|   | PistolPetede | 23.12.2012 16:03 |  
 hier OTL.txt:  Code: 
 OTL logfile created on: 23.12.2012 15:48:59 - Run 4OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Xxx\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
 Internet Explorer (Version = 9.0.8112.16421)
 Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
 2,94 Gb Total Physical Memory | 2,21 Gb Available Physical Memory | 75,09% Memory free
 5,87 Gb Paging File | 5,14 Gb Available in Paging File | 87,56% Paging File free
 Paging file location(s): ?:\pagefile.sys [binary data]
 
 %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
 Drive C: | 109,38 Gb Total Space | 78,25 Gb Free Space | 71,54% Space Free | Partition Type: NTFS
 Drive D: | 1397,26 Gb Total Space | 128,20 Gb Free Space | 9,17% Space Free | Partition Type: NTFS
 Drive E: | 931,51 Gb Total Space | 463,28 Gb Free Space | 49,73% Space Free | Partition Type: NTFS
 Drive G: | 9,86 Gb Total Space | 5,73 Gb Free Space | 58,14% Space Free | Partition Type: NTFS
 Drive H: | 1863,01 Gb Total Space | 486,36 Gb Free Space | 26,11% Space Free | Partition Type: NTFS
 Drive I: | 58,92 Gb Total Space | 1,41 Gb Free Space | 2,40% Space Free | Partition Type: NTFS
 Unable to calculate disk information.
 
 Computer Name: XXX | User Name: Xxx | Logged in as Administrator.
 Boot Mode: Normal | Scan Mode: All users
 Company Name Whitelist: On | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
 ========== Processes (SafeList) ==========
 
 PRC - C:\Users\Xxx\Desktop\OTL.exe (OldTimer Tools)
 PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Programme\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe ()
 PRC - C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
 PRC - C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
 PRC - C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
 PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
 PRC - C:\Windows\explorer.exe (Microsoft Corporation)
 PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
 PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
 PRC - C:\Programme\Logitech\GamePanel Software\LGDevAgt.exe (Logitech Inc.)
 PRC - C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
 PRC - C:\Programme\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
 PRC - C:\Windows\System32\PrintIsolationHost.exe (Microsoft Corporation)
 PRC - C:\Programme\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
 PRC - C:\Programme\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
 
 
 ========== Modules (No Company Name) ==========
 
 
 ========== Services (SafeList) ==========
 
 SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
 SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
 SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
 SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
 SRV - (vToolbarUpdater13.2.0) -- C:\Programme\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe ()
 SRV - (FLEXnet Licensing Service) -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
 SRV - (Stereo Service) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
 SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
 SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
 SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
 SRV - (osppsvc) -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
 SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
 SRV - (AdobeActiveFileMonitor8.0) -- C:\Programme\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
 SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
 SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
 ========== Driver Services (SafeList) ==========
 
 DRV - (catchme) -- C:\Users\Xxx\AppData\Local\Temp\catchme.sys File not found
 DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
 DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
 DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
 DRV - (avgtp) -- C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
 DRV - (SKYNET) -- C:\Windows\System32\drivers\SkyNET.sys (TechniSat Digital, S.A.)
 DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
 DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
 DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
 DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
 DRV - (epmntdrv) -- C:\Windows\System32\epmntdrv.sys ()
 DRV - (EuGdiDrv) -- C:\Windows\System32\EuGdiDrv.sys ()
 DRV - (LGVirHid) -- C:\Windows\System32\drivers\LGVirHid.sys (Logitech Inc.)
 DRV - (LGBusEnum) -- C:\Windows\System32\drivers\LGBusEnum.sys (Logitech Inc.)
 DRV - (AtcL001) -- C:\Windows\System32\drivers\l160x86.sys (Atheros Communications, Inc.)
 DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
 DRV - (AsIO) -- C:\Windows\System32\drivers\AsIO.sys ()
 DRV - (ElbyCDFL) -- C:\Windows\System32\drivers\ElbyCDFL.sys (Elaborate Bytes AG)
 
 
 ========== Standard Registry (SafeList) ==========
 
 
 ========== Internet Explorer ==========
 
 IE - HKLM\..\SearchScopes,DefaultScope =
 IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
 IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 56 74 EA 8A 18 A7 CD 01  [binary data]
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1001\..\SearchScopes,DefaultScope =
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 IE - HKU\S-1-5-21-2986282668-171375975-58925643-1003\..\SearchScopes,DefaultScope =
 
 ========== FireFox ==========
 
 FF - prefs.js..browser.search.selectedEngine: "Google"
 FF - prefs.js..browser.search.useDBForOrder: true
 FF - prefs.js..browser.startup.homepage: "hxxp://web.de/"
 FF - prefs.js..extensions.enabledAddons: toolbar%40web.de:2.3.4.1
 FF - prefs.js..extensions.enabledAddons: %7Bdc572301-7619-498c-a57d-39143191b318%7D:0.4.0.3.1
 FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.1
 FF - prefs.js..extensions.enabledAddons: %7Bc50ca3c4-5656-43c2-a061-13e717f73fc8%7D:4.2.4
 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
 FF - user.js - File not found
 
 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
 FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
 FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
 FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
 FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
 FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.12.07 12:27:47 | 000,000,000 | ---D | M]
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.12.07 12:27:43 | 000,000,000 | ---D | M]
 FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.12.07 12:27:47 | 000,000,000 | ---D | M]
 FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.12.07 12:27:43 | 000,000,000 | ---D | M]
 
