Hey, erstmal vielen vielen Dank! 
Bisher hat alles funktioniert, ich hoffe das stimmt:  
OTL Text:  
OTL Logfile:   Code:  
 OTL logfile created on: 16.01.2012 16:59:00 - Run 1 
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Dogan\Desktop 
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,18 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 88,34% Memory free 
6,35 Gb Paging File | 6,02 Gb Available in Paging File | 94,69% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 103,64 Gb Total Space | 35,87 Gb Free Space | 34,61% Space Free | Partition Type: NTFS 
Drive D: | 492,29 Gb Total Space | 395,83 Gb Free Space | 80,41% Space Free | Partition Type: FAT32 
  
Computer Name: DOGAN-PC | User Name: Dogan | Logged in as Administrator. 
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan 
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - [2012.01.16 16:57:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Dogan\Desktop\OTL.exe 
PRC - [2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe 
  
   ========== Modules (No Company Name) ========== 
  
MOD - [2011.05.28 21:04:56 | 000,140,288 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll 
MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV - [2011.08.09 16:22:23 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) 
SRV - [2011.06.12 10:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) 
SRV - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) 
SRV - [2011.05.21 07:01:00 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) 
SRV - [2011.05.20 21:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) 
SRV - [2011.04.21 06:53:48 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) 
SRV - [2010.04.15 22:42:22 | 002,533,400 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R) 
SRV - [2010.04.15 22:42:18 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R) 
SRV - [2010.01.15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) 
SRV - [2009.10.22 16:05:40 | 000,118,560 | ---- | M] (Wistron Corp.) [Disabled | Stopped] -- C:\Program Files\Launch Manager\WisLMSvc.exe -- (WisLMSvc) 
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) 
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV - [2011.08.09 16:22:24 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) 
DRV - [2011.08.09 16:22:24 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) 
DRV - [2011.06.10 16:00:04 | 000,161,664 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc) 
DRV - [2011.06.10 16:00:02 | 000,069,504 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub) 
DRV - [2011.05.21 07:01:00 | 010,589,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) 
DRV - [2011.05.21 07:01:00 | 000,023,144 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvpciflt.sys -- (nvpciflt) 
DRV - [2011.03.22 12:44:48 | 000,069,232 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) 
DRV - [2011.03.14 16:15:58 | 001,115,240 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192se.sys -- (rtl8192se) 
DRV - [2010.10.29 22:11:08 | 000,197,224 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR) 
DRV - [2010.10.15 00:27:18 | 000,269,824 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R) 
DRV - [2010.06.17 14:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) 
DRV - [2010.02.26 15:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd) 
DRV - [2009.09.18 02:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI) Intel(R) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) 
  
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.bearshare.com/ 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 B1 0C D2 A0 56 CC 01  [binary data] 
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) 
IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaultengine: "Ask.com" 
FF - prefs.js..browser.search.defaultenginename: "Ask.com" 
FF - prefs.js..browser.search.order.1: "Ask.com" 
FF - prefs.js..browser.search.selectedEngine: "Ask.com" 
FF - prefs.js..browser.search.useDBForOrder: true 
FF - prefs.js..browser.startup.homepage: "hxxp://de.ask.com/?l=dis&o=15506" 
FF - prefs.js..keyword.URL: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=PTF&o=15503&locale=de_DE&apn_uid=E2BF9D19-039A-434E-B932-C838312368F2&apn_ptnrs=LH&apn_sauid=A9658D41-A316-4268-8633-50CDC065C39C&apn_dtid=YYYYYYYYDE&&q=" 
  
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () 
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) 
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) 
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.93\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.93\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Dogan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.08.09 17:49:44 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.01.08 01:03:04 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.09.23 17:58:51 | 000,000,000 | ---D | M] 
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\finder@meingutscheincode.de: C:\Program Files\Mein Gutscheincode Finder\Firefox [2011.08.11 01:49:01 | 000,000,000 | ---D | M] 
  
[2011.08.09 17:45:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dogan\AppData\Roaming\mozilla\Extensions 
[2011.12.05 18:16:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dogan\AppData\Roaming\mozilla\Firefox\Profiles\gnwx9f08.default\extensions 
[2011.12.05 18:16:49 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\Dogan\AppData\Roaming\mozilla\Firefox\Profiles\gnwx9f08.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} 
[2012.01.06 14:05:43 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\Dogan\AppData\Roaming\mozilla\Firefox\Profiles\gnwx9f08.default\extensions\toolbar@ask.com 
[2012.01.15 19:44:23 | 000,002,400 | ---- | M] () -- C:\Users\Dogan\AppData\Roaming\Mozilla\Firefox\Profiles\gnwx9f08.default\searchplugins\askcom.xml 
[2011.08.11 07:04:26 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions 
[2011.09.16 20:54:03 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} 
() (No name found) -- C:\USERS\DOGAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GNWX9F08.DEFAULT\EXTENSIONS\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.XPI 
[2012.01.08 01:03:03 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll 
[2011.10.04 23:37:45 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml 
[2011.10.04 23:37:45 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml 
[2011.10.04 23:37:45 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml 
[2011.10.04 23:37:45 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml 
[2011.10.04 23:37:45 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml 
[2011.10.04 23:37:45 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml 
   ========== Chrome  ========== 
  
