Hallo, 
hier ist der Inhalt der Dateien.  
OTL.txt:   Code:  
 OTL logfile created on: 05.07.2013 11:52:26 - Run 1 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Siegfried\Desktop 
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.10.9200.16614) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,86 Gb Total Physical Memory | 2,20 Gb Available Physical Memory | 56,99% Memory free 
7,73 Gb Paging File | 5,83 Gb Available in Paging File | 75,47% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 256,94 Gb Total Space | 202,73 Gb Free Space | 78,90% Space Free | Partition Type: NTFS 
Drive D: | 99,07 Gb Total Space | 98,73 Gb Free Space | 99,65% Space Free | Partition Type: NTFS 
Drive Q: | 9,77 Gb Total Space | 1,37 Gb Free Space | 13,98% Space Free | Partition Type: NTFS 
  
Computer Name: SIEGFRIED-THINK | User Name: Siegfried | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans 
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - [2013.07.05 11:50:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Siegfried\Desktop\OTL.exe 
PRC - [2013.07.04 15:58:48 | 000,030,096 | ---- | M] (VER_COMPANY_NAME) -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon.exe 
PRC - [2013.05.10 09:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 
PRC - [2013.03.23 01:49:41 | 002,890,232 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe 
PRC - [2013.02.14 23:30:23 | 000,237,048 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe 
PRC - [2013.02.14 23:30:21 | 000,929,272 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe 
PRC - [2013.02.14 23:29:06 | 000,217,592 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe 
PRC - [2013.02.05 17:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe 
PRC - [2013.01.29 22:21:05 | 000,159,296 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe 
PRC - [2012.12.27 22:07:26 | 003,729,400 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe 
PRC - [2012.12.21 15:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) -- C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe 
PRC - [2012.08.23 04:50:22 | 000,403,888 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe 
PRC - [2012.08.23 04:49:48 | 006,049,096 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe 
PRC - [2012.08.18 22:22:02 | 007,027,752 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe 
PRC - [2012.07.24 16:13:58 | 000,943,856 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe 
PRC - [2012.05.09 23:25:15 | 000,357,400 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe 
PRC - [2012.03.19 22:58:12 | 000,514,128 | ---- | M] (REINER SCT) -- C:\Windows\SysWOW64\cjpcsc.exe 
PRC - [2011.05.27 16:23:00 | 004,999,976 | ---- | M] (Synaptics Incorporated) -- C:\Program Files (x86)\Synaptics\Scrybe\scrybe.exe 
PRC - [2011.05.27 16:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe 
PRC - [2011.01.17 18:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe 
PRC - [2011.01.17 18:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin 
PRC - [2010.04.20 14:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe 
PRC - [2010.04.20 14:23:28 | 000,062,312 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRRES.exe 
PRC - [2010.04.20 14:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\CamMute.exe 
PRC - [2010.04.07 07:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\VIRTSCRL\lvvsst.exe 
PRC - [2010.04.07 07:37:24 | 000,063,928 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe 
PRC - [2010.04.07 05:02:18 | 000,045,496 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\micmute.exe 
PRC - [2010.04.02 10:18:54 | 001,185,112 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE 
PRC - [2010.04.01 07:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\VIRTSCRL\virtscrl.exe 
PRC - [2010.03.15 14:54:56 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe 
PRC - [2009.12.21 11:49:46 | 000,069,568 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe 
PRC - [2009.11.24 06:51:20 | 000,176,056 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPONSCR.exe 
PRC - [2009.11.11 10:33:12 | 000,078,272 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\tpnumlkd.exe 
PRC - [2009.11.04 06:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 
PRC - [2009.11.04 06:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 
PRC - [2009.05.27 23:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe 
PRC - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe 
PRC - [2008.01.10 13:13:50 | 000,061,440 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe 
PRC - [2007.01.04 20:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe 
  
   ========== Modules (No Company Name) ========== 
  
MOD - [2012.08.23 04:35:38 | 013,873,200 | ---- | M] () -- C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers.dll 
MOD - [2012.08.23 04:31:22 | 001,590,656 | ---- | M] () -- C:\Program Files (x86)\Common Files\Acronis\Home\icudt38.dll 
MOD - [2012.07.24 15:48:28 | 000,012,160 | ---- | M] () -- C:\Program Files (x86)\Common Files\Acronis\TibMounter\icudt38.dll 
MOD - [2011.04.20 12:53:32 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 
MOD - [2011.03.31 19:29:46 | 000,066,856 | ---- | M] () -- C:\Windows\SysWOW64\SynTPEnhPS.dll 
MOD - [2009.05.27 23:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe 
  