 [2012.10.04 22:02:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\Extensions
 [2012.12.15 18:20:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\Firefox\Profiles\l4ouc8my.default\extensions
 [2012.12.02 21:37:50 | 000,566,966 | ---- | M] () (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\extensions\toolbar@web.de.xpi
 [2012.12.09 17:44:28 | 000,347,581 | ---- | M] () (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
 [2012.12.15 18:20:43 | 000,316,317 | ---- | M] () (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi
 [2012.11.25 16:01:25 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
 [2012.11.30 13:59:10 | 000,710,866 | ---- | M] () (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
 [2012.12.08 13:52:57 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
 [2012.12.02 21:37:53 | 000,002,273 | ---- | M] () -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\searchplugins\englische-ergebnisse.xml
 [2012.12.02 21:37:53 | 000,010,563 | ---- | M] () -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\searchplugins\gmx-suche.xml
 [2012.12.02 21:37:53 | 000,002,432 | ---- | M] () -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\searchplugins\lastminute.xml
 [2012.12.02 21:37:53 | 000,005,545 | ---- | M] () -- C:\Users\Xxx\AppData\Roaming\mozilla\firefox\profiles\l4ouc8my.default\searchplugins\webde-suche.xml
 [2012.12.07 12:27:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
 [2012.12.07 12:27:47 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
 [2011.12.09 18:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
 [2012.11.02 09:12:26 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
 [2012.11.02 09:12:26 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
 [2012.11.02 09:12:26 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
 [2012.11.02 09:12:26 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
 [2012.11.02 09:12:26 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
 [2012.11.02 09:12:26 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
 O1 HOSTS File: ([2012.12.23 10:29:37 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
 O1 - Hosts: 127.0.0.1       localhost
 O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
 O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
 O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
 O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
 O4 - HKLM..\Run: [CloneCDElbyCDFL] C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe (Elaborate Bytes AG)
 O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
 O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
 O4 - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
 O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
 O4 - HKU\S-1-5-21-2986282668-171375975-58925643-1001..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
 O4 - HKU\S-1-5-21-2986282668-171375975-58925643-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
 O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O7 - HKU\S-1-5-21-2986282668-171375975-58925643-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O7 - HKU\S-1-5-21-2986282668-171375975-58925643-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
 O7 - HKU\S-1-5-21-2986282668-171375975-58925643-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
 O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
 O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
 O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
 O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B9F1D5D-50DF-4CF7-8F33-5CB646D4F9B7}: DhcpNameServer = 0.0.0.0
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D75BEE7C-FAF2-453E-9A79-54EA6940B384}: DhcpNameServer = 192.168.178.1
 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
 O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
 O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
 O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
 O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
 O32 - HKLM CDRom: AutoRun - 1
 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
 O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - I:\autoexec.bat -- [ NTFS ]
 O34 - HKLM BootExecute: (autocheck autochk *)
 O35 - HKLM\..comfile [open] -- "%1" %*
 O35 - HKLM\..exefile [open] -- "%1" %*
 O37 - HKLM\...com [@ = ComFile] -- "%1" %*
 O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
 O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
 ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
 ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
 ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
 ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
 ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
 ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
 ActiveX: {60702D8B-5E32-B289-79CA-87872305474F} - Microsoft Windows Media Player 12.0
 ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
 ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
 ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
 ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
 ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
 ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
 ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
 ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
 ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
 ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
 ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
 ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
 ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
 ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
 NetSvcs: FastUserSwitchingCompatibility -  File not found
 NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
 NetSvcs: Nla -  File not found
 NetSvcs: Ntmssvc -  File not found
 NetSvcs: NWCWorkstation -  File not found
 NetSvcs: Nwsapagent -  File not found
 NetSvcs: SRService -  File not found
 NetSvcs: WmdmPmSp -  File not found
 NetSvcs: LogonHours -  File not found
 NetSvcs: PCAudit -  File not found
 NetSvcs: helpsvc -  File not found
 NetSvcs: uploadmgr -  File not found
 
 
 Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
 Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
 
 SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
 SafeBootMin: Base - Driver Group
 SafeBootMin: Boot Bus Extender - Driver Group
 SafeBootMin: Boot file system - Driver Group
 SafeBootMin: File system - Driver Group
 SafeBootMin: Filter - Driver Group
 SafeBootMin: HelpSvc - Service
 SafeBootMin: NTDS -  File not found
 SafeBootMin: PCI Configuration - Driver Group
 SafeBootMin: PNP Filter - Driver Group
 SafeBootMin: Primary disk - Driver Group
 SafeBootMin: sacsvr - Service
 SafeBootMin: SCSI Class - Driver Group
 SafeBootMin: System Bus Extender - Driver Group
 SafeBootMin: vmms - Service
 SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
 SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
 SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
 SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
 SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
 SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
 SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
 SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
 SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
 SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
 SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
 SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
 SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
 SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
 SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
 SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
 SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
 SafeBootNet: Base - Driver Group
 SafeBootNet: Boot Bus Extender - Driver Group
 SafeBootNet: Boot file system - Driver Group
 SafeBootNet: File system - Driver Group
 SafeBootNet: Filter - Driver Group
 SafeBootNet: HelpSvc - Service
 SafeBootNet: Messenger - Service
 SafeBootNet: NDIS Wrapper - Driver Group
 SafeBootNet: NetBIOSGroup - Driver Group
 SafeBootNet: NetDDEGroup - Driver Group
 SafeBootNet: Network - Driver Group
 SafeBootNet: NetworkProvider - Driver Group
 SafeBootNet: NTDS -  File not found
 SafeBootNet: PCI Configuration - Driver Group
 SafeBootNet: PNP Filter - Driver Group
 SafeBootNet: PNP_TDI - Driver Group
 SafeBootNet: Primary disk - Driver Group
 SafeBootNet: rdsessmgr - Service
 SafeBootNet: sacsvr - Service
 SafeBootNet: SCSI Class - Driver Group
 SafeBootNet: Streams Drivers - Driver Group
 SafeBootNet: System Bus Extender - Driver Group
 SafeBootNet: TDI - Driver Group
 SafeBootNet: vmms - Service
 SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 SafeBootNet: WudfUsbccidDriver - Driver
 SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
 SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
 SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
 SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
 SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
 SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
 SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
 SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
 SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
 SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
 SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
 SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
 SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
 SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
 SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
 SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
 SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
 SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
 SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
 SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
 SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
 SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
 CREATERESTOREPOINT
 Restore point Set: OTL Restore Point
 