CHR - Extension: preisspion.de = C:\Users\Dogan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgfpelakfkbbkkdchaaaknckhoadkcbo\3.0.0_0\ 
CHR - Extension: Click to call with Skype = C:\Users\Dogan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.8013_0\ 
CHR - Extension: Winload = C:\Users\Dogan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnjhfpfhadncgafgbneeljaginimmmk\2.0.1.4_0\ 
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Dogan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\ 
  
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts 
O2 - BHO: (Mein Gutscheincode Finder zeigt automatisch Shopping-Gutscheine an mit denen Sie beim Online-Einkauf sparen können.) - {1ED16E0A-E8C4-40A0-8BC2-79485D21F796} - C:\Programme\Mein Gutscheincode Finder\Internet Explorer\x86\ConversionOneIE.dll (Conversion One GmbH) 
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) 
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) 
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) 
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) 
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) 
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) 
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) 
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) 
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) 
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) 
O3 - HKCU\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Programme\Winload\prxtbWinl.dll (Conduit Ltd.) 
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask) 
O4 - HKLM..\Run: []  File not found 
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) 
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) 
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () 
O4 - HKLM..\Run: [FILSHtray] C:\Program Files\FILSHtray\FILSHtray.exe (FILSH Media GmbH) 
O4 - HKLM..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron) 
O4 - HKLM..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe" File not found 
O4 - HKLM..\Run: [LMgrVolOSD] C:\Program Files\Launch Manager\OSD.exe (Wistron Corp.) 
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation) 
O4 - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor) 
O4 - HKLM..\Run: [TaskTray]  File not found 
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe (Simply Super Software) 
O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe (Wistron Corp.) 
O4 - HKCU..\Run: [{14AA463F-C292-11E0-B931-806E6F6E6963}] C:\Users\Dogan\AppData\Roaming\Microsoft\dllhsts.exe (TrueCrypt Foundation) 
O4 - HKCU..\Run: [Facebook Update] C:\Users\Dogan\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) 
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) 
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O13 - gopher Prefix: missing 
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab (DLM Control) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) 
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 83.169.184.33 83.169.184.97 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81FCEBE6-3FDB-4FB2-8934-BC9F67F78F6C}: DhcpNameServer = 83.169.184.33 83.169.184.97 
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) 
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) 
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation) 
O20 - AppInit_DLLs: (C:\Windows\system32\nvinit.dll) -C:\Windows\System32\nvinit.dll (NVIDIA Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
  
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework 
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework 
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings 
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install 
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig 
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP 
  
NetSvcs: FastUserSwitchingCompatibility -  File not found 
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) 
NetSvcs: Nla -  File not found 
NetSvcs: Ntmssvc -  File not found 
NetSvcs: NWCWorkstation -  File not found 
NetSvcs: Nwsapagent -  File not found 
NetSvcs: SRService -  File not found 
NetSvcs: WmdmPmSp -  File not found 
NetSvcs: LogonHours -  File not found 
NetSvcs: PCAudit -  File not found 
NetSvcs: helpsvc -  File not found 
NetSvcs: uploadmgr -  File not found 
  