   ========== Services (SafeList) ========== 
  
SRV:64bit: - [2011.01.13 15:05:46 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC) 
SRV:64bit: - [2010.01.13 16:04:10 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) 
SRV:64bit: - [2009.11.18 07:04:24 | 000,045,928 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC) 
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) 
SRV - [2013.06.28 00:11:33 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) 
SRV - [2013.06.12 20:33:24 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) 
SRV - [2013.05.10 09:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) 
SRV - [2013.03.23 01:49:41 | 002,890,232 | ---- | M] (Sophos Limited) [Auto | Running] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe -- (swi_service) 
SRV - [2013.02.14 23:30:23 | 000,237,048 | ---- | M] (Sophos Limited) [Auto | Running] -- C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe -- (Sophos AutoUpdate Service) 
SRV - [2013.02.14 23:29:06 | 000,217,592 | ---- | M] (Sophos Limited) [Auto | Running] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe -- (SAVAdminService) 
SRV - [2013.02.05 17:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService) 
SRV - [2013.01.29 22:21:05 | 000,159,296 | ---- | M] (Sophos Limited) [Auto | Running] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe -- (SAVService) 
SRV - [2013.01.29 22:18:39 | 002,010,688 | ---- | M] (Sophos Limited) [Auto | Stopped] -- C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe -- (swi_update_64) 
SRV - [2012.12.27 22:07:26 | 003,729,400 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) 
SRV - [2012.12.21 15:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Running] -- C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate) 
SRV - [2012.08.23 04:50:44 | 001,127,432 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) 
SRV - [2012.08.18 22:22:02 | 007,027,752 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe -- (syncagentsrv) 
SRV - [2012.07.20 14:00:51 | 002,635,776 | ---- | M] (Deutsche Telekom AG) [Auto | Running] -- C:\Users\Siegfried\Netzmanager\NMInfraIS2\Netzmanager_Service.exe -- (Netzmanager Service) 
SRV - [2012.05.09 23:25:15 | 000,357,400 | ---- | M] (Sophos Limited) [Auto | Running] -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe -- (Sophos Web Control Service) 
SRV - [2012.03.19 22:58:12 | 000,514,128 | ---- | M] (REINER SCT) [Auto | Running] -- C:\Windows\SysWOW64\cjpcsc.exe -- (cjpcsc) 
SRV - [2012.02.10 11:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe -- (BBUpdate) 
SRV - [2012.02.10 11:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe -- (BBSvc) 
SRV - [2011.05.27 16:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) [Auto | Running] -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe -- (ScrybeUpdater) 
SRV - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) 
SRV - [2010.09.21 15:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) 
SRV - [2010.08.24 20:30:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service) 
SRV - [2010.07.15 07:23:58 | 000,199,272 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\RtkAudioService64.exe -- (RtkAudioService) 
SRV - [2010.04.20 14:23:32 | 000,074,088 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC) 
SRV - [2010.04.20 14:23:18 | 000,050,536 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE) 
SRV - [2010.04.07 07:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC) 
SRV - [2010.04.07 07:37:24 | 000,063,928 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC) 
SRV - [2010.04.07 05:02:18 | 000,045,496 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE) 
SRV - [2010.04.05 21:55:01 | 000,116,104 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE -- (IJPLMSVC) 
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) 
SRV - [2010.03.15 14:54:56 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService) 
SRV - [2010.03.05 11:26:38 | 001,425,168 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) 
SRV - [2010.03.05 11:07:58 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) 
SRV - [2010.03.05 11:06:22 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) 
SRV - [2009.11.04 06:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) 
SRV - [2009.11.04 06:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) 
SRV - [2009.09.29 18:25:48 | 000,126,392 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost) 
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) 
SRV - [2008.10.24 17:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService) 
SRV - [2008.01.10 13:13:50 | 000,061,440 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper) 
SRV - [2007.01.04 20:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - [2013.01.29 22:26:27 | 000,154,952 | ---- | M] (Sophos Limited) [File_System | System | Running] -- C:\Windows\SysNative\drivers\savonaccess.sys -- (SAVOnAccess) 
DRV:64bit: - [2012.12.27 22:07:27 | 000,367,200 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp) 
DRV:64bit: - [2012.12.27 22:07:24 | 001,340,040 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpman.sys -- (tdrpman) 
DRV:64bit: - [2012.12.27 22:07:20 | 001,093,256 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tib_mounter.sys -- (tib_mounter) 
DRV:64bit: - [2012.12.27 22:07:18 | 000,228,488 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vididr.sys -- (vididr) 
DRV:64bit: - [2012.12.27 22:07:16 | 000,166,024 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vidsflt.sys -- (vidsflt) 
DRV:64bit: - [2012.12.27 22:07:13 | 000,340,104 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman) 
DRV:64bit: - [2012.12.27 22:07:12 | 000,155,272 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fltsrv.sys -- (fltsrv) 
DRV:64bit: - [2012.10.08 14:09:34 | 000,054,272 | ---- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GigasetGenericUSB_x64.sys -- (GigasetGenericUSB_x64) 
DRV:64bit: - [2012.03.05 21:53:58 | 000,036,640 | ---- | M] (Sophos Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdcfilter.sys -- (sdcfilter) 
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) 
DRV:64bit: - [2011.03.31 19:32:00 | 001,424,944 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) 
DRV:64bit: - [2011.03.29 11:50:26 | 000,034,672 | ---- | M] (REINER SCT) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cjusb.sys -- (cjusb) 
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) 
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) 
DRV:64bit: - [2011.01.13 15:04:20 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf) 
DRV:64bit: - [2011.01.13 15:02:28 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN) 
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) 
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) 
DRV:64bit: - [2010.11.20 11:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) 
DRV:64bit: - [2010.08.24 20:30:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF) 
DRV:64bit: - [2010.07.15 07:23:48 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService) 
DRV:64bit: - [2010.03.17 23:21:58 | 007,680,512 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) 
DRV:64bit: - [2010.03.17 12:30:36 | 000,161,664 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\5U877.sys -- (5U877) 
DRV:64bit: - [2010.02.08 14:57:22 | 000,239,136 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) 
DRV:64bit: - [2010.01.15 22:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) 
DRV:64bit: - [2010.01.15 06:23:00 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt) 
DRV:64bit: - [2010.01.15 06:23:00 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio) 
DRV:64bit: - [2010.01.15 06:23:00 | 000,021,288 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid) 
DRV:64bit: - [2010.01.13 16:26:02 | 006,327,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) 
DRV:64bit: - [2010.01.13 16:26:02 | 006,327,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag) 
DRV:64bit: - [2010.01.13 15:10:58 | 000,185,344 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) 
DRV:64bit: - [2009.11.30 08:56:00 | 000,053,800 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt) 
DRV:64bit: - [2009.11.18 07:04:04 | 000,032,880 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV) 
DRV:64bit: - [2009.10.26 05:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) 
DRV:64bit: - [2009.10.02 12:58:12 | 000,258,560 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) 
DRV:64bit: - [2009.09.29 18:25:50 | 000,012,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB) 
DRV:64bit: - [2009.09.17 05:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) 
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) 
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) 
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) 
DRV:64bit: - [2009.07.14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM) 
DRV:64bit: - [2009.07.02 04:16:02 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd) 
DRV:64bit: - [2009.06.10 23:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92) 
DRV:64bit: - [2009.06.10 23:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac) 
DRV:64bit: - [2009.06.10 23:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA) 
DRV:64bit: - [2009.06.10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) 
DRV:64bit: - [2009.06.10 22:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) 
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) 
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) 
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) 
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) 
DRV:64bit: - [2009.04.07 07:33:00 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap) 
DRV:64bit: - [2009.02.09 11:06:31 | 000,025,608 | ---- | M] (Sophos Plc) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\SophosBootDriver.sys -- (SophosBootDriver) 
DRV:64bit: - [2008.05.12 11:04:26 | 000,015,400 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi) 
DRV - [2011.06.27 17:06:54 | 000,025,584 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Programme\PC-Doctor\pcdsrvc_x64.pkms -- (PCDSRVC{127174DC-C366ED8B-06020200}_0) 
DRV - [2010.09.16 17:02:59 | 000,045,664 | ---- | M] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Running] -- C:\Users\Siegfried\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys -- (TelekomNM6) 
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {31CA554A-5500-4812-875C-F4719B5572E2} 
IE:64bit: - HKLM\..\SearchScopes\{31CA554A-5500-4812-875C-F4719B5572E2}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
IE - HKLM\..\SearchScopes,DefaultScope = {3EEE0C04-FCC8-4DA9-8801-8DE8D162280E} 
IE - HKLM\..\SearchScopes\{3EEE0C04-FCC8-4DA9-8801-8DE8D162280E}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox 
  
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo.msn.com 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad [binary data] 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.tb.ask.com/index.jhtml?n=77DE8857&p2=^Y6^xdm043^YYA^de&ptb=9724A557-6BF6-4DA9-B1EF-1977726E1F7B&si=swissconverter 
IE - HKCU\..\SearchScopes,DefaultScope = {A45A69E5-9511-4C45-9AAF-7F5F8F3DA4CA} 
IE - HKCU\..\SearchScopes\{A45A69E5-9511-4C45-9AAF-7F5F8F3DA4CA}: "URL" = hxxp://www.google.de/search?q={searchTerms} 
IE - HKCU\..\SearchScopes\{D9A8C407-B63A-4232-AEAD-0612A4782451}: "URL" = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms} 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaultenginename: "Ask Web Search" 
FF - prefs.js..browser.search.selectedEngine: "LEO Eng-Deu" 
FF - prefs.js..browser.search.useDBForOrder: true 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" 
FF - prefs.js..extensions.enabledAddons: fb_add_on%40avm.de:1.7.0 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0 
FF - prefs.js..keyword.URL: "hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=9724A557-6BF6-4DA9-B1EF-1977726E1F7B&n=77fd044f&ind=2013070415&p2=^Y6^xdm043^YYA^de&si=swissconverter&searchfor=" 
FF - prefs.js..network.proxy.type: 0 
FF - user.js - File not found 
  