 ========== Files/Folders - Created Within 30 Days ==========
 
 [2012.12.23 10:32:52 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
 [2012.12.23 10:32:48 | 000,000,000 | ---D | C] -- C:\Windows\temp
 [2012.12.23 10:32:48 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Local\temp
 [2012.12.23 10:19:22 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
 [2012.12.23 10:19:22 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
 [2012.12.23 10:19:22 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
 [2012.12.23 10:14:51 | 000,000,000 | ---D | C] -- C:\Qoobox
 [2012.12.23 10:14:44 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
 [2012.12.23 10:10:44 | 005,012,898 | R--- | C] (Swearware) -- C:\Users\Xxx\Desktop\ComboFix.exe
 [2012.12.22 20:12:25 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Xxx\Desktop\dds.com
 [2012.12.22 20:12:11 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\Xxx\Desktop\TFC.exe
 [2012.12.22 12:12:39 | 000,937,224 | ---- | C] (Crawler.com                                                 ) -- C:\Users\Xxx\Desktop\SpywareTerminator30074Setup.exe
 [2012.12.22 10:48:26 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\Malwarebytes
 [2012.12.22 10:48:17 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
 [2012.12.22 10:48:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
 [2012.12.22 10:48:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
 [2012.12.22 10:48:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
 [2012.12.22 10:47:53 | 010,669,952 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Xxx\Desktop\mbam-setup-1.65.1.1000.exe
 [2012.12.21 21:49:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Xxx\Desktop\OTL.exe
 [2012.12.21 21:47:47 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Xxx\Desktop\tdsskiller.exe
 [2012.12.18 03:19:09 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Local\Microsoft Games
 [2012.12.17 21:44:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exifer
 [2012.12.17 21:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\Exifer
 [2012.12.12 21:37:33 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
 [2012.12.12 21:37:32 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
 [2012.12.12 21:37:32 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
 [2012.12.12 21:37:31 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
 [2012.12.12 21:37:31 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
 [2012.12.12 21:37:30 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
 [2012.12.12 21:37:30 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
 [2012.12.12 21:37:28 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
 [2012.12.12 21:27:50 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
 [2012.12.12 21:27:47 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
 [2012.12.12 21:27:47 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
 [2012.12.12 21:27:46 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
 [2012.12.12 21:27:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
 [2012.12.12 21:27:42 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
 [2012.12.12 21:27:39 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
 [2012.12.11 13:20:49 | 000,000,000 | ---D | C] -- g:\Eigene Dateien\DVDFab Passkey
 [2012.12.11 09:54:54 | 000,000,000 | ---D | C] -- g:\Eigene Dateien\Eigene Projekte bei druckstdu
 [2012.12.10 22:58:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\druckstdu.de
 [2012.12.10 21:25:25 | 000,000,000 | ---D | C] -- C:\Program Files\druckstdu.de
 [2012.12.10 20:13:35 | 000,000,000 | ---D | C] -- C:\Users\Xxx\Desktop\Sabine
 [2012.12.07 23:12:16 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maniac Mansion Deluxe
 [2012.12.07 23:12:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maniac Mansion Deluxe
 [2012.12.07 23:11:41 | 000,000,000 | ---D | C] -- C:\Program Files\LucasFan Games
 [2012.12.07 21:48:56 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\DVDFab
 [2012.12.07 12:27:43 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
 [2012.12.05 23:08:37 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\Media Player Classic
 [2012.12.05 23:07:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC
 [2012.12.05 23:07:57 | 000,000,000 | ---D | C] -- C:\Program Files\MPC-HC
 [2012.11.30 19:05:57 | 000,000,000 | ---D | C] -- C:\ISO
 [2012.11.30 18:59:07 | 000,000,000 | ---D | C] -- C:\ProgramData\dvdfab
 [2012.11.30 18:58:23 | 000,000,000 | ---D | C] -- C:\Temp
 [2012.11.30 18:54:28 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\NVIDIA
 [2012.11.30 18:54:28 | 000,000,000 | ---D | C] -- C:\Log
 [2012.11.30 18:54:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt
 [2012.11.30 18:54:19 | 000,000,000 | ---D | C] -- C:\Program Files\DVDFab 8 Qt
 [2012.11.30 14:00:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoGebra
 [2012.11.30 14:00:11 | 000,000,000 | ---D | C] -- C:\Program Files\GeoGebra
 [2012.11.30 13:58:51 | 000,000,000 | ---D | C] -- C:\Users\Xxx\AppData\Roaming\mathegrafix
 [2012.10.07 12:11:19 | 000,270,406 | ---- | C] (DVD Shrink) -- C:\Program Files\DVD Shrink 3.0 Beta 5.exe
 
 ========== Files - Modified Within 30 Days ==========
 
 [2012.12.23 15:38:44 | 000,014,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 [2012.12.23 15:38:44 | 000,014,928 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 [2012.12.23 15:38:26 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
 [2012.12.23 15:38:26 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
 [2012.12.23 15:38:26 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
 [2012.12.23 15:38:26 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
 [2012.12.23 15:31:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
 [2012.12.23 15:31:22 | 2364,940,288 | -HS- | M] () -- C:\hiberfil.sys
 [2012.12.23 10:30:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
 [2012.12.23 10:29:37 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
 [2012.12.23 10:10:56 | 005,012,898 | R--- | M] (Swearware) -- C:\Users\Xxx\Desktop\ComboFix.exe
 [2012.12.22 20:12:26 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Xxx\Desktop\dds.com
 [2012.12.22 20:12:13 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\Xxx\Desktop\TFC.exe
 [2012.12.22 20:12:02 | 000,547,175 | ---- | M] () -- C:\Users\Xxx\Desktop\adwcleaner.exe
 [2012.12.22 12:12:39 | 000,937,224 | ---- | M] (Crawler.com                                                 ) -- C:\Users\Xxx\Desktop\SpywareTerminator30074Setup.exe
 [2012.12.22 10:48:18 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 [2012.12.22 10:47:56 | 010,669,952 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Xxx\Desktop\mbam-setup-1.65.1.1000.exe
 [2012.12.21 21:49:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Xxx\Desktop\OTL.exe
 [2012.12.21 21:47:47 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Xxx\Desktop\tdsskiller.exe
 [2012.12.21 06:19:38 | 000,425,671 | ---- | M] () -- C:\Users\Xxx\Desktop\Weihnachtsbild.jpg
 [2012.12.21 06:17:46 | 000,620,248 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
 [2012.12.17 21:44:50 | 000,000,888 | ---- | M] () -- C:\Users\Xxx\Desktop\Exifer.lnk
 [2012.12.11 15:28:23 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
 [2012.12.11 15:28:23 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
 [2012.12.11 13:22:01 | 000,000,336 | ---- | M] () -- C:\Users\Xxx\Desktop\BR-Laufwerk (X).lnk
 [2012.12.09 17:44:02 | 001,422,466 | ---- | M] () -- C:\Users\Xxx\Desktop\Ritterburg.mp4
 [2012.12.05 16:12:56 | 000,220,298 | ---- | M] () -- C:\Users\Xxx\Desktop\Baustelle.jpg
 [2012.11.30 18:54:24 | 000,000,973 | ---- | M] () -- C:\Users\Xxx\Desktop\DVDFab 8 Qt.lnk
 [2012.11.30 17:17:20 | 000,050,277 | ---- | M] () -- C:\Users\Xxx\Desktop\Terminplan CSG.pdf
 [2012.11.30 14:00:13 | 000,001,778 | ---- | M] () -- C:\Users\Public\Desktop\GeoGebra.lnk
 