  
CREATERESTOREPOINT 
Error creating restore point. 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2012.01.16 16:57:03 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Dogan\Desktop\OTL.exe 
[2012.01.16 00:23:58 | 000,000,000 | ---D | C] -- C:\Users\Dogan\Documents\Simply Super Software 
[2012.01.16 00:23:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover 
[2012.01.16 00:23:45 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover 
[2012.01.16 00:23:45 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Roaming\Simply Super Software 
[2012.01.16 00:23:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software 
[2012.01.16 00:02:26 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\ElevatedDiagnostics 
[2012.01.15 20:29:17 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Roaming\Malwarebytes 
[2012.01.15 20:29:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware 
[2012.01.15 20:29:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2012.01.15 20:29:13 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys 
[2012.01.15 20:29:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware 
[2012.01.15 13:42:51 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{2FF3FCC2-4F77-487E-8BF1-FC8E2EFCC2B7} 
[2012.01.15 13:42:38 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{BCEE048D-6EEE-40B8-A2C0-4276E1AA6A92} 
[2012.01.14 19:41:27 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{FB2F2B07-A497-487D-83F4-95B9A9C5C942} 
[2012.01.14 19:41:15 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{267B95FC-EE6D-4BBB-8B56-B3DB37248402} 
[2012.01.14 01:28:51 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{C8866AAB-C703-4838-990B-281E55B47C64} 
[2012.01.14 01:28:40 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{7BF371A7-F567-4BCF-8CAD-933E672772CB} 
[2012.01.13 13:28:12 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{906552BF-493B-4D49-9321-7A56120E8A93} 
[2012.01.13 13:28:00 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{05C8FFDA-AF52-4C75-8AF4-B05C3ED0104E} 
[2012.01.13 00:22:10 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{DE708A21-2F4C-48F9-9E35-0F31B46E3050} 
[2012.01.13 00:21:58 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{32EBED0D-2E8F-4433-80B1-CE9797D92517} 
[2012.01.12 12:21:26 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{F419E604-A3CD-4F80-933D-4AEC0590E5A4} 
[2012.01.12 12:21:11 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{CF36AA44-A08C-4A95-9DF8-97DB11C4B501} 
[2012.01.11 16:49:09 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{B8D00A85-E3DD-4D6C-8476-73A64F4B27B8} 
[2012.01.11 16:48:54 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{3EFBB929-59A5-4E77-952B-05E4C6CD6B1B} 
[2012.01.10 16:03:47 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{FC0D2A24-2104-423E-97DD-5F1FB2D50FFF} 
[2012.01.10 16:03:34 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{343C9EAC-D162-4DE8-9CEE-3404946F9FB3} 
[2012.01.09 14:05:57 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{79A6244A-40EF-4A0C-902B-EDF9B32CD1ED} 
[2012.01.09 14:05:44 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{E2591022-37B6-4924-B429-F8F1C2BA040A} 
[2012.01.08 15:53:28 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{0B0D0C9B-3FE1-4469-A492-653A51E5FE0B} 
[2012.01.08 15:53:16 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{0CA0CEB0-B42A-4FF6-A4F8-DF9AB061DEA0} 
[2012.01.07 16:45:32 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{AF857C60-5A2B-48A8-A8DE-99906D817BA5} 
[2012.01.07 16:45:19 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{EBEE48B5-5BB6-47C6-820F-66C3349C7207} 
[2012.01.07 00:44:22 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{75D00E90-74AC-49DA-BD40-F2EF6DEB981C} 
[2012.01.07 00:44:10 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{54AC8945-F638-4415-95B0-2DBEC520F448} 
[2012.01.06 09:16:45 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{AF85C5C1-E4ED-4C41-82BE-9B0A16621890} 
[2012.01.06 09:16:33 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{14C663D1-D290-4A72-AA7A-306D0C1885C5} 
[2012.01.05 17:47:47 | 000,000,000 | ---D | C] -- C:\Users\Dogan\Documents\FILSHtray 
[2012.01.05 17:47:47 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\FILSH_Media_GmbH 
[2012.01.05 17:47:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FILSHtray 
[2012.01.05 17:47:38 | 000,000,000 | ---D | C] -- C:\Program Files\FILSHtray 
[2012.01.05 14:51:52 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{E325A5D9-C147-43DA-82D9-6CA5B892BEE1} 
[2012.01.05 14:51:40 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{779B3D2C-E912-48E7-A3DE-64A774891A84} 
[2012.01.04 21:19:03 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{F5EFBA45-84C8-47C2-8934-B82F42AE6C38} 
[2012.01.04 21:18:50 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{57BC5D2B-E4D9-4730-9CF2-39BE359E54D4} 
[2012.01.04 08:39:51 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{5444A26F-B6FB-4B93-B8DD-D595604C5D63} 
[2012.01.04 08:39:39 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{80F5F1DA-675B-4F18-AC02-700FDD1CC483} 
[2012.01.03 20:15:11 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan 
[2012.01.03 20:15:11 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS 
[2012.01.03 20:15:11 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan 
[2012.01.03 20:15:11 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS\0305010.008 
[2012.01.03 16:55:08 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{BE387750-3582-4BB2-A113-36614A6F2820} 
[2012.01.03 16:54:53 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{DF2EA3D7-E30D-4705-8ECC-FCFA091B5EEC} 
[2012.01.03 03:33:06 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{8B51DA3C-57DC-4757-A776-505680B9DBBE} 
[2012.01.03 03:32:54 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{AA765BD5-AE53-4A78-8E28-AB2AF7B4B362} 
[2012.01.02 15:32:25 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{0D144372-07BD-4B8A-8DE0-4EEC34E36789} 
[2012.01.02 15:32:13 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{A653D26D-B508-4AB9-B752-D85B33BD9E2F} 
[2012.01.02 03:31:45 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{3B6022FE-8213-4B68-BABC-332F24E28AAA} 
[2012.01.02 03:31:33 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{82A738DD-671C-4299-AF29-ECDBBF797D48} 
[2012.01.01 15:31:04 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{C12789CB-3CC1-453F-A9E2-EB56BFDE898C} 
[2012.01.01 15:30:52 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{3F61E331-9491-45A8-948E-9E361750A33C} 
[2012.01.01 01:39:34 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{ADECFD46-DF73-4E62-AE85-82E7055427C8} 
[2012.01.01 01:39:21 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{A08E596F-6D5F-42A9-AB0F-99C347BF9278} 
[2011.12.31 13:38:33 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{40B67784-BEF3-4715-B122-775B29065196} 
[2011.12.31 13:38:18 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{8B5F2C89-A187-4198-82B1-E40B1B7B0209} 
[2011.12.30 17:55:15 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{42200F20-059C-4DE7-A20C-097528A152D9} 
[2011.12.30 17:55:02 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{00FC2A2C-9CF4-48F0-B37E-B26CD81FD264} 
[2011.12.30 03:28:03 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{62E371E4-96AB-4ECE-A7FA-70E031518928} 
[2011.12.30 03:27:51 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{9DE39BE1-E5AF-48AA-95A6-BD76400D9869} 
[2011.12.29 15:04:58 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{F1407A9C-B66D-4940-AE59-9A51A7BC59DD} 
[2011.12.29 15:04:46 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{5C2BB5F1-3656-4D83-BD45-8CCC9A5B53D5} 
[2011.12.29 03:04:18 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{E8246101-78F9-4148-9482-EEA4904495EC} 
[2011.12.29 03:04:06 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{694B305C-F40A-4542-9205-0954A2A94A3D} 
[2011.12.28 15:03:22 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{6BF9F88A-A203-4013-99DF-88B8D7BFC775} 
[2011.12.28 15:03:09 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{DADE1C9C-4F30-4B12-B5E8-BFC64017BD7F} 
[2011.12.27 20:20:04 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{96BFF371-C0B3-4F7D-A942-6ED91FC278E8} 
[2011.12.27 20:19:50 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{C95E8902-EF60-4401-8085-961E843495B3} 
[2011.12.27 02:53:05 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{5894C295-AE98-487B-A0C2-D4BF1C36DC36} 
[2011.12.27 02:52:53 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{12B98497-5545-4DC7-AEDC-CEF5F6FA7889} 
[2011.12.26 14:52:25 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{5220130D-7E6D-4B71-BB18-65F3AA9D3267} 
[2011.12.26 14:52:10 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{D03CC8B2-EE39-4158-86A5-6CAA8C657AA9} 
[2011.12.26 01:44:31 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{BE84D258-1046-4936-8EF3-6A9B17CBDC98} 
[2011.12.26 01:44:18 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{047EE124-AA22-4E5B-863D-FB339DC69465} 
[2011.12.25 13:43:48 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{45B3B1DD-B5A3-452E-A38D-46A7F0B19173} 
[2011.12.25 13:43:36 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{7D324F59-B1AD-4753-9D0F-28E5F219E49D} 
[2011.12.25 01:26:11 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{8E4FBFB6-C90C-4362-893B-A45314957EF6} 
[2011.12.25 01:26:00 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{63BA9FD3-47EB-4CA5-8865-46FB16121A7E} 
[2011.12.24 13:25:27 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{3F837373-844D-475E-8CC2-2B7EDB2BA533} 
[2011.12.24 13:25:15 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{9098AB88-D3EE-41B9-BA54-70B9446C759B} 
[2011.12.24 01:04:34 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{70851037-11F0-489E-9777-C3ACF98D64DD} 
[2011.12.24 01:04:23 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{EDE16BD8-0829-4F7A-8837-97412902FBFD} 
[2011.12.23 13:03:39 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{33CABB74-4B20-4D57-9F9B-5CF10169D1E9} 
[2011.12.23 13:03:26 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{B9DAE060-C893-466F-8B45-01C3DC6B6666} 
[2011.12.23 01:02:45 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{28436933-878C-4BC8-8EBA-D8F194D8234D} 
[2011.12.23 01:02:33 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{31544A35-A43B-4D1C-9624-22FAB9DC1CED} 
[2011.12.22 13:02:03 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{E077974B-1A0D-49A6-84A6-1C836200E7AE} 
[2011.12.22 13:01:48 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{A4118FCA-E3B0-4336-8CEE-181F4159E13A} 
[2011.12.21 15:10:19 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{EB80B8D1-E422-4182-B1DE-F01093BF0FB3} 
[2011.12.21 15:10:07 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{1EDE5971-7847-4C4D-8EA8-401D0ED69EC4} 
[2011.12.20 15:06:35 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{594FD941-7C26-4A6A-B50C-73087CCEE859} 
[2011.12.20 15:06:22 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{EF483389-20E6-485C-808D-AC796AF34BF5} 
[2011.12.19 19:40:06 | 000,000,000 | -HSD | C] -- C:\found.002 
[2011.12.19 17:40:38 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{D50B4DD1-9608-4105-A91A-2597B4330EA1} 
[2011.12.19 17:40:26 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{D667D2BB-7B4C-4CCD-8C08-1AC44E5FB5F3} 
[2011.12.18 12:49:04 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{17376458-8959-476E-8F87-4F50FD147A78} 
[2011.12.18 12:48:52 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{2AEE77B4-3E9F-42E0-B16D-8DBE508208BD} 
[2011.12.18 00:47:30 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{B7C1CB1C-D2C7-40EC-8A44-1782A3F04136} 
[2011.12.18 00:47:18 | 000,000,000 | ---D | C] -- C:\Users\Dogan\AppData\Local\{DE53AE07-AC56-4434-A25F-5F33DE07AF55} 
[2011.07.26 14:40:10 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll 
   ========== Files - Modified Within 30 Days ========== 
  