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found 
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () 
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) 
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre1.6.0_22\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) 
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found 
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011.06.21 15:56:44 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins 
  
[2011.06.21 15:57:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Siegfried\AppData\Roaming\mozilla\Extensions 
[2011.06.21 15:57:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Siegfried\AppData\Roaming\mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28} 
[2013.07.05 11:45:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Siegfried\AppData\Roaming\mozilla\Firefox\Profiles\9rsq7463.default\extensions 
[2013.04.13 11:11:31 | 000,000,000 | ---D | M] ("FRITZ!Box AddOn") -- C:\Users\Siegfried\AppData\Roaming\mozilla\Firefox\Profiles\9rsq7463.default\extensions\fb_add_on@avm.de 
[2011.06.21 15:57:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Siegfried\AppData\Roaming\mozilla\Sunbird\Profiles\9tzvolni.default\extensions 
[2013.07.04 15:58:53 | 000,009,612 | ---- | M] () -- C:\Users\Siegfried\AppData\Roaming\mozilla\firefox\profiles\9rsq7463.default\searchplugins\ask-web-search.xml 
[2013.06.28 00:11:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions 
[2013.06.28 00:11:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} 
[2013.06.28 00:11:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} 
[2013.06.28 00:11:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions 
[2013.06.28 00:11:33 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} 
   ========== Chrome  ========== 
  
CHR - default_search_provider: Google (Enabled) 
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} 
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter} 
CHR - homepage: hxxp://www.google.com/ 
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\gcswf32.dll 
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll 
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll 
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll 
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll 
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll 
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\gears.dll 
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll 
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll 
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll 
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll 
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll 
CHR - plugin: Default Plug-in (Enabled) = default_plugin 
  
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) 
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found 
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_22\bin\ssv.dll (Sun Microsystems, Inc.) 
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.) 
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.6.0_22\bin\jp2ssv.dll (Sun Microsystems, Inc.) 
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. 
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.) 
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. 
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) 
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation) 
O4:64bit: - HKLM..\Run: [LENOVO.TPKNRRES] C:\Programme\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited) 
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) 
O4:64bit: - HKLM..\Run: [TPHOTKEY] C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited) 
O4:64bit: - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.) 
O4 - HKLM..\Run: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Acronis) 
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) 
O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor File not found 
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe (Sophos Limited) 
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) 
O4 - HKLM..\RunOnce: [FromDocToPDF_65bar Uninstall] rundll32 C:\PROGRA~2\65UNIN~1.DLL,O -3 uninstalltype="FF" File not found 
O4 - Startup: C:\Users\Siegfried\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk = C:\Users\Siegfried\Netzmanager\netzmanager.exe (Deutsche Telekom AG) 
O4 - Startup: C:\Users\Siegfried\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 
O9:64bit: - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm () 
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm () 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited) 
O1364bit: - gopher Prefix: missing 
O13 - gopher Prefix: missing 
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) 
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) 
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) 
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 10.15.2) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C7522CC-4D4C-429F-B803-8D9E9B89D770}: DhcpNameServer = 192.168.178.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1E0C0BFF-17C4-4830-B483-7D2926513271}: DhcpNameServer = 192.168.0.1 
O18:64bit: - Protocol\Handler\livecall - No CLSID value found 
O18:64bit: - Protocol\Handler\msnim - No CLSID value found 
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found 
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found 
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL) - C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL (Sophos Limited) 
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL (Sophos Limited) 
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ] 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) 
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) 
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) 
  
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX:64bit: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache 
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig 
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install 
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework 
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework 
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework 
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache 
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -  
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install 
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome 
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player 
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework 
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
  
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
  
  
CREATERESTOREPOINT 
Restore point Set: OTL Restore Point 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2013.07.05 11:50:37 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Siegfried\Desktop\OTL.exe 
[2013.07.05 11:45:17 | 000,712,264 | ---- | C] (MindSpark) -- C:\Program Files (x86)\65Uninstall FromDocToPDF.dll 
[2013.07.05 00:14:54 | 000,000,000 | ---D | C] -- C:\Users\Siegfried\AppData\Local\{F9ADF71E-D4B5-4FFA-8106-4BAFB1705DB6} 
[2013.07.04 15:58:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FromDocToPDF_65 
[2013.07.02 12:07:37 | 000,000,000 | ---D | C] -- C:\Users\Siegfried\AppData\Local\{071CE1FF-171E-4315-A241-15A56EA0A2DE} 
[2013.06.29 01:27:43 | 000,000,000 | ---D | C] -- C:\Users\Siegfried\AppData\Local\{9539EFFE-A316-4F6B-A9E5-E36C96AB0BAD} 
[2013.06.28 00:11:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 
[2013.06.25 01:34:04 | 000,000,000 | ---D | C] -- C:\Users\Siegfried\AppData\Local\{F7C1803F-8051-48AE-A7D1-47DF1B9B44C4} 
[2013.06.20 15:14:49 | 000,000,000 | ---D | C] -- C:\Users\Siegfried\AppData\Local\{FF48B5CC-DA2E-4D9D-B077-5047E3FB8924} 
[2013.06.18 18:53:40 | 000,000,000 | ---D | C] -- C:\Users\Siegfried\AppData\Local\{6625C0C1-09EB-4B85-90A1-823BFDDE746A} 
   ========== Files - Modified Within 30 Days ========== 
  
[2013.07.05 11:50:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Siegfried\Desktop\OTL.exe 
[2013.07.05 11:39:17 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2013.07.05 11:39:17 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2013.07.05 11:32:09 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job 
[2013.07.05 11:30:06 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2013.07.05 11:29:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2013.07.05 11:29:14 | 3111,555,072 | -HS- | M] () -- C:\hiberfil.sys 
[2013.07.05 10:21:02 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2013.07.04 23:50:50 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job 
[2013.07.04 15:58:49 | 000,194,944 | ---- | M] () -- C:\Program Files (x86)\65res.dll 
[2013.07.04 15:58:48 | 000,712,264 | ---- | M] (MindSpark) -- C:\Program Files (x86)\65Uninstall FromDocToPDF.dll 
[2013.07.04 13:01:26 | 003,320,813 | ---- | M] () -- C:\Users\Siegfried\Documents\Trojaner Anfrage.rtf 
[2013.07.04 12:49:07 | 002,650,011 | ---- | M] () -- C:\Users\Siegfried\Documents\Trojaner Mail.rtf 
[2013.07.02 21:39:45 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2013.07.02 21:39:45 | 000,654,400 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2013.07.02 21:39:45 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2013.07.02 21:39:45 | 000,130,240 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2013.07.02 21:39:45 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2013.06.28 14:00:00 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job 
[2013.06.28 14:00:00 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job 
[2013.06.20 16:27:02 | 000,002,194 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk 
[2013.06.16 16:41:43 | 000,004,693 | ---- | M] () -- C:\Users\Siegfried\Documents\RENTE  EURO- SFR  mit Berechnung.rtf 
   ========== Files Created - No Company Name ========== 
  