 ========== Files Created - No Company Name ==========
 
 [2012.12.23 10:19:22 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
 [2012.12.23 10:19:22 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
 [2012.12.23 10:19:22 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
 [2012.12.23 10:19:22 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
 [2012.12.23 10:19:22 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
 [2012.12.22 20:12:02 | 000,547,175 | ---- | C] () -- C:\Users\Xxx\Desktop\adwcleaner.exe
 [2012.12.22 12:33:39 | 000,032,768 | ---- | C] () -- C:\Windows\System32\drivers\sp_rsdrv2.sys
 [2012.12.22 10:48:18 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 [2012.12.21 06:19:38 | 000,425,671 | ---- | C] () -- C:\Users\Xxx\Desktop\Weihnachtsbild.jpg
 [2012.12.17 21:44:50 | 000,000,888 | ---- | C] () -- C:\Users\Xxx\Desktop\Exifer.lnk
 [2012.12.11 13:22:01 | 000,000,336 | ---- | C] () -- C:\Users\Xxx\Desktop\BR-Laufwerk (X).lnk
 [2012.12.09 17:44:02 | 001,422,466 | ---- | C] () -- C:\Users\Xxx\Desktop\Ritterburg.mp4
 [2012.12.05 16:05:34 | 000,220,298 | ---- | C] () -- C:\Users\Xxx\Desktop\Baustelle.jpg
 [2012.11.30 18:54:24 | 000,000,973 | ---- | C] () -- C:\Users\Xxx\Desktop\DVDFab 8 Qt.lnk
 [2012.11.30 17:17:20 | 000,050,277 | ---- | C] () -- C:\Users\Xxx\Desktop\Terminplan CSG.pdf
 [2012.11.30 14:00:13 | 000,001,778 | ---- | C] () -- C:\Users\Public\Desktop\GeoGebra.lnk
 [2012.10.08 18:44:00 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
 [2012.10.08 18:43:59 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe
 [2012.10.08 18:43:59 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
 [2012.10.08 18:43:59 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
 [2012.10.08 18:43:59 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
 [2012.10.05 21:35:35 | 000,000,416 | ---- | C] () -- C:\Windows\BRWMARK.INI
 [2012.10.05 21:35:34 | 000,000,065 | ---- | C] () -- C:\Windows\System32\BD7045N.DAT
 [2012.10.05 21:34:56 | 000,045,056 | ---- | C] () -- C:\Windows\System32\BRTCPCON.DLL
 [2012.10.05 21:34:54 | 000,000,114 | ---- | C] () -- C:\Windows\System32\BRLMW03A.INI
 [2012.10.05 18:41:35 | 000,024,576 | ---- | C] () -- C:\Windows\System32\AsIO.dll
 [2012.10.05 18:41:35 | 000,012,400 | ---- | C] () -- C:\Windows\System32\drivers\AsIO.sys
 [2012.10.04 21:20:44 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
 
 ========== ZeroAccess Check ==========
 
 [2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
 [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
 [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
 [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
 "ThreadingModel" = Apartment
 
 [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
 "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 03:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
 "ThreadingModel" = Free
 
 [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
 "ThreadingModel" = Both
 
 ========== LOP Check ==========
 
 [2012.10.07 12:13:10 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Design Science
 [2012.12.07 21:48:56 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\DVDFab
 [2012.10.09 23:15:59 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\FastCopy
 [2012.11.30 13:58:51 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\mathegrafix
 [2012.10.08 20:33:03 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Mp3tag
 [2012.10.07 12:05:50 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\OpenOffice.org
 [2012.12.16 11:40:03 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\PersBackup5
 [2012.12.18 21:34:31 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\TV-Browser
 [2012.10.04 22:57:47 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\UBitMenu
 
 ========== Purity Check ==========
 
 
 
 ========== Custom Scans ==========
 
 < %SYSTEMDRIVE%\*. >
 [2012.12.23 10:32:53 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
 [2012.10.31 23:28:12 | 000,000,000 | ---D | M] -- C:\Boot
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
 [2012.10.04 21:20:44 | 000,000,000 | ---D | M] -- C:\Intel
 [2012.11.30 19:05:57 | 000,000,000 | ---D | M] -- C:\ISO
 [2012.11.30 19:00:47 | 000,000,000 | ---D | M] -- C:\Log
 [2012.10.04 22:22:01 | 000,000,000 | R--D | M] -- C:\MSOCache
 [2012.10.10 11:49:35 | 000,000,000 | ---D | M] -- C:\NST
 [2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs
 [2012.12.23 10:10:20 | 000,000,000 | R--D | M] -- C:\Program Files
 [2012.12.23 10:10:20 | 000,000,000 | ---D | M] -- C:\ProgramData
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\Programme
 [2012.12.23 10:32:50 | 000,000,000 | ---D | M] -- C:\Qoobox
 [2012.10.04 21:09:47 | 000,000,000 | ---D | M] -- C:\Recovery
 [2012.10.11 18:38:25 | 000,000,000 | ---D | M] -- C:\SharePoint-Entwürfe
 [2012.12.23 15:50:14 | 000,000,000 | -HSD | M] -- C:\System Volume Information
 [2012.11.30 19:00:49 | 000,000,000 | ---D | M] -- C:\Temp
 [2012.10.04 21:25:24 | 000,000,000 | R--D | M] -- C:\Users
 [2012.12.23 10:32:48 | 000,000,000 | ---D | M] -- C:\Windows
 