[2012.01.16 16:57:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Dogan\Desktop\OTL.exe 
[2012.01.16 16:54:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2012.01.16 16:54:12 | 2558,595,072 | -HS- | M] () -- C:\hiberfil.sys 
[2012.01.16 16:43:43 | 000,009,888 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2012.01.16 16:43:43 | 000,009,888 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2012.01.15 20:56:48 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2012.01.15 20:33:06 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2012.01.15 20:29:15 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
[2012.01.15 19:39:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-870719477-432128228-2100777228-1000UA.job 
[2012.01.15 19:39:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-870719477-432128228-2100777228-1000Core.job 
[2012.01.14 19:52:31 | 000,001,104 | ---- | M] () -- C:\Users\Dogan\Desktop\Mozilla Firefox (2).lnk 
[2012.01.14 02:16:34 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat 
[2012.01.14 02:16:34 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat 
[2012.01.14 02:16:34 | 000,004,284 | ---- | M] () -- C:\Windows\System32\perfh009.dat 
[2012.01.14 02:16:34 | 000,004,092 | ---- | M] () -- C:\Windows\System32\perfc009.dat 
[2012.01.04 07:26:50 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Dogan.job 
[2012.01.03 20:15:14 | 000,001,305 | ---- | M] () -- C:\Users\Dogan\Norton Security Scan.lnk 
[2011.12.26 16:53:30 | 000,208,896 | ---- | M] () -- C:\Users\Dogan\AppData\Roaming\mahmud.exe 
   ========== Files Created - No Company Name ========== 
  