[2013.07.05 11:45:17 | 000,194,944 | ---- | C] () -- C:\Program Files (x86)\65res.dll 
[2013.07.04 13:01:26 | 003,320,813 | ---- | C] () -- C:\Users\Siegfried\Documents\Trojaner Anfrage.rtf 
[2013.07.04 12:49:07 | 002,650,011 | ---- | C] () -- C:\Users\Siegfried\Documents\Trojaner Mail.rtf 
[2013.06.28 10:52:15 | 000,000,528 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job 
[2013.03.21 12:17:37 | 000,167,936 | ---- | C] () -- C:\Windows\SysWow64\SerialXP.dll 
[2012.10.14 18:42:12 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll 
[2011.08.28 16:12:45 | 000,393,256 | ---- | C] () -- C:\Windows\SysWow64\CNQ4809N.DAT 
[2011.05.22 21:50:30 | 000,000,680 | RHS- | C] () -- C:\Users\Siegfried\ntuser.pol 
[2011.05.08 16:27:38 | 000,020,540 | ---- | C] () -- C:\Users\Siegfried\AppData\Roaming\UserTile.png 
   ========== ZeroAccess Check ========== 
  
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] 
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Both 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] 
   ========== LOP Check ========== 
  
[2012.04.06 18:44:51 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\Acronis 
[2011.08.28 17:01:18 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\Canon 
[2011.12.07 22:00:03 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\elsterformular 
[2011.04.20 13:59:53 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\OpenOffice.org 
[2011.05.12 21:40:58 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\PCDr 
[2011.06.27 13:59:18 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\Secure Soft 
[2012.10.14 18:45:24 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\Synaptics 
[2011.05.12 21:29:50 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\Update 
[2011.06.06 18:56:18 | 000,000,000 | ---D | M] -- C:\Users\Siegfried\AppData\Roaming\Windows Live Writer 
   ========== Purity Check ========== 
  
  
   ========== Custom Scans ========== 
   < %SYSTEMDRIVE%\*. > 
[2011.05.22 23:50:13 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin 
[2009.07.24 19:28:56 | 000,000,000 | -HSD | M] -- C:\Boot 
[2009.07.14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings 
[2011.03.28 21:11:50 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen 
[2011.03.03 17:51:35 | 000,000,000 | ---D | M] -- C:\Intel 
[2011.03.04 01:58:09 | 000,000,000 | ---D | M] -- C:\mfg 
[2009.07.14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs 
[2013.03.14 12:48:54 | 000,000,000 | R--D | M] -- C:\Program Files 
[2013.07.05 11:45:17 | 000,000,000 | R--D | M] -- C:\Program Files (x86) 
[2013.01.06 17:28:16 | 000,000,000 | -H-D | M] -- C:\ProgramData 
[2011.03.28 21:11:50 | 000,000,000 | -HSD | M] -- C:\Programme 
[2011.03.28 21:12:14 | 000,000,000 | ---D | M] -- C:\swshare 
[2011.03.28 21:38:37 | 000,000,000 | ---D | M] -- C:\SWTOOLS 
[2013.07.05 11:54:39 | 000,000,000 | -HSD | M] -- C:\System Volume Information 
[2011.05.22 23:59:54 | 000,000,000 | R--D | M] -- C:\Users 
[2012.03.26 14:09:00 | 000,000,000 | ---D | M] -- C:\usr 
[2013.03.23 14:59:26 | 000,000,000 | ---D | M] -- C:\Windows 
   < %PROGRAMFILES%\*.exe > 
   < %LOCALAPPDATA%\*.exe > 
   < %systemroot%\*. /mp /s > 
   < C:\Windows\system32\*.tsp > 
[2012.10.08 14:26:52 | 000,495,616 | ---- | M] (Gigaset Communications GmbH) -- C:\Windows\system32\Gqstsp.tsp 
[2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp 
[2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp 
[2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp 
[2009.07.14 03:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp 
[2010.11.20 14:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp 
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT 
[2009.07.14 07:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT 
[2011.04.22 23:17:50 | 000,001,112 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 
[2011.04.22 23:17:50 | 000,001,116 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 
[2011.05.12 21:40:14 | 000,000,466 | ---- | C] () -- C:\Windows\Tasks\SystemToolsDailyTest.job 
[2011.05.12 21:40:15 | 000,000,528 | ---- | C] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job 
[2012.04.19 10:37:01 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job 
[2013.06.28 10:52:15 | 000,000,528 | ---- | C] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job 
   < MD5 for: AGP440.SYS  > 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys 
   < MD5 for: ATAPI.SYS  > 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys 
   < MD5 for: CNGAUDIT.DLL  > 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll 
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll 
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll 
   < MD5 for: EXPLORER.EXE  > 
[2011.02.26 08:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe 
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe 
[2009.07.14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe 
[2011.02.26 07:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe 
[2011.03.04 02:24:38 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe 
[2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe 
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe 
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe 
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe 
[2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe 
[2011.03.04 02:23:01 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe 
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe 
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe 
[2011.03.04 02:24:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe 
[2011.03.04 02:23:01 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe 
[2010.11.20 15:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe 
[2011.03.04 02:24:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe 
[2011.03.04 02:23:01 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe 
[2009.07.14 03:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe 
[2011.03.04 02:24:38 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe 
[2011.02.26 08:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe 
[2011.03.04 02:23:01 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe 
   < MD5 for: IASTOR.SYS  > 
[2010.01.15 22:22:08 | 000,538,136 | ---- | M] (Intel Corporation) MD5=85977CD13FC16069CE0AF7943A811775 -- C:\SWTOOLS\DRIVERS\IMSM\iaStor.sys 
[2010.01.15 22:22:08 | 000,538,136 | ---- | M] (Intel Corporation) MD5=85977CD13FC16069CE0AF7943A811775 -- C:\Windows\SysNative\drivers\iaStor.sys 
[2010.01.15 22:22:08 | 000,538,136 | ---- | M] (Intel Corporation) MD5=85977CD13FC16069CE0AF7943A811775 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_5d42c6448888c5bd\iaStor.sys 
   < MD5 for: IASTORV.SYS  > 
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys 
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys 
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys 
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys 
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys 
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys 
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys 
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys 
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys 
   < MD5 for: NETLOGON.DLL  > 
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll 
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll 
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll 
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll 
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll 
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll 
   < MD5 for: NVSTOR.SYS  > 
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys 
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys 
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys 
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys 
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys 
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys 
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys 
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys 
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys 
   < MD5 for: SCECLI.DLL  > 
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll 
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll 
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll 
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll 
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll 
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll 
   < MD5 for: USER32.DLL  > 
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll 
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll 
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll 
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll 
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll 
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll 
   < MD5 for: USERINIT.EXE  > 
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe 
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe 
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe 
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe 
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe 
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe 
   < MD5 for: WINLOGON.EXE  > 
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe 
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe 
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe 
[2011.03.04 02:24:38 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe 
[2011.03.04 02:24:38 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe 
   < MD5 for: WS2IFSL.SYS  > 
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys 
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys 
   < %systemroot%\system32\drivers\*.sys /lockedfiles > 
   < %systemroot%\System32\config\*.sav > 
   < %systemroot%\system32\*.dll /lockedfiles > 
[2010.11.20 14:21:37 | 011,410,432 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\wmp.dll 
[2010.11.20 14:21:37 | 000,299,520 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\wmpdxm.dll 
   < %USERPROFILE%\*.* > 
[2013.07.05 11:53:52 | 002,621,440 | -HS- | M] () -- C:\Users\Siegfried\ntuser.dat 
[2013.07.05 11:53:52 | 000,262,144 | -HS- | M] () -- C:\Users\Siegfried\ntuser.dat.LOG1 
[2011.03.28 21:11:56 | 000,000,000 | -HS- | M] () -- C:\Users\Siegfried\ntuser.dat.LOG2 
[2011.03.28 20:55:39 | 000,065,536 | -HS- | M] () -- C:\Users\Siegfried\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf 
[2011.03.28 20:55:39 | 000,524,288 | -HS- | M] () -- C:\Users\Siegfried\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms 
[2011.03.28 20:55:39 | 000,524,288 | -HS- | M] () -- C:\Users\Siegfried\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms 
[2011.05.12 15:58:57 | 000,065,536 | -HS- | M] () -- C:\Users\Siegfried\ntuser.dat{c07ee47d-7c9a-11e0-9e7c-60eb69df35ee}.TM.blf 
[2011.05.12 15:58:57 | 000,524,288 | -HS- | M] () -- C:\Users\Siegfried\ntuser.dat{c07ee47d-7c9a-11e0-9e7c-60eb69df35ee}.TMContainer00000000000000000001.regtrans-ms 
[2011.05.12 15:58:57 | 000,524,288 | -HS- | M] () -- C:\Users\Siegfried\ntuser.dat{c07ee47d-7c9a-11e0-9e7c-60eb69df35ee}.TMContainer00000000000000000002.regtrans-ms 
[2011.03.28 21:11:56 | 000,000,020 | -HS- | M] () -- C:\Users\Siegfried\ntuser.ini 
[2012.11.10 09:34:12 | 000,000,680 | RHS- | M] () -- C:\Users\Siegfried\ntuser.pol 
[2011.08.28 17:01:19 | 000,000,000 | ---- | M] () -- C:\Users\Siegfried\Sti_Trace.log 
   < %USERPROFILE%\Local Settings\Temp\*.exe > 
   < %USERPROFILE%\Local Settings\Temp\*.dll > 
   < %USERPROFILE%\Application Data\*.exe > 
   < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 
   <   > 
   ========== Alternate Data Streams ========== 
  