 < %SYSTEMDRIVE%\*.* >
 [2012.12.22 20:13:15 | 000,005,341 | ---- | M] () -- C:\AdwCleaner[S1].txt
 [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
 [2012.10.10 11:49:41 | 000,000,345 | RHS- | M] () -- C:\boot.ini
 [2004.08.04 13:00:00 | 000,004,952 | RHS- | M] () -- C:\bootfont.bin
 [2012.10.30 09:47:14 | 000,383,786 | RHS- | M] () -- C:\bootmgr
 [2012.12.23 10:32:46 | 000,012,919 | ---- | M] () -- C:\ComboFix.txt
 [2009.06.10 22:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
 [2012.12.23 15:31:22 | 2364,940,288 | -HS- | M] () -- C:\hiberfil.sys
 [2012.10.10 11:39:23 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
 [2012.10.10 13:39:41 | 000,118,904 | ---- | M] () -- C:\metal.jpg
 [2012.10.10 11:39:23 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
 [2012.10.10 11:49:41 | 000,047,772 | RHS- | M] () -- C:\NTDETECT.COM
 [2008.04.13 23:01:56 | 000,251,712 | RHS- | M] () -- C:\ntldr
 [2012.12.23 15:31:23 | 3153,256,448 | -HS- | M] () -- C:\pagefile.sys
 [2012.12.21 21:48:15 | 000,257,784 | ---- | M] () -- C:\TDSSKiller.2.8.15.0_21.12.2012_21.47.55_log.txt
 
 < %PROGRAMFILES%\*.* >
 [2009.07.14 05:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
 [2003.08.16 01:57:36 | 000,270,406 | ---- | M] (DVD Shrink) -- C:\Program Files\DVD Shrink 3.0 Beta 5.exe
 Invalid Environment Variable: PROGRAMFILES(X86)
 
 < %appdata%\*.  >
 [2012.10.20 14:29:39 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Adobe
 [2012.10.10 07:13:28 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Ahead
 [2012.10.04 22:12:57 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Avira
 [2012.10.07 12:13:10 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Design Science
 [2012.11.30 19:37:28 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\DVD Shrink 3.0
 [2012.11.08 10:53:06 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\dvdcss
 [2012.12.07 21:48:56 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\DVDFab
 [2012.10.09 23:15:59 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\FastCopy
 [2012.10.04 21:10:10 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Identities
 [2012.10.05 21:34:36 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\InstallShield
 [2012.10.04 22:10:02 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Macromedia
 [2012.12.22 10:48:26 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Malwarebytes
 [2012.11.30 13:58:51 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\mathegrafix
 [2009.07.14 09:56:41 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Media Center Programs
 [2012.12.05 23:08:37 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Media Player Classic
 [2012.10.11 15:09:04 | 000,000,000 | --SD | M] -- C:\Users\Xxx\AppData\Roaming\Microsoft
 [2012.10.04 22:02:31 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Mozilla
 [2012.10.08 20:33:03 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Mp3tag
 [2012.11.30 18:54:28 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\NVIDIA
 [2012.10.07 12:05:50 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\OpenOffice.org
 [2012.12.16 11:40:03 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\PersBackup5
 [2012.12.18 21:34:31 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\TV-Browser
 [2012.10.04 22:57:47 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\UBitMenu
 [2012.12.18 09:03:39 | 000,000,000 | -H-D | M] -- C:\Users\Xxx\AppData\Roaming\vlc
 [2012.10.04 22:49:34 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Roaming\Winamp
 
 < %appdata%\*.*  >
 
 < %localappdata%\*.  >
 [2012.10.12 19:02:28 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Adobe
 [2012.10.08 21:23:17 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Ahead
 [2012.10.04 21:10:01 | 000,000,000 | -HSD | M] -- C:\Users\Xxx\AppData\Local\Anwendungsdaten
 [2012.12.08 08:47:49 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Diagnostics
 [2012.10.20 13:15:54 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Logitech
 [2012.10.04 22:10:02 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Macromedia
 [2012.12.17 21:31:12 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Microsoft
 [2012.12.18 03:33:25 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Microsoft Games
 [2012.10.10 07:30:36 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Microsoft Help
 [2012.10.04 22:02:27 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\Mozilla
 [2012.10.09 18:12:29 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\NeoSmart_Technologies
 [2012.12.23 15:48:39 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\temp
 [2012.10.04 21:10:01 | 000,000,000 | -HSD | M] -- C:\Users\Xxx\AppData\Local\Temporary Internet Files
 [2012.10.04 21:10:01 | 000,000,000 | -HSD | M] -- C:\Users\Xxx\AppData\Local\Verlauf
 [2012.10.08 20:25:37 | 000,000,000 | ---D | M] -- C:\Users\Xxx\AppData\Local\VirtualStore
 
 < %localappdata%\*.* >
 [2012.12.10 21:25:45 | 000,137,488 | ---- | M] () -- C:\Users\Xxx\AppData\Local\GDIPFONTCACHEV1.DAT
 [2012.12.23 14:03:39 | 004,875,487 | -H-- | M] () -- C:\Users\Xxx\AppData\Local\IconCache.db
 
 < %allusersprofile%\*.  >
 [2012.11.13 14:43:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe
 [2012.10.08 21:16:59 | 000,000,000 | ---D | M] -- C:\ProgramData\Ahead
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
 [2012.10.04 22:07:06 | 000,000,000 | ---D | M] -- C:\ProgramData\Avira
 [2012.11.06 17:10:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Battle.net
 [2012.11.18 10:22:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Blizzard Entertainment
 [2012.10.05 21:34:40 | 000,000,000 | ---D | M] -- C:\ProgramData\Brother
 [2012.10.11 13:51:46 | 000,000,000 | ---D | M] -- C:\ProgramData\CMUV
 [2012.10.16 22:43:35 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
 [2012.11.30 18:59:07 | 000,000,000 | ---D | M] -- C:\ProgramData\dvdfab
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
 [2012.10.16 19:53:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\FLEXnet
 [2012.10.20 13:15:39 | 000,000,000 | ---D | M] -- C:\ProgramData\Logitech
 [2012.12.22 10:48:17 | 000,000,000 | ---D | M] -- C:\ProgramData\Malwarebytes
 [2012.10.11 15:09:04 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft
 [2012.12.12 21:38:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help
 [2012.10.04 22:02:19 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla
 [2012.10.08 21:14:44 | 000,000,000 | ---D | M] -- C:\ProgramData\Nero
 [2012.12.23 15:31:28 | 000,000,000 | ---D | M] -- C:\ProgramData\NVIDIA
 [2012.10.04 21:24:32 | 000,000,000 | ---D | M] -- C:\ProgramData\NVIDIA Corporation
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
 [2012.10.08 19:43:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\Sun
 [2012.10.08 18:32:47 | 000,000,000 | ---D | M] -- C:\ProgramData\Synology
 [2012.10.11 13:50:25 | 000,000,000 | ---D | M] -- C:\ProgramData\Technisat
 [2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
 [2012.10.04 21:09:47 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
 
