:10 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
 [2007.06.25 19:31:21 | 000,000,552 | ---- | C] () -- C:\Users\Alli\AppData\Local\d3d8caps.dat
 [2007.05.19 10:55:48 | 000,001,199 | ---- | C] () -- C:\Windows\WININIT.INI
 [2007.05.19 10:55:34 | 000,000,000 | ---- | C] () -- C:\Windows\odbcddp.ini
 [2007.05.19 10:55:17 | 000,000,178 | ---- | C] () -- C:\Windows\_delis43.ini
 [2007.05.19 10:54:22 | 000,001,612 | ---- | C] () -- C:\Windows\ODBC.INI
 [2007.05.19 10:54:22 | 000,000,892 | ---- | C] () -- C:\Windows\ODBCINST.INI
 [2007.05.19 10:54:12 | 000,000,161 | ---- | C] () -- C:\Windows\KLETT.INI
 [2007.05.19 10:54:05 | 000,247,296 | ---- | C] () -- C:\Windows\UN160407.EXE
 [2007.04.27 20:24:25 | 000,000,052 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\Default.PLS
 [2007.04.27 10:35:30 | 000,000,025 | ---- | C] () -- C:\Windows\CDE D88PLUS.ini
 [2007.04.27 10:27:34 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
 [2007.04.27 10:27:34 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
 [2007.04.27 10:27:34 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
 [2007.04.27 10:27:34 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
 [2007.04.27 10:27:34 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
 [2007.04.27 10:27:34 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
 [2007.04.27 10:27:34 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
 [2007.04.27 10:27:34 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
 [2007.04.27 10:27:34 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
 [2007.04.27 10:27:34 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
 [2007.04.27 10:27:34 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
 [2007.04.27 10:27:33 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
 [2007.04.27 10:27:33 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
 [2007.04.27 10:27:33 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
 [2007.04.27 10:27:33 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
 [2007.04.27 10:27:33 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
 [2007.04.27 10:27:33 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
 [2007.04.27 10:27:33 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
 [2007.04.27 10:27:33 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
 [2007.04.27 10:18:49 | 000,003,904 | ---- | C] () -- C:\Users\Alli\AppData\Roaming\wklnhst.dat
 [2007.04.26 16:00:48 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
 [2007.04.25 20:40:21 | 000,007,052 | ---- | C] () -- C:\Users\Alli\AppData\Local\d3d9caps.dat
 [2007.04.21 23:59:20 | 000,096,768 | ---- | C] () -- C:\Users\Alli\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 [2007.02.12 11:30:06 | 000,299,008 | ---- | C] () -- C:\Windows\System32\midas.dll
 [2007.02.12 11:30:06 | 000,120,320 | ---- | C] () -- C:\Windows\System32\UnzDll.dll
 [2007.02.10 17:17:37 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
 [2007.02.09 16:43:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
 [2007.02.09 15:32:51 | 000,127,184 | ---- | C] () -- C:\Windows\Unwise.exe
 [2007.02.09 15:12:31 | 000,003,072 | ---- | C] () -- C:\Windows\System32\34CoInstaller.dll
 [2006.12.11 06:06:31 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
 [2006.11.02 17:33:31 | 000,628,504 | ---- | C] () -- C:\Windows\System32\perfh007.dat
 [2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
 [2006.11.02 17:33:31 | 000,126,054 | ---- | C] () -- C:\Windows\System32\perfc007.dat
 [2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
 [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
 [2006.11.02 14:47:37 | 000,403,776 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
 [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
 [2006.11.02 12:33:01 | 000,595,798 | ---- | C] () -- C:\Windows\System32\perfh009.dat
 [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
 [2006.11.02 12:33:01 | 000,103,872 | ---- | C] () -- C:\Windows\System32\perfc009.dat
 [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
 [2006.11.02 12:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
 [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
 [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
 [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
 [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
 [2006.11.02 09:27:46 | 000,000,518 | ---- | C] () -- C:\Windows\System32\SP207.INI
 [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 [2006.09.20 08:34:10 | 000,000,000 | ---- | C] () -- C:\Windows\Buhl.ini
 [2002.03.21 15:39:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\UNACEV2.DLL
 [1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
 
 ========== LOP Check ==========
 
 [2011.04.09 19:14:37 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\5015
 [2007.04.27 12:47:28 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\ACD Systems
 [2008.02.12 16:23:06 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Atari
 [2009.10.10 09:31:27 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Desktopicon
 [2008.02.03 21:14:33 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\EPSON
 [2008.12.16 17:29:02 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\fun communications
 [2010.11.15 20:43:38 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\gtk-2.0
 [2011.07.07 18:49:01 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\ICQ
 [2010.04.05 19:52:00 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\kikin
 [2011.04.09 19:14:07 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\kock
 [2008.04.17 17:21:27 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\LimeWire
 [2008.10.21 16:35:37 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\MAGIX
 [2009.05.16 21:58:03 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\McLoad
 [2007.04.27 12:37:59 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\MusicIP
 [2010.12.23 17:41:38 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\NCH Swift Sound
 [2009.09.28 16:22:09 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\OCS
 [2009.01.13 22:49:20 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\OpenOffice.org
 [2009.09.28 16:22:14 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Opera
 [2009.03.21 18:39:06 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\PeerNetworking
 [2007.04.27 10:19:03 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Template
 [2011.04.16 08:39:04 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\UAs
 [2008.02.15 19:27:12 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Ulead Systems
 [2008.05.01 13:14:18 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\Windows Live Writer
 [2011.04.16 08:44:10 | 000,000,000 | ---D | M] -- C:\Users\Alli\AppData\Roaming\xmldm
 [2008.05.01 13:00:50 | 000,000,252 | ---- | M] () -- C:\Windows\Tasks\Auf Updates für Windows Live Toolbar prüfen.job
 [2011.08.08 12:40:05 | 000,032,530 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 [2011.08.09 00:18:20 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{3B71DEDA-8EF0-4F1A-8789-F75916A1D24D}.job
 
 ========== Purity Check ==========
 
 
 
 ========== Alternate Data Streams ==========
 
 @Alternate Data Stream - 64 bytes -> C:\Users\Alli\Jason Derulo - Revolution (New 2010) (Official Off New Album).mp3:TOC.WMV
 @Alternate Data Stream - 64 bytes -> C:\Users\Alli\Documents\Pitbull_-_Hotel_Room_Service_Official_Video_2oo9_High_Quali.mp3:TOC.WMV
 
 < End of report >
 |