@Alternate Data Stream - 929 bytes -> C:\Users\Siegfried\Documents\Re-Reiserücktritt-ERV,Antwort.eml:OECustomProperty 
@Alternate Data Stream - 1252 bytes -> C:\Users\Siegfried\Documents\Re-Reiserücktritt-ERV.eml:OECustomProperty   
< End of report >   --- --- ---    
Extras.txt   Code:  
 OTL Extras logfile created on: 05.07.2013 11:52:26 - Run 1 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Siegfried\Desktop 
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.10.9200.16614) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
3,86 Gb Total Physical Memory | 2,20 Gb Available Physical Memory | 56,99% Memory free 
7,73 Gb Paging File | 5,83 Gb Available in Paging File | 75,47% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 256,94 Gb Total Space | 202,73 Gb Free Space | 78,90% Space Free | Partition Type: NTFS 
Drive D: | 99,07 Gb Total Space | 98,73 Gb Free Space | 99,65% Space Free | Partition Type: NTFS 
Drive Q: | 9,77 Gb Total Space | 1,37 Gb Free Space | 13,98% Space Free | Partition Type: NTFS 
  
Computer Name: SIEGFRIED-THINK | User Name: Siegfried | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans 
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) 
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) 
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) 
  
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" 
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) 
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" 
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) 
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. 
   ========== Security Center Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data] 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] 
"" =  
"DisableMonitoring" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
   ========== Firewall Settings ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
   ========== Authorized Applications List ========== 
  