 < %allusersprofile%\*.* >
 
 <           >
 [2009.07.14 05:53:46 | 000,032,630 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 [2009.07.14 05:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
 [2012.10.04 22:09:29 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
 
 < End of report >
 und hier Extras.txt:   Code: 
 OTL Extras logfile created on: 23.12.2012 15:48:59 - Run 4OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Xxx\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
 Internet Explorer (Version = 9.0.8112.16421)
 Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
 2,94 Gb Total Physical Memory | 2,21 Gb Available Physical Memory | 75,09% Memory free
 5,87 Gb Paging File | 5,14 Gb Available in Paging File | 87,56% Paging File free
 Paging file location(s): ?:\pagefile.sys [binary data]
 
 %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
 Drive C: | 109,38 Gb Total Space | 78,25 Gb Free Space | 71,54% Space Free | Partition Type: NTFS
 Drive D: | 1397,26 Gb Total Space | 128,20 Gb Free Space | 9,17% Space Free | Partition Type: NTFS
 Drive E: | 931,51 Gb Total Space | 463,28 Gb Free Space | 49,73% Space Free | Partition Type: NTFS
 Drive G: | 9,86 Gb Total Space | 5,73 Gb Free Space | 58,14% Space Free | Partition Type: NTFS
 Drive H: | 1863,01 Gb Total Space | 486,36 Gb Free Space | 26,11% Space Free | Partition Type: NTFS
 Drive I: | 58,92 Gb Total Space | 1,41 Gb Free Space | 2,40% Space Free | Partition Type: NTFS
 Unable to calculate disk information.
 
 Computer Name: XXX | User Name: Xxx | Logged in as Administrator.
 Boot Mode: Normal | Scan Mode: All users
 Company Name Whitelist: On | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
 ========== Extra Registry (SafeList) ==========
 
 
 ========== File Associations ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
 .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
 .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
 [HKEY_USERS\S-1-5-21-2986282668-171375975-58925643-1001\SOFTWARE\Classes\<extension>]
 .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
 ========== Shell Spawning ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
 batfile [open] -- "%1" %*
 cmdfile [open] -- "%1" %*
 comfile [open] -- "%1" %*
 cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
 exefile [open] -- "%1" %*
 helpfile [open] -- Reg Error: Key error.
 hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
 htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
 inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
 piffile [open] -- "%1" %*
 regfile [merge] -- Reg Error: Key error.
 scrfile [config] -- "%1"
 scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
 scrfile [open] -- "%1" /S
 txtfile [edit] -- Reg Error: Key error.
 Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
 Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 Folder [explore] -- Reg Error: Value error.
 Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
 ========== Security Center Settings ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 "cval" = 1
 "FirewallDisableNotify" = 0
 "AntiVirusDisableNotify" = 0
 "UpdatesDisableNotify" = 0
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 "VistaSp1" = Reg Error: Unknown registry data type -- File not found
 "AntiVirusOverride" = 0
 "AntiSpywareOverride" = 0
 "FirewallOverride" = 0
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
 ========== System Restore Settings ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
 "DisableSR" = 0
 
 ========== Firewall Settings ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 "DisableNotifications" = 0
 "EnableFirewall" = 1
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
 "DisableNotifications" = 0
 "EnableFirewall" = 1
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
 "DisableNotifications" = 0
 "EnableFirewall" = 1
 
 ========== Authorized Applications List ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
 ========== Vista Active Open Ports Exception List ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 "{260ECEF8-52FE-4CE4-83FA-467B97E894FC}" = rport=138 | protocol=17 | dir=out | app=system |
 "{41A0709A-827F-4025-B57D-74BB2F9950FA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
 "{545EACDB-DBC3-4B6B-897F-6DD43827A346}" = rport=139 | protocol=6 | dir=out | app=system |
 "{559E74D7-9B52-4217-9A92-5C21E5F0F7D9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
 "{659B67BA-4FA0-4DC1-8823-8ED1ECFC184B}" = rport=445 | protocol=6 | dir=out | app=system |
 "{7E9A995B-DEEB-4201-87A1-16D85605DFF7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
 "{84CD4A86-27B2-4C35-9B92-7F44F1D5C95F}" = lport=445 | protocol=6 | dir=in | app=system |
 "{8A2C4E55-0506-4F1A-957D-59CD2398C685}" = rport=10243 | protocol=6 | dir=out | app=system |
 "{8DAB3CCD-E003-4445-84D1-F1D7FFDC50B2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
 "{8E0E4018-0DB3-489C-9A74-A022139A8C5B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{ABBADDA1-F2ED-4660-985D-BAB53B1067C8}" = rport=137 | protocol=17 | dir=out | app=system |
 "{B0474B44-05B5-4757-9CF5-B9E18873FC66}" = lport=10243 | protocol=6 | dir=in | app=system |
 "{B82868D5-A801-4322-AC5F-E69E5C02280F}" = lport=2869 | protocol=6 | dir=in | app=system |
 "{B8D885D1-F707-4A94-8A43-878A0D7535F1}" = lport=139 | protocol=6 | dir=in | app=system |
 "{C1F587F0-AED2-4BA5-B0FB-0874C516C39D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{C6152428-57E2-44D9-A445-F03F6E77893C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 "{D99AEA42-00B3-41B9-9A84-F96240CE15AF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{DAF53D5E-15A0-422E-8D7F-6C951724DD0B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
 "{DBFD28BB-8052-413D-BE88-BB75E07155EB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{EB6F6967-6F63-4E66-988F-FA80CB196702}" = lport=138 | protocol=17 | dir=in | app=system |
 "{EE8D16DC-15AA-46B0-AF5A-AA65AE6B60FB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 "{F1B44D30-2543-41C2-BAE5-4E0DEAA9E962}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
 "{FD5131B6-D822-4E61-9D1D-5544548D5440}" = lport=137 | protocol=17 | dir=in | app=system |
 