[2012.01.16 00:23:51 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll 
[2012.01.16 00:23:50 | 000,162,304 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll 
[2012.01.16 00:23:50 | 000,153,088 | ---- | C] () -- C:\Windows\System32\UNRAR3.dll 
[2012.01.16 00:23:50 | 000,075,264 | ---- | C] () -- C:\Windows\System32\unacev2.dll 
[2012.01.15 20:29:15 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 
[2012.01.14 19:52:31 | 000,001,104 | ---- | C] () -- C:\Users\Dogan\Desktop\Mozilla Firefox (2).lnk 
[2012.01.03 20:15:14 | 000,001,305 | ---- | C] () -- C:\Users\Dogan\Norton Security Scan.lnk 
[2012.01.03 20:15:11 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NSS\0305010.008\isolate.ini 
[2011.12.19 19:27:53 | 000,208,896 | ---- | C] () -- C:\Users\Dogan\AppData\Roaming\mahmud.exe 
[2011.08.10 22:36:45 | 000,179,362 | ---- | C] () -- C:\Windows\hpoins38.dat 
[2011.08.09 17:45:22 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat 
[2011.08.09 16:35:47 | 001,283,212 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin 
[2011.08.09 15:25:49 | 000,451,072 | ---- | C] () -- C:\Windows\System32\ISSRemoveSP.exe 
[2011.07.26 15:14:50 | 000,128,204 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin 
[2011.07.26 15:14:44 | 000,105,608 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin 
[2011.07.26 15:14:42 | 000,867,020 | ---- | C] () -- C:\Windows\System32\igkrng575.bin 
[2011.07.26 14:50:58 | 013,903,872 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll 
[2011.07.26 14:37:22 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll 
[2011.05.20 21:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe 
[2011.02.11 17:38:44 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config 
[2009.07.14 09:47:43 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat 
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat 
[2009.07.14 09:47:43 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat 
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat 
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat 
[2009.07.14 05:33:53 | 000,406,584 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT 
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat 
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat 
[2009.07.14 03:05:48 | 000,004,284 | ---- | C] () -- C:\Windows\System32\perfh009.dat 
[2009.07.14 03:05:48 | 000,004,092 | ---- | C] () -- C:\Windows\System32\perfc009.dat 
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT 
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat 
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin 
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll 
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll 
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat 
[2009.06.04 18:59:42 | 000,000,622 | ---- | C] () -- C:\Windows\hpomdl38.dat 
[2006.12.30 18:48:38 | 000,000,476 | ---- | C] () -- C:\Windows\powermp3cutterjoiner.ini 
[2003.08.07 14:01:52 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll 
   ========== LOP Check ========== 
  