   ========== Vista Active Open Ports Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{094C44E9-6C62-4E98-B616-86E33574BE7B}" = lport=445 | protocol=6 | dir=in | app=system |  
"{0B55B1A5-6932-4DE9-B42E-B9ED39B7E97B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |  
"{2091066F-31E9-45C7-A246-A8362FE23CCE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{2CCC1948-3BCF-4A7D-911E-69898D78D8EF}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |  
"{3CDE2325-2C70-4F4E-BD95-17193E6C3C83}" = rport=138 | protocol=17 | dir=out | app=system |  
"{3CF4D896-9F86-4D35-B826-51092B12A74A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{3F9CD409-E337-4A97-95A2-5A0BEEE8565A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{401B6C8F-8311-443B-B736-159B147D7F95}" = rport=137 | protocol=17 | dir=out | app=system |  
"{41141E9A-2E53-4166-9EFA-E33DB94E5976}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |  
"{534EB270-EBBA-42D5-893B-40E5C4EAF20B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{53F0DAD6-46E1-4B00-A504-AE9A0D02EBAD}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{598250FF-8554-4BE7-993E-C80DA9A1628D}" = rport=445 | protocol=6 | dir=out | app=system |  
"{598BF50A-5239-4835-95C1-B5C8514BE5B9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{5CE11C0C-9E58-476B-A5D3-D1479ED61F6D}" = rport=139 | protocol=6 | dir=out | app=system |  
"{6F7EACA3-C84D-4B3D-B00E-DB827B2EE034}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{709CC8F5-2C0E-45AF-AEA6-5B6B4706D25F}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |  
"{873B3933-CE76-46CD-945F-6D2A284A79F7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{952E0415-8D7C-410B-91D7-0F6BBB11D6DA}" = lport=2869 | protocol=6 | dir=in | app=system |  
"{A0FD5E4E-EE3B-4C79-B6A9-5883D9C4D2D1}" = lport=137 | protocol=17 | dir=in | app=system |  
"{A8592D9B-5F87-4D1B-B469-B663852887FF}" = lport=138 | protocol=17 | dir=in | app=system |  
"{B01A1F8B-2F10-4794-8650-7195B6667DC3}" = rport=10243 | protocol=6 | dir=out | app=system |  
"{B1B54ABD-C48D-4C88-9B4A-77B86DE079B3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{C3B4C4B0-9C1F-4AFB-A76F-A14A7DAA6E6F}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |  
"{C7585F07-48A1-4A22-9639-9E606F1550FB}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |  
"{C7FAD3A3-EA12-40F0-9E60-2B1F415EA75C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{CD13F72A-A3A4-4B8F-B97F-6BC619F8566E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |  
"{CFE8640E-D636-4BE9-BBE4-F39089EE9D31}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |  
"{D47F679B-0B29-42E7-B856-D1BC07086B49}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{EA658E9D-62D2-433D-93A1-0515F66E3FF6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{EB4D8C65-6C12-4695-896A-0D71AE934F70}" = lport=10243 | protocol=6 | dir=in | app=system |  
"{EFA3A7E0-6DD4-43FC-9610-0326DB4F902C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{EFB75F88-B139-4197-836E-9DBDF287384C}" = lport=139 | protocol=6 | dir=in | app=system |  
"{F4BA445D-AED5-45EA-952B-03A74A3F1328}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
   ========== Vista Active Application Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{0D88E077-6FF8-4CCD-A6E6-65BEB007991B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{1E4FCA54-DE3E-438B-A3AB-CC244C0558CB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |  
"{202516AB-13AC-433C-9AB6-50949DADD039}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |  
"{2F4CD372-8032-4263-9759-0DAF760856F2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{375FF641-B899-48B4-ADF4-A2977C7686DF}" = protocol=6 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\app\starmoney.exe |  
"{39491979-03E4-407B-A01D-6EC25F667145}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{4F47D0EB-4EC6-4D5C-A53C-D4292F05E934}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |  
"{540B2013-DC96-4598-96E1-7886086BDC4D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{64E1E002-F805-468B-9B42-A7C8047CAF9A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{68D6344F-045D-4910-BD4F-C1D67D6BA4BB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |  
"{728144B7-72A0-42D9-A2E1-80D6701512FB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{73F53992-80C5-4A96-B8D0-D67335615BA5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{789BB646-9D71-42A6-8459-B42909290B8B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{78DBF5AF-970F-4BD9-B874-AC87328AAD6E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |  
"{8F724D59-1A20-463A-9F66-40035126BE33}" = protocol=6 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\ouservice\starmoneyonlineupdate.exe |  
"{96D7BE01-7606-47DE-8B27-B6CEC01133B5}" = protocol=17 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\ouservice\starmoneyonlineupdate.exe |  
"{9A41EB7A-4F64-4013-BBCC-869D9CE0A76B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |  
"{9F58836A-B1B8-475B-8A84-65DDC76C9D6F}" = protocol=6 | dir=out | app=system |  
"{B10179A7-98BF-4504-923A-DC91DE4A8703}" = protocol=17 | dir=in | app=c:\program files (x86)\starmoney 8.0 s-edition\app\starmoney.exe |  
"{C0D4267D-402C-49ED-8C64-F2C6FD2F732B}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |  
"{CA62CC46-E0A8-4853-8D62-17C5A2B47740}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |  
"{D07AD168-F048-4E93-825B-FA5E1150DF04}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |  
"{E12C3411-B10F-443D-943E-8792766DA3D8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{E3211EA6-EE62-4DEE-9269-2F15EA0EC47E}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |  
"{E5774317-F0C9-4D71-B95C-B0F76553BF1E}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |  
"{ECCAFCDB-E8D5-40BC-9E38-C3E897929D18}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |  
"{F80C1329-7877-4CBF-93E4-C6719DD17C84}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{FC6F2E95-F8CD-4925-B829-A483AA592860}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |  
"TCP Query User{8E1CE0D9-5702-488C-B63F-91FDD4F0BB6A}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |  
"TCP Query User{B3A91FDE-2C15-4CC9-83AC-81BAC7FDBC5E}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |  
"UDP Query User{3E78C24C-11EE-4DF9-8085-8C12C3BD9CAA}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |  
"UDP Query User{921EE986-821E-4103-A64B-DA0C3A106D38}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) 
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4809" = CanoScan LiDE 210 Scanner Driver 
"{1A8BA6CE-822D-4888-89E2-ACBF4308F271}" = Intel(R) PROSet/Wireless WiFi-Software 
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant 
"{26A24AE4-039D-4CA4-87B4-2F86416017FF}" = Java(TM) 6 Update 17 (64-bit) 
"{2AB30FC1-9094-88DE-F76F-7BA690329B1D}" = ccc-utility64 
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Überwachungstool für die Intel® Turbo-Boost-Technik 
"{3ADFDEB3-E659-E340-F3C5-33F237A807C5}" = ATI Catalyst Install Manager 
"{43B74FAB-FB58-447D-8D3A-5F638AF36FD1}" = Netzmanager 
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz 
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector 
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 
"{627673ff-f4ea-43fd-893d-28fc6176fb2d}" = Gigaset QuickSync 
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64) 
"{88C6A6D9-324C-46E8-BA87-563D14021442}_is1" = ThinkVantage Communications Utility 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = ThinkPad Bluetooth with Enhanced Data Rate Software 
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) 
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources 
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources 
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter 
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client 
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service 
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile 
"03A7DBDC77B53F52C7EA041F531310CFC5E2AD9E" = Windows-Treiberpaket - Realtek Semiconductor Corp. HD Audio Driver (06/29/2010 6.0.1.6146) 
"114EB224AD576F278686036AA9E1EFB7847E3935" = Windows-Treiberpaket - Lenovo 1.60.0.4 (11/18/2009 1.60.0.4) 
"1AE98C75AE2DD1284F66876FA76F46BFDF6B9D31" = Windows-Treiberpaket - Intel hdc  (06/04/2009 7.0.0.1013) 
"573C3C32A1DB5625CA00E633E584E8A0E6383672" = Windows-Treiberpaket - Intel System  (10/28/2009 9.1.1.1022) 
"70FAF0B3C6F143057FDFD46764A316A0A08A990E" = Windows-Treiberpaket - Realtek Semiconductor Corp. HD Audio Driver (01/26/2010 5.10.0.6034) 
"A7B0B8D913E4DC2FA0B31E392E1512A901CA66B9" = Windows-Treiberpaket - Intel USB  (08/20/2009 9.1.1.1020) 
"ATI Uninstaller" = ATI Uninstaller 
"BBABA9FE13F046C64FAED28FC869D210D2BB7A08" = Windows-Treiberpaket - Realtek Semiconductor Corp. HD Audio Driver (01/26/2010 6.0.1.6034) 
