| Sabine74 |  24.07.2010 06:42 |        Vielen, vielen Dank für die schnelle Antwort! 
Hier die Logs:   
Malwarebytes' Anti-Malware 1.46 
www.malwarebytes.org  
Datenbank Version: 4342  
Windows 6.1.7600 
Internet Explorer 8.0.7600.16385  
24.07.2010 07:24:54 
mbam-log-2010-07-24 (07-24-54).txt  
Art des Suchlaufs: Vollständiger Suchlauf (C:\|) 
Durchsuchte Objekte: 229113 
Laufzeit: 7 Stunde(n), 52 Minute(n), 4 Sekunde(n)  
Infizierte Speicherprozesse: 0 
Infizierte Speichermodule: 0 
Infizierte Registrierungsschlüssel: 0 
Infizierte Registrierungswerte: 0 
Infizierte Dateiobjekte der Registrierung: 0 
Infizierte Verzeichnisse: 0 
Infizierte Dateien: 0  
Infizierte Speicherprozesse: 
(Keine bösartigen Objekte gefunden)  
Infizierte Speichermodule: 
(Keine bösartigen Objekte gefunden)  
Infizierte Registrierungsschlüssel: 
(Keine bösartigen Objekte gefunden)  
Infizierte Registrierungswerte: 
(Keine bösartigen Objekte gefunden)  
Infizierte Dateiobjekte der Registrierung: 
(Keine bösartigen Objekte gefunden)  
Infizierte Verzeichnisse: 
(Keine bösartigen Objekte gefunden)  
Infizierte Dateien: 
(Keine bösartigen Objekte gefunden)    
OTL: 
OTL Logfile:   Code:  
 OTL logfile created on: 24.07.2010 07:30:05 - Run 1 
OTL by OldTimer - Version 3.2.9.1     Folder = C:\Users\Thomas\Desktop 
64bit- An unknown product  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 40,00% Memory free 
4,00 Gb Paging File | 2,00 Gb Available in Paging File | 52,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 224,47 Gb Total Space | 168,54 Gb Free Space | 75,08% Space Free | Partition Type: NTFS 
D: Drive not present or media not loaded 
E: Drive not present or media not loaded 
F: Drive not present or media not loaded 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: LAPTOP-THOMAS 
Current User Name: Thomas 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: Current user 
Include 64bit Scans 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Users\Thomas\Desktop\OTL.exe (OldTimer Tools) 
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.) 
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) 
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION) 
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) 
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) 
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) 
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) 
PRC - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA) 
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION) 
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) 
PRC - C:\Program Files (x86)\TOSHIBA\TNROTATE\TNROTATE.exe (TOSHIBA Corporation) 
PRC - C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin) 
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin) 
  
   ========== Modules (SafeList) ========== 
  
MOD - C:\Users\Thomas\Desktop\OTL.exe (OldTimer Tools) 
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) 
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV:64bit: - (TPCHSrv) -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation) 
SRV:64bit: - (TosCoSrv) -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) 
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) 
SRV:64bit: - (Thpsrv) -- C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation) 
SRV:64bit: - (TOSHIBA eco Utility Service) -- C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation) 
SRV:64bit: - (TODDSrv) -- C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation) 
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) 
SRV:64bit: - (StorSvc) -- C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation) 
SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) 
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
SRV - (cfWiMAXService) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION) 
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH) 
SRV - (TMachInfo) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation) 
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) 
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) 
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) 
SRV - (ConfigFree Service) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION) 
SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) 
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) 
DRV:64bit: - (ApfiltrService) -- C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.) 
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) 
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) 
DRV:64bit: - (IntcDAud) Intel(R) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation) 
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation) 
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            ) 
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) 
DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) 
DRV:64bit: - (tdcmdpst) -- C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.) 
DRV:64bit: - (risdpcie) -- C:\Windows\SysNative\drivers\risdpe64.sys (REDC) 
DRV:64bit: - (tos_sps64) -- C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation) 
DRV:64bit: - (TVALZ) -- C:\Windows\SysNative\drivers\TVALZ.SYS (TOSHIBA Corporation) 
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) 
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) 
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) 
DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) 
DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) 
DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) 
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) 
DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) 
DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) 
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) 
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) 
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation) 
DRV:64bit: - (rixdpcie) -- C:\Windows\SysNative\drivers\rixdpe64.sys (REDC) 
DRV:64bit: - (rimspci) -- C:\Windows\SysNative\drivers\rimspe64.sys (REDC) 
DRV:64bit: - (Thpevm) -- C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation) 
DRV:64bit: - (Thpdrv) -- C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation) 
DRV:64bit: - (PGEffect) -- C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation) 
DRV:64bit: - (TVALZFL) -- C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation) 
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp) 
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () 
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) 
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) 
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) 
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) 
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
  