[2011.08.09 23:10:08 | 000,000,000 | ---D | M] -- C:\Users\Dogan\AppData\Roaming\PhotoFiltre 
[2012.01.16 00:23:45 | 000,000,000 | ---D | M] -- C:\Users\Dogan\AppData\Roaming\Simply Super Software 
[2011.08.11 01:39:41 | 000,000,000 | ---D | M] -- C:\Users\Dogan\AppData\Roaming\WindSolutions 
[2012.01.15 19:39:00 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-870719477-432128228-2100777228-1000Core.job 
[2012.01.15 19:39:01 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-870719477-432128228-2100777228-1000UA.job 
[2012.01.12 19:42:38 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT 
   ========== Purity Check ========== 
  
  
   ========== Custom Scans ========== 
  
   < %SYSTEMDRIVE%\*. > 
[2011.08.15 06:22:54 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin 
[2011.08.09 16:15:06 | 000,000,000 | -HSD | M] -- C:\Boot 
[2012.01.12 09:17:52 | 000,000,000 | -H-D | M] -- C:\Config.Msi 
[2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings 
[2011.08.09 15:22:09 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen 
[2011.08.25 16:08:44 | 000,000,000 | -HSD | M] -- C:\found.000 
[2011.12.14 22:17:44 | 000,000,000 | -HSD | M] -- C:\found.001 
[2011.12.19 19:40:06 | 000,000,000 | -HSD | M] -- C:\found.002 
[2011.08.09 16:49:02 | 000,000,000 | ---D | M] -- C:\Intel 
[2011.09.16 21:04:23 | 000,000,000 | ---D | M] -- C:\Medion 
[2011.08.09 17:27:34 | 000,000,000 | RH-D | M] -- C:\MSOCache 
[2012.01.15 20:16:24 | 000,000,000 | ---D | M] -- C:\My Downloads 
[2011.08.09 16:33:37 | 000,000,000 | ---D | M] -- C:\NVIDIA 
[2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs 
[2012.01.16 00:23:45 | 000,000,000 | R--D | M] -- C:\Program Files 
[2012.01.16 00:23:45 | 000,000,000 | -H-D | M] -- C:\ProgramData 
[2011.08.09 15:22:10 | 000,000,000 | -HSD | M] -- C:\Programme 
[2011.08.09 15:22:10 | 000,000,000 | -HSD | M] -- C:\Recovery 
[2012.01.15 19:01:11 | 000,000,000 | -HSD | M] -- C:\System Volume Information 
[2011.08.15 06:22:42 | 000,000,000 | R--D | M] -- C:\Users 
[2012.01.15 20:36:41 | 000,000,000 | ---D | M] -- C:\Windows 
   < %PROGRAMFILES%\*.exe > 
   < %LOCALAPPDATA%\*.exe > 
   < %systemroot%\*. /mp /s > 
   < %systemroot%\system32\*.manifest /3 > 
  
   < MD5 for: EXPLORER.EXE  > 
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe 
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe 
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe 
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe 
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\explorer.exe 
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe 
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe 
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe 
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe 
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe 
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe 
   < MD5 for: REGEDIT.EXE  > 
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe 
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe 
   < MD5 for: USERINIT.EXE  > 
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe 
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe 
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe 
   < MD5 for: WININIT.EXE  > 
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe 
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe 
   < MD5 for: WINLOGON.EXE  > 
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe 
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe 
[2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe 
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe 
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe 
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe 
   < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 
   < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > 
   < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-13 12:32:42 
   <           >   
< End of report >   --- --- ---   
Extra Text:  
OTL Logfile:   Code:  
 OTL Extras logfile created on: 16.01.2012 16:59:00 - Run 1 
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Dogan\Desktop 
 Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,18 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 88,34% Memory free 
6,35 Gb Paging File | 6,02 Gb Available in Paging File | 94,69% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 103,64 Gb Total Space | 35,87 Gb Free Space | 34,61% Space Free | Partition Type: NTFS 
Drive D: | 492,29 Gb Total Space | 395,83 Gb Free Space | 80,41% Space Free | Partition Type: FAT32 
  