"C39A7AFB5CAF49F10B9573FFE2E981F1AB2074B6" = Windows-Treiberpaket - Intel (iaStor) hdc  (01/15/2010 9.5.7.1002) 
"D94DFF1289C7A7BEBA126E4CDADE0E85B99E60F1" = Windows-Treiberpaket - Intel System  (10/28/2009 9.1.1.1022) 
"E7B58217635B8F723D4744A328A4B3237DB35FA9" = Windows-Treiberpaket - Intel System  (06/04/2009 1.0.0.0002) 
"EnablePS" = Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 
"Kyocera Product Library" = Kyocera Product Library 
"LENOVO.SMIIF" = Lenovo System Interface Driver 
"LenovoAutoScrollUtility" = Lenovo Auto Scroll Utility 
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile 
"OnScreenDisplay" = Anzeige am Bildschirm 
"PC-Doctor for Windows" = Lenovo ThinkVantage Toolbox 
"Power Management Driver" = ThinkPad Power Management Driver 
"ProInst" = Intel PROSet Wireless 
"SynTPDeinstKey" = Synaptics Pointing Device Driver 
"W7DevOR" =  Registry Patch to arrange icons in Device and Printers folder of Windows 7 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{00C18D9B-3B61-6EAA-1F47-095B265A340D}" = CCC Help Russian 
"{04EEBFD2-D1B7-B71B-34D3-48AC17FE58C6}" = CCC Help Hungarian 
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer 
"{0B3B35C8-5429-4A90-A447-D1B9ED499FE8}" = STEUEReasy 2011 
"{142E95CC-EE6F-427F-DBD3-2A74347BC490}" = CCC Help Finnish 
"{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}" = Synaptics Gesture Suite featuring SYNAPTICS | Scrybe 
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate 
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources 
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update 
"{1FCBD504-AB7D-4757-9A14-850348384B08}" = StarMoney 
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions 
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8 
"{25C64847-B900-48AD-A164-1B4F9B774650}" = System Update 
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22 
"{2BC3066C-6522-8BFF-0010-205EF1B1F4CF}" = CCC Help Swedish 
"{2D45FA3F-EDFA-7F3F-C3E3-4C2F99CF4878}" = CCC Help Chinese Standard 
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery 
"{33F43046-217B-8FE2-B6A8-00E80F0DE721}" = CCC Help French 
"{353E97F1-DF93-4678-85B8-7B30138C21E7}" = STEUEReasy 2012 
"{3B3B6E6A-31AA-2FFE-A986-22FD68D2B388}" = Catalyst Control Center Localization All 
"{3D6C32FD-673E-3F32-BA03-C710C695D23C}" = CCC Help Chinese Traditional 
"{422110B2-BE71-88F3-ECBB-7AEB5DC4AD9A}" = Catalyst Control Center Graphics Light 
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3 
"{4330AAE7-1893-42F9-BC38-539A1A60530B}" = Mobile Broadband 
"{44C38280-CD0D-00E7-2ABA-DD88EB67BF4E}" = CCC Help Polish 
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth 
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater 
"{4C8BA45A-8545-4BF1-A757-C237674CF175}" = StarMoney 8.0 S-Edition 
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform 
"{4D0EAA2D-8EE2-43AB-BE00-18A1D0A9281C}" = STEUEReasy 2013 
"{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}" = Create Recovery Media 
"{50F68032-B5B7-4513-9116-C978DBD8F27A}" = Corel DVD MovieFactory 7 
"{520C1D80-935C-42B9-9340-E883849D804F}_is1" = DriverTuner 3.1.0.0 
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI 
"{54E8A213-8C8D-5C6A-9A17-E2AA8A4B4AE1}" = CCC Help Korean 
"{57FA0525-01F9-4051-8DE9-CBF43CAC68D9}" = Catalyst Control Center - Branding 
"{59CA8312-841C-45F0-A1CC-2A9DA1118DAE}" = P7S Viewer 
"{59F3D2AC-5F1F-4A93-8F23-6FD4F029D9A9}" = True Image 2013 
"{59F3D2AC-5F1F-4A93-8F23-6FD4F029D9A9}Visible" = True Image 2013 
"{644B0FE3-1E49-F195-E94C-FFA6C856CF6D}" = CCC Help Spanish 
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components 
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE 
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 
"{6E32A17B-4BF9-AE7B-6213-02A5290D0148}" = Catalyst Control Center Graphics Previews Vista 
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable 
"{744702BE-912F-AA8D-F2DA-289315CD674B}" = Catalyst Control Center Core Implementation 
"{76CF34E5-2041-1F8E-A4F0-479D0A23ADF9}" = CCC Help Greek 
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 
"{79EE96DB-D2DE-C601-2E42-06DE30338545}" = CCC Help Italian 
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer 
"{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger 
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later 
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime 
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT 
"{8E0560F6-425A-A1CE-6226-6F843CCA2E51}" = CCC Help English 
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker 
"{9582ED80-CB4D-4350-BBB9-34CDBA20EED0}" = Steuer-Taxi 2010 
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader 
"{96DF4640-C0B2-2994-FC5A-4C8CCD36461D}" = Catalyst Control Center Graphics Full Existing 
"{99D421D6-3D74-9428-DCE8-9C049B7D5F9F}" = Catalyst Control Center InstallProxy 
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus 
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 
"{9CA0DEE4-E84B-466F-9B96-FC255F3A929F}" = Integrated Camera TWAIN 
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail 
"{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack 
"{A3BE3F1E-2472-4211-8735-E8239BE49D9F}" = Burn.Now 4.5 
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common 
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer 
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Deutsch 
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh 
"{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}" = AAVUpdateManager 
"{AFBC82E7-8FE1-1503-CD03-29162C955907}" = CCC Help Turkish 
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie 
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail 
"{BCF03B5E-E469-A3B8-91BD-20D4E6D14B6B}" = CCC Help Japanese 
"{C28E9816-276D-FE9E-F717-747B52A5D42B}" = CCC Help Thai 
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common 
"{C3CD17B4-08B0-492D-8A4C-81716D33E520}" = Integrated Camera Driver Installer Package Ver.1.0.1.7 
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections 
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help 
"{CD310B9F-8345-D567-C53B-38EEFD119CA3}" = ccc-core-static 
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform 
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform 
"{D61CF128-FA46-4830-9F93-92D742F8BE02}" = CCC Help German 
"{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}" = Bing Bar 
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel(R) Turbo Boost Technology Driver 
"{D7359EC2-B1C9-D079-3DB4-C30E21B51465}" = CCC Help Norwegian 
"{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}" = ThinkPad Energie-Manager 
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh 
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 
"{E2F2B987-F2BC-4969-95F2-92099486B811}" = StarMoney 
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime 
"{E4D15292-7CB1-B02B-7FC3-A0047C2E567D}" = CCC Help Dutch 
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker 
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger 
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] 
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver 
"{F1A347D9-BC91-116A-70A8-DC0D55E0E63F}" = Catalyst Control Center Graphics Full New 
"{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder 
"{F647E40C-DA6F-C9AD-A4BF-C8852026E365}" = CCC Help Portuguese 
"{F6BCAAA0-3BDA-13BE-002C-2D7D04E63733}" = CCC Help Danish 
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials 
"{FB90BC38-52E4-C701-578C-2B542FBEFEB1}" = CCC Help Czech 
"{FC338210-F594-11D3-BA24-00001C3AB4DF}" = cyberJack Base Components 
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus 
"{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}" = Lenovo Warranty Information 
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program 
"CanonSolutionMenuEX" = Canon Solution Menu EX 
"ElsterFormular" = ElsterFormular 
"ElsterFormular für Privatanwender 12.2.0.6412p" = ElsterFormular-Upgrade 
"Google Chrome" = Google Chrome 
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8 
"InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}" = Corel DVD MovieFactory Lenovo Edition 
"InstallShield_{A3BE3F1E-2472-4211-8735-E8239BE49D9F}" = Corel Burn.Now Lenovo Edition 
"InstallShield_{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder 
"Lenovo Welcome_is1" = Lenovo Welcome 
"McAfee Security Scan" = McAfee Security Scan Plus 
"Mozilla Firefox 22.0 (x86 de)" = Mozilla Firefox 22.0 (x86 de) 
"MozillaMaintenanceService" = Mozilla Maintenance Service 
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0 
"Netzmanager" = Netzmanager 
"WinLiveSuite" = Windows Live Essentials 
   ========== Last 20 Event Log Errors ========== 
  