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEH&bmod=TSEH 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
  
  
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) 
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.) 
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. 
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) 
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.) 
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) 
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) 
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) 
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) 
O4:64bit: - HKLM..\Run: []  File not found 
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Programme\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) 
O4:64bit: - HKLM..\Run: [HSON] C:\Programme\Toshiba\TBS\HSON.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) 
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) 
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) 
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Programme\Toshiba\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [SmoothView] C:\Programme\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Programme\Toshiba\Registration\ToshibaReminder.exe (Toshiba Europe GmbH) 
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH) 
O4:64bit: - HKLM..\Run: [TosNC] C:\Programme\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Programme\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Programme\Toshiba\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Programme\Toshiba\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Programme\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation) 
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Programme\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation) 
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) 
O4 - HKLM..\Run: [TNRotate] C:\Program Files (x86)\TOSHIBA\TNRotate\TNRotate.exe (TOSHIBA Corporation) 
O4 - HKLM..\Run: [TOSDCR] C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe () 
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation) 
O4 - HKLM..\Run: [TUSBSleepChargeSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA) 
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.) 
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) 
O4 - HKCU..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe (TOSHIBA) 
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) 
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) 
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) 
O13 - gopher Prefix: missing 
O13 - gopher Prefix: missing 
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) 
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) 
O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab (CeWe Color AG & Co. OHG Control) 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14) 
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14) 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) 
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 
O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found 
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found 
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation) 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O32 - HKLM CDRom: AutoRun - 1 
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2010.07.24 07:28:14 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Thomas\Desktop\OTL.exe 
[2010.07.23 23:31:26 | 000,000,000 | ---D | C] -- C:\Users\Thomas\AppData\Roaming\Malwarebytes 
[2010.07.23 23:31:12 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys 
[2010.07.23 23:31:10 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys 
[2010.07.23 23:31:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware 
[2010.07.23 23:31:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2010.07.16 10:54:16 | 000,000,000 | -HSD | C] -- C:\Config.Msi 
[2010.07.14 11:24:31 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cdd.dll 
[2010.06.28 11:31:13 | 000,000,000 | ---D | C] -- C:\Users\Thomas\Documents\Mein Garmin 
[2010.06.28 11:31:12 | 000,000,000 | ---D | C] -- C:\Users\Thomas\AppData\Roaming\GARMIN 
[2010.06.28 11:31:12 | 000,000,000 | ---D | C] -- C:\ProgramData\GARMIN 
[2010.06.28 11:30:23 | 000,000,000 | ---D | C] -- C:\Programme\Tracks4Africa 
[2010.06.28 11:29:45 | 000,000,000 | ---D | C] -- C:\Programme\DIFX 
[2010.06.28 11:29:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Garmin 
[2010.06.28 11:29:20 | 000,000,000 | ---D | C] -- C:\MapSource 
[2010.06.28 11:29:20 | 000,000,000 | ---D | C] -- C:\Garmin 
[2010.06.25 12:27:14 | 000,000,000 | ---D | C] -- C:\ProgramData\tmp 
[2010.06.25 12:27:14 | 000,000,000 | ---D | C] -- C:\ProgramData\hps 
[2010.06.25 12:21:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Müller Foto 
[2010.06.24 14:09:11 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dfshim.dll 
[2010.06.24 14:09:11 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dfshim.dll 
[2010.06.24 14:09:11 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\PresentationHost.exe 
[2010.06.24 14:09:11 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PresentationHost.exe 
[2010.06.24 14:09:11 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\PresentationHostProxy.dll 
[2010.06.24 14:09:11 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PresentationHostProxy.dll 
[2010.06.24 14:09:11 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netfxperf.dll 
[2010.06.24 14:09:11 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\netfxperf.dll 
[2010.06.24 10:18:26 | 001,736,608 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntdll.dll 
[2010.06.24 10:18:22 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\CPFilters.dll 
[2010.06.24 10:18:21 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CPFilters.dll 
[2010.06.24 10:18:21 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mpg2splt.ax 
[2010.06.24 10:18:20 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msdri.dll 
[2010.06.24 10:18:20 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\MSNP.ax 
[2010.06.24 10:18:20 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MSNP.ax 
[2010.06.24 10:18:20 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mpg2splt.ax 
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] 
   ========== Files - Modified Within 30 Days ========== 
  