 ========== Vista Active Application Exception List ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 "{19796979-1808-43DB-9B89-9320BEFADBBA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
 "{31EE915A-503B-4AE2-8DA2-E3CB579EF921}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
 "{331CE90D-5850-4B1F-9978-68F835FF82F5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
 "{4EAEE201-599C-4A4B-A876-F39181903BCC}" = protocol=17 | dir=in | app=c:\program files\tv-browser\tvbrowser_nodd.exe |
 "{5A2F64AA-9801-4449-B914-B910C9E88939}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
 "{5B6CDA8C-E0FE-4D11-B257-033ECD8EE054}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
 "{5D64DB2B-F68C-4111-AF60-6E408548E813}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{6BDE143B-10F2-41EB-B38E-54BC2C6BE088}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
 "{71DAFC11-BB9E-43F0-B8C5-CABD4FAB3B0A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{72021E8C-6E99-485F-AE3D-3027F95ABB83}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
 "{734FE830-5927-4BF1-B1C9-CADCFB0FAFFD}" = protocol=6 | dir=out | app=system |
 "{80BBD45E-DB51-433F-9F7C-C630D3F416E4}" = protocol=6 | dir=in | app=c:\program files\tv-browser\tvbrowser_nodd.exe |
 "{96CEEA04-C5B3-473D-A2F1-07D4394AC1FD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{A02DFE4C-6965-4AB8-B580-4C51DAD967C7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
 "{AFA82716-CA98-43A0-B7DE-C3208F270DCA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{B7176462-52C7-4BF3-BD5D-213FB5E2E6CD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
 "{C1107AFA-4F09-400B-8581-048D026475DC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{D02EABCC-219E-4002-B381-B4BE5B898167}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{D87F70C5-EAA3-454C-8006-9FB8467511D0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{DA608886-664D-4EC7-8AC0-746C9C2A6F5E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
 "{E407F026-8824-4A0D-863F-EDA8279B416D}" = protocol=17 | dir=in | app=c:\program files\tv-browser\tvbrowser.exe |
 "{E5422EBC-023F-41A7-9BF8-0E3D7A1DCA8C}" = protocol=6 | dir=in | app=c:\program files\tv-browser\tvbrowser.exe |
 "{E759D9F3-F553-44F7-89BC-B4D5F66EE3A4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
 "{FEB7DCAB-AD02-4E9E-BA39-2FAF60695CA2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
 "TCP Query User{2165B3DD-AFEA-4CD2-B281-B9F8779EB888}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
 "TCP Query User{78542CE7-F2B5-416C-8177-8010FF71E7E9}C:\users\Xxx\desktop\dsassistant_1920\win\dsassistant.exe" = protocol=6 | dir=in | app=c:\users\Xxx\desktop\dsassistant_1920\win\dsassistant.exe |
 "TCP Query User{943F4162-5872-42B4-AFFC-AB43B3B68AEE}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
 "TCP Query User{A84A81F1-72BB-4A81-8C4E-5DE1F2870A12}I:\program files\starcraft ii\versions\base23260\sc2.exe" = protocol=6 | dir=in | app=i:\program files\starcraft ii\versions\base23260\sc2.exe |
 "UDP Query User{1B4C0DC6-C1E8-4899-93E3-9E0207C0157B}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
 "UDP Query User{7C8E696C-9BC7-409F-B0C2-D24E179402BA}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
 "UDP Query User{84BE70BB-F338-41BA-8BF4-54E4428CAA65}C:\users\Xxx\desktop\dsassistant_1920\win\dsassistant.exe" = protocol=17 | dir=in | app=c:\users\Xxx\desktop\dsassistant_1920\win\dsassistant.exe |
 "UDP Query User{93F511FF-F405-48BD-AADE-EFF271973B63}I:\program files\starcraft ii\versions\base23260\sc2.exe" = protocol=17 | dir=in | app=i:\program files\starcraft ii\versions\base23260\sc2.exe |
 
 ========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 "{109945A8-D8D5-48B8-B4A5-195D3F99B56D}" = Logitech GamePanel Software 3.04.143
 "{1719FAD6-2F6A-4F5E-BF2B-1F6F6F1E3806_PasswordRemover}_is1" = Wondershare PDF Password Remover (Build 1.3.0)
 "{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
 "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1
 "{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = MPC-HC 1.6.4.6052
 "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
 "{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
 "{46E1B1F2-A279-4356-9B17-029F9CC72EAE}" = Brother MFL-Pro Suite DCP-7045N
 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
 "{6E19F210-3813-4002-B561-94D66AA182B6}" = Attansic L1 Gigabit Ethernet Driver
 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
 "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
 "{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
 "{98EFD8F0-08DE-48DB-B922-A2EBAB711031}" = Nero 7 Premium
 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
 "{A066194B-DC8F-449A-8E0F-B57BDD3A2072}" = SyncToy 2.1 (x86)
 "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 306.97
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 306.23
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0604
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
 "{CBCFD97D-FE82-43F4-A978-996CACF71E6B}_is1" = UBitMenuDE
 "{D3A80508-CD83-4CA3-8671-914A1BC78B61}" = Microsoft Sync Framework 2.0 Provider Services (x86) ENU
 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
 "{FF63121D-91C6-42CC-B341-F1AA729728E7}" = Microsoft Sync Framework 2.0 Core Components (x86) ENU
 "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
 "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
 "Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
 "Avira AntiVir Desktop" = Avira Free Antivirus
 "CloneCD" = CloneCD
 "druckstdu.de Designer 1.6.9_is1" = druckstdu.de Designer 1.6.9
 "DSMT5" = MathType 5
 "DVDFab 8 Qt_is1" = DVDFab 8.2.2.2 (23/11/2012) Qt
 "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.1 Home Edition
 "EasyBCD" = EasyBCD 2.2
 "Exifer_is1" = Exifer
 "GeoGebra" = GeoGebra
 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
 "Maniac Mansion Deluxe" = Maniac Mansion Deluxe
 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
 "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
 "Mozilla Firefox 17.0.1 (x86 de)" = Mozilla Firefox 17.0.1 (x86 de)
 "MozillaMaintenanceService" = Mozilla Maintenance Service
 "Mp3tag" = Mp3tag v2.52
 "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
 "Office14.SingleImage" = Microsoft Office Home and Student 2010
 "pdfsam" = pdfsam
 "Personal Backup 5_is1" = Personal Backup 5.4
 "tvbrowser" = TV-Browser 3.2
 "VLC media player" = VLC media player 2.0.3
 "Winamp" = Winamp
 
 ========== HKEY_USERS Uninstall List ==========
 
 [HKEY_USERS\S-1-5-21-2986282668-171375975-58925643-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 "Winamp Detect" = Winamp Erkennungs-Plug-in
 