Computer Name: DOGAN-PC | User Name: Dogan | Logged in as Administrator. 
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan 
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) 
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) 
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) 
  
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) 
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) 
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) 
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = Reg Error: Unknown registry data type -- File not found 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   ========== Firewall Settings ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
   ========== Authorized Applications List ========== 
  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller 
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer 
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan 
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger 
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953 
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources 
"{1E05CF2E-BF5F-4A43-9147-2CCBBE57BC3C}_is1" = Mein Gutscheincode Finder 1.0.0.0 
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update 
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions 
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26 
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm 
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver 
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack 
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile 
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg 
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater 
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module 
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver 
"{5928359F-BF46-4646-BF19-B64E55171EB5}_is1" = FILSHtray Version 0.8 
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM 
"{61CF2C86-8E46-4210-A115-E4D6C65AF369}" = HP Photosmart B109a-m All-In-One Driver Software 13.0 Rel .6 
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module 
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components 
"{656FDFA4-C7C6-40D9-99F7-F6F331412AEF}" = WarrantyExtension 
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE 
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes 
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin 
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support 
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox 
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update 
"{80FE5490-E9DD-4AE9-8537-3EB5EFB606FC}" = PS_AIO_06_B109a-m_SW_Min 
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform 
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT 
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 
"{90140000-0015-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.PROPLUSR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010 
"{90140000-0044-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010 
"{90140000-00BA-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) 
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer 
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader 
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 
"{9D3D8C60-A55F-4fed-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver 
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common 
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer 
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.0) - Deutsch 
"{AF20390E-5ADD-4CB0-BF9D-EDF6E7891AD9}" = B109a-m 
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter 
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 275.33 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 275.33 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 275.33 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 275.33 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.3.5 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.10.0514 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application 
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components 
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype 
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX 
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support 
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common 
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant 
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime 
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget 
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform 
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour 
"{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager 
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform 
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger 
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module 
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics 
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver 
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack 
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin 
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6 
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus 
"conduitEngine" = Conduit Engine 
"DivX Setup" = DivX-Setup 
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition 
"Google Chrome" = Google Chrome 
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver 
"LastFM_is1" = Last.fm 1.5.4.27091 
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.0.1800 
"McAfee Security Scan" = McAfee Security Scan Plus 
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile 
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack 
"Mozilla Firefox 9.0.1 (x86 de)" = Mozilla Firefox 9.0.1 (x86 de) 
"NSS" = Norton Security Scan 
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver 
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver 
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010 
"Power MP3 Cutter Joiner_is1" = Power MP3 Cutter Joiner 1.12 
"Trojan Remover_is1" = Trojan Remover 6.8.2 
"WinLiveSuite" = Windows Live Essentials 
"Winload Toolbar" = Winload Toolbar 
"WinRAR archiver" = WinRAR 4.01 (32-Bit) 
"YTdetect" = Yahoo! Detect 
   ========== HKEY_CURRENT_USER Uninstall List ========== 
  
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater 
"PhotoFiltre" = PhotoFiltre 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 12.01.2012 09:41:10 | Computer Name = Dogan-PC | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version: 9.0.1.4371, 
 Zeitstempel: 0x4ef15e07  Name des fehlerhaften Moduls: NPSWF32.dll, Version: 10.3.181.34, 
 Zeitstempel: 0x4e0117de  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00178918  ID des fehlerhaften 
 Prozesses: 0x15a4  Startzeit der fehlerhaften Anwendung: 0x01ccd122e59f3340  Pfad der 
 fehlerhaften Anwendung: C:\Program Files\Mozilla Firefox\plugin-container.exe  Pfad 
 des fehlerhaften Moduls: C:\Windows\system32\Macromed\Flash\NPSWF32.dll  Berichtskennung: 
 15c55a88-3d23-11e1-846d-00262dc2100c 
  
Error - 12.01.2012 10:52:06 | Computer Name = Dogan-PC | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912, 
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: msxml3.dll, Version: 8.110.7600.16723, 
 Zeitstempel: 0x4d103aab  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00005fb0  ID des fehlerhaften 
 Prozesses: 0x6f8  Startzeit der fehlerhaften Anwendung: 0x01ccd12fdaf536b9  Pfad der 
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des 
 fehlerhaften Moduls: C:\Windows\System32\msxml3.dll  Berichtskennung: fe42ff8e-3d2c-11e1-846d-00262dc2100c 
  