[ Application Events ] 
Error - 12.06.2013 14:09:44 | Computer Name = Siegfried-THINK | Source = PerfNet | ID = 2004 
Description =  
  
Error - 16.06.2013 14:41:22 | Computer Name = Siegfried-THINK | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 22.06.2013 05:41:12 | Computer Name = Siegfried-THINK | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, 
 Zeitstempel: 0x4a5bc3c1  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, 
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000000000016ecf 
ID 
 des fehlerhaften Prozesses: 0x840  Startzeit der fehlerhaften Anwendung: 0x01ce6f2c3e4cef3f 
Pfad 
 der fehlerhaften Anwendung: C:\Windows\system32\svchost.exe  Pfad des fehlerhaften 
 Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: df6da8bd-db1f-11e2-8906-60eb69df35ee 
  
Error - 23.06.2013 18:06:23 | Computer Name = Siegfried-THINK | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 27.06.2013 09:49:53 | Computer Name = Siegfried-THINK | Source = PerfNet | ID = 2004 
Description =  
  
Error - 28.06.2013 04:40:09 | Computer Name = Siegfried-THINK | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: SAVAdminService.exe, Version: 10.2.4.7009, 
 Zeitstempel: 0x50eff938  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, 
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00053dfe  ID des fehlerhaften 
 Prozesses: 0x102c  Startzeit der fehlerhaften Anwendung: 0x01ce73da29eca01f  Pfad der 
 fehlerhaften Anwendung: C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe 
Pfad 
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: 56b27ac8-dfce-11e2-823d-60eb69df35ee 
  
Error - 28.06.2013 09:20:40 | Computer Name = Siegfried-THINK | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: services.exe, Version: 6.1.7600.16385, 
 Zeitstempel: 0x4a5bc10e  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, 
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0000000000021cca 
ID 
 des fehlerhaften Prozesses: 0x394  Startzeit der fehlerhaften Anwendung: 0x01ce7401ff7ab574 
Pfad 
 der fehlerhaften Anwendung: C:\Windows\system32\services.exe  Pfad des fehlerhaften 
 Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: 86beb362-dff5-11e2-864b-60eb69df35ee 
  
Error - 30.06.2013 05:18:43 | Computer Name = Siegfried-THINK | Source = Application Hang | ID = 1002 
Description = Programm TrueImage.exe, Version 16.0.0.5551 kann nicht mehr unter  
Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in 
 der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem  
zu suchen.    Prozess-ID: 1438    Startzeit: 01ce751d05a89432    Endzeit: 5    Anwendungspfad: C:\Program 
 Files (x86)\Acronis\TrueImageHome\TrueImage.exe    Berichts-ID: faf9eda9-e165-11e2-a3fc-60eb69df35ee   
  
Error - 30.06.2013 13:03:33 | Computer Name = Siegfried-THINK | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 02.07.2013 18:37:02 | Computer Name = Siegfried-THINK | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 02.07.2013 18:37:38 | Computer Name = Siegfried-THINK | Source = Windows Backup | ID = 4103 
Description =  
  
[ Lenovo-Message Center Plus/Admin Events ] 
Error - 26.06.2011 15:13:15 | Computer Name = Siegfried-THINK | Source = Lenovo-Message Center Plus/Admin | ID = 4 
Description = Relevancy program timed out for message 'MCPToLTT_ROW': LTTCheck.exe 
  
[ Media Center Events ] 
Error - 17.11.2012 07:57:36 | Computer Name = Siegfried-THINK | Source = MCUpdate | ID = 0 
Description = 12:57:34 - MCEClientUX konnte nicht abgerufen werden (Fehler: Die  
zugrunde liegende Verbindung wurde geschlossen: Für den geschützten SSL/TLS-Kanal 
 konnte keine Vertrauensstellung hergestellt werden..)   
  
Error - 05.01.2013 15:18:15 | Computer Name = Siegfried-THINK | Source = MCUpdate | ID = 0 
Description = 20:18:15 - Fehler beim Herstellen der Internetverbindung.  20:18:15  
-     Serververbindung konnte nicht hergestellt werden..   
  
Error - 05.01.2013 15:18:49 | Computer Name = Siegfried-THINK | Source = MCUpdate | ID = 0 
Description = 20:18:44 - Fehler beim Herstellen der Internetverbindung.  20:18:44  
-     Serververbindung konnte nicht hergestellt werden..   
  
Error - 05.01.2013 16:19:19 | Computer Name = Siegfried-THINK | Source = MCUpdate | ID = 0 
Description = 21:19:19 - Fehler beim Herstellen der Internetverbindung.  21:19:19  
-     Serververbindung konnte nicht hergestellt werden..   
  
Error - 05.01.2013 16:19:49 | Computer Name = Siegfried-THINK | Source = MCUpdate | ID = 0 
Description = 21:19:48 - Fehler beim Herstellen der Internetverbindung.  21:19:48  
-     Serververbindung konnte nicht hergestellt werden..   
  
[ System Events ] 
Error - 03.07.2013 06:12:32 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
Error - 03.07.2013 09:11:08 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
Error - 03.07.2013 12:22:03 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
Error - 03.07.2013 18:07:39 | Computer Name = Siegfried-THINK | Source = DCOM | ID = 10010 
Description =  
  
Error - 04.07.2013 04:16:17 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
Error - 04.07.2013 17:52:32 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
Error - 05.07.2013 04:11:36 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
Error - 05.07.2013 04:31:39 | Computer Name = Siegfried-THINK | Source = SCardSvr | ID = 610 
Description =  
  
Error - 05.07.2013 05:30:25 | Computer Name = Siegfried-THINK | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 
Description = Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.    Modulpfad: 
 C:\Windows\System32\IWMSSvc.dll  Fehlercode: 87   
  
Error - 05.07.2013 05:32:09 | Computer Name = Siegfried-THINK | Source = Service Control Manager | ID = 7022 
Description = Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" 
 wurde nicht richtig gestartet. 
  
  
< End of report >   --- --- ---    |