 ========== Last 20 Event Log Errors ==========
 
 [ Application Events ]
 Error - 16.12.2012 07:36:24 | Computer Name = Xxx | Source = Application Hang | ID = 1002
 Description = Programm Persbackup.exe, Version 5.4.2.1 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: e4c    Startzeit:
 01cddb7ebfd5d00b    Endzeit: 16    Anwendungspfad: C:\Program Files\Personal Backup 5\Persbackup.exe
 
 Berichts-ID:
 
 
 Error - 17.12.2012 17:52:50 | Computer Name = Xxx | Source = Brother BrLog | ID = 1001
 Description = STI BrtSTI: [2012/12/17 22:52:50.687]: [00000360]: CUsbScnDev: DeviceIoControl()
 failed. ErrorCode = 5
 
 Error - 17.12.2012 18:23:02 | Computer Name = Xxx | Source = Brother BrLog | ID = 1001
 Description = STI BrtSTI: [2012/12/17 23:23:02.671]: [00000360]: CUsbScnDev: DeviceIoControl()
 failed. ErrorCode = 5
 
 Error - 17.12.2012 22:08:19 | Computer Name = Xxx | Source = Application Error | ID = 1000
 Description = Name der fehlerhaften Anwendung: druckstdu.exe, Version: 2.0.0.3,
 Zeitstempel: 0x4f15946b  Name des fehlerhaften Moduls: druckstdu.exe, Version: 2.0.0.3,
 Zeitstempel: 0x4f15946b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x001bc899  ID des fehlerhaften
 Prozesses: 0x550  Startzeit der fehlerhaften Anwendung: 0x01cddc91ddbe8bdc  Pfad der
 fehlerhaften Anwendung: C:\Program Files\druckstdu.de\druckstdu.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\druckstdu.de\druckstdu.exe  Berichtskennung: ca328a1b-48b7-11e2-8107-0018f3649394
 
 Error - 22.12.2012 13:12:01 | Computer Name = Xxx | Source = Application Error | ID = 1000
 Description = Name der fehlerhaften Anwendung: winamp.exe, Version: 5.6.2.3199,
 Zeitstempel: 0x4ee2440b  Name des fehlerhaften Moduls: winamp.exe, Version: 5.6.2.3199,
 Zeitstempel: 0x4ee2440b  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0004029b  ID des fehlerhaften
 Prozesses: 0xbb4  Startzeit der fehlerhaften Anwendung: 0x01cde0676c690782  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Winamp\winamp.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\Winamp\winamp.exe  Berichtskennung: b2bf2ac4-4c5a-11e2-9447-0018f3649394
 
 Error - 22.12.2012 14:13:38 | Computer Name = Xxx | Source = Brother BrLog | ID = 1001
 Description = STI BrtSTI: [2012/12/22 19:13:38.888]: [00000288]: CUsbScnDev: DeviceIoControl()
 failed. ErrorCode = 5
 
 Error - 22.12.2012 14:13:49 | Computer Name = Xxx | Source = Brother BrLog | ID = 1001
 Description = STI BrtSTI: [2012/12/22 19:13:49.749]: [00000288]: CUsbScnDev: DeviceIoControl()
 failed. ErrorCode = 5
 
 Error - 22.12.2012 14:13:50 | Computer Name = Xxx | Source = Brother BrLog | ID = 1001
 Description = STI BrtSTI: [2012/12/22 19:13:50.763]: [00000288]: CUsbScnDev: DeviceIoControl()
 failed. ErrorCode = 5
 
 Error - 22.12.2012 14:13:51 | Computer Name = Xxx | Source = Brother BrLog | ID = 1001
 Description = STI BrtSTI: [2012/12/22 19:13:51.777]: [00000288]: CUsbScnDev: DeviceIoControl()
 failed. ErrorCode = 5
 
 Error - 23.12.2012 05:24:45 | Computer Name = Xxx | Source = Application Error | ID = 1000
 Description = Name der fehlerhaften Anwendung: PEV.exe, Version: 0.0.0.0, Zeitstempel:
 0x4e06cfe8  Name des fehlerhaften Moduls: PEV.exe, Version: 0.0.0.0, Zeitstempel:
 0x4e06cfe8  Ausnahmecode: 0x40000015  Fehleroffset: 0x0008d1c0  ID des fehlerhaften Prozesses:
 0xe4c  Startzeit der fehlerhaften Anwendung: 0x01cde0ef58025e54  Pfad der fehlerhaften
 Anwendung: C:\ComboFix\PEV.exe  Pfad des fehlerhaften Moduls: C:\ComboFix\PEV.exe
 Berichtskennung:
 966af5ea-4ce2-11e2-916d-0018f3649394
 
 [ System Events ]
 Error - 18.12.2012 16:34:37 | Computer Name = Xxx | Source = Disk | ID = 262155
 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden.
 
 Error - 18.12.2012 16:34:38 | Computer Name = Xxx | Source = Disk | ID = 262155
 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden.
 
 Error - 18.12.2012 16:34:39 | Computer Name = Xxx | Source = Disk | ID = 262155
 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden.
 
 Error - 18.12.2012 16:34:39 | Computer Name = Xxx | Source = Disk | ID = 262155
 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden.
 
 Error - 18.12.2012 16:41:42 | Computer Name = Xxx | Source = Disk | ID = 262155
 Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR6 gefunden.
 
 Error - 22.12.2012 15:15:42 | Computer Name = Xxx | Source = Service Control Manager | ID = 7034
 Description = Dienst "NVIDIA Display Driver Service" wurde unerwartet beendet. Dies
 ist bereits 1 Mal passiert.
 
 Error - 22.12.2012 15:16:05 | Computer Name = Xxx | Source = Service Control Manager | ID = 7034
 Description = Dienst "Spyware Terminator 2012 Realtime Shield Service" wurde unerwartet
 beendet. Dies ist bereits 1 Mal passiert.
 
 Error - 23.12.2012 05:19:58 | Computer Name = Xxx | Source = Service Control Manager | ID = 7030
 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet.
 Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich
 sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
 Error - 23.12.2012 05:22:27 | Computer Name = Xxx | Source = Service Control Manager | ID = 7030
 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet.
 Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich
 sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
 Error - 23.12.2012 05:29:43 | Computer Name = Xxx | Source = Service Control Manager | ID = 7030
 Description = Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet.
 Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich
 sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
 
 < End of report >
 Zwischendurch: Schonmal DANKE für Deine Hilfe!!! |