Error - 12.01.2012 13:23:30 | Computer Name = Dogan-PC | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16912, 
 Zeitstempel: 0x4eb4a5ea  Name des fehlerhaften Moduls: msxml3.dll, Version: 8.110.7600.16723, 
 Zeitstempel: 0x4d103aab  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00005fb0  ID des fehlerhaften 
 Prozesses: 0x1d14  Startzeit der fehlerhaften Anwendung: 0x01ccd14e8fd88084  Pfad der 
 fehlerhaften Anwendung: C:\Program Files\Internet Explorer\iexplore.exe  Pfad des 
 fehlerhaften Moduls: C:\Windows\System32\msxml3.dll  Berichtskennung: 253a0500-3d42-11e1-846d-00262dc2100c 
  
Error - 12.01.2012 14:45:21 | Computer Name = Dogan-PC | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version: 9.0.1.4371, 
 Zeitstempel: 0x4ef15e07  Name des fehlerhaften Moduls: NPSWF32.dll, Version: 10.3.181.34, 
 Zeitstempel: 0x4e0117de  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00178918  ID des fehlerhaften 
 Prozesses: 0x13d0  Startzeit der fehlerhaften Anwendung: 0x01ccd15a3e175f58  Pfad der 
 fehlerhaften Anwendung: C:\Program Files\Mozilla Firefox\plugin-container.exe  Pfad 
 des fehlerhaften Moduls: C:\Windows\system32\Macromed\Flash\NPSWF32.dll  Berichtskennung: 
 9463f0e5-3d4d-11e1-84f2-00262dc2100c 
  
Error - 13.01.2012 20:25:00 | Computer Name = Dogan-PC | Source = Application Hang | ID = 1002 
Description = Programm firefox.exe, Version 9.0.1.4371 kann nicht mehr unter Windows 
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, 
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: d48    Startzeit:  
01ccd252a2df1316    Endzeit: 60    Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe   
Berichts-ID: 
 29fe5cc6-3e46-11e1-a0ce-00262dc2100c   
  
Error - 13.01.2012 21:34:46 | Computer Name = Dogan-PC | Source = Bonjour Service | ID = 100 
Description = 456: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde 
 vom Remotehost geschlossen.) 
  
Error - 13.01.2012 21:34:46 | Computer Name = Dogan-PC | Source = Bonjour Service | ID = 100 
Description = 288: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde 
 vom Remotehost geschlossen.) 
  
Error - 13.01.2012 21:34:46 | Computer Name = Dogan-PC | Source = Bonjour Service | ID = 100 
Description = 196: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde 
 vom Remotehost geschlossen.) 
  
Error - 14.01.2012 16:09:02 | Computer Name = Dogan-PC | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version: 9.0.1.4371, 
 Zeitstempel: 0x4ef15e07  Name des fehlerhaften Moduls: NPSWF32.dll, Version: 10.3.181.34, 
 Zeitstempel: 0x4e0117de  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00178918  ID des fehlerhaften 
 Prozesses: 0x1418  Startzeit der fehlerhaften Anwendung: 0x01ccd2f1e27f8474  Pfad der 
 fehlerhaften Anwendung: C:\Program Files\Mozilla Firefox\plugin-container.exe  Pfad 
 des fehlerhaften Moduls: C:\Windows\system32\Macromed\Flash\NPSWF32.dll  Berichtskennung: 
 99ea8313-3eeb-11e1-8ea2-00262dc2100c 
  
Error - 15.01.2012 11:20:56 | Computer Name = Dogan-PC | Source = Application Hang | ID = 1002 
Description = Programm firefox.exe, Version 9.0.1.4371 kann nicht mehr unter Windows 
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, 
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 10e8    Startzeit: 
 01ccd3832700d97d    Endzeit: 166    Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe   
Berichts-ID: 
    
  
[ System Events ] 
Error - 05.11.2011 23:55:09 | Computer Name = Dogan-PC | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 06.11.2011 11:46:49 | Computer Name = Dogan-PC | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 06.11.2011 18:27:39 | Computer Name = Dogan-PC | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. 
  
Error - 07.11.2011 10:21:21 | Computer Name = Dogan-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 07.11.2011 12:26:18 | Computer Name = Dogan-PC | Source = EventLog | ID = 6008 
Description = Das System wurde zuvor am ?07.?11.?2011 um 17:24:54 unerwartet heruntergefahren. 
  
Error - 08.11.2011 07:03:36 | Computer Name = Dogan-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 09.11.2011 18:01:36 | Computer Name = Dogan-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 10.11.2011 14:41:03 | Computer Name = Dogan-PC | Source = EventLog | ID = 6008 
Description = Das System wurde zuvor am ?10.?11.?2011 um 19:17:35 unerwartet heruntergefahren. 
  
Error - 11.11.2011 13:51:00 | Computer Name = Dogan-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 11.11.2011 17:30:40 | Computer Name = Dogan-PC | Source = DCOM | ID = 10010 
Description =  
  
  
< End of report >   --- --- ---   
Ich hoffe das ist korrekt so bisher?    |