[2010.07.24 07:32:08 | 001,572,864 | -HS- | M] () -- C:\Users\Thomas\NTUSER.DAT 
[2010.07.24 07:28:16 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Thomas\Desktop\OTL.exe 
[2010.07.24 07:27:00 | 000,025,088 | ---- | M] () -- C:\Users\Thomas\Documents\Malwarebytes.doc 
[2010.07.24 07:13:51 | 000,001,108 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job 
[2010.07.24 07:13:07 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat 
[2010.07.23 23:31:15 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2010.07.23 22:13:05 | 000,001,104 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job 
[2010.07.23 21:08:30 | 000,017,280 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2010.07.23 21:08:30 | 000,017,280 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2010.07.23 21:01:07 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT 
[2010.07.23 21:00:53 | 1447,366,656 | -HS- | M] () -- C:\hiberfil.sys 
[2010.07.23 17:13:44 | 001,800,890 | -H-- | M] () -- C:\Users\Thomas\AppData\Local\IconCache.db 
[2010.07.22 13:33:50 | 001,472,002 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI 
[2010.07.22 13:33:50 | 000,643,866 | ---- | M] () -- C:\windows\SysNative\perfh007.dat 
[2010.07.22 13:33:50 | 000,607,190 | ---- | M] () -- C:\windows\SysNative\perfh009.dat 
[2010.07.22 13:33:50 | 000,126,394 | ---- | M] () -- C:\windows\SysNative\perfc007.dat 
[2010.07.22 13:33:50 | 000,103,568 | ---- | M] () -- C:\windows\SysNative\perfc009.dat 
[2010.07.22 13:29:42 | 000,022,271 | ---- | M] () -- C:\Users\Thomas\Documents\Baar.ahn 
[2010.07.22 13:23:13 | 000,022,137 | ---- | M] () -- C:\Users\Thomas\Documents\Baar.001.bak 
[2010.07.22 13:07:15 | 000,021,398 | ---- | M] () -- C:\Users\Thomas\Documents\Baar.002.bak 
[2010.07.22 12:53:42 | 000,020,199 | ---- | M] () -- C:\Users\Thomas\Documents\Baar.003.bak 
[2010.07.22 12:50:03 | 000,020,161 | ---- | M] () -- C:\Users\Thomas\Documents\Baar.004.bak 
[2010.07.22 12:38:21 | 000,016,964 | ---- | M] () -- C:\Users\Thomas\Documents\Baar.005.bak 
[2010.07.18 22:06:31 | 000,031,232 | ---- | M] () -- C:\Users\Thomas\Documents\Urlaub Namibia 2010.xls 
[2010.07.16 21:23:44 | 000,021,504 | ---- | M] () -- C:\Users\Thomas\Documents\NÜSSLEIN CHECK.xls 
[2010.07.16 10:54:26 | 000,002,025 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk 
[2010.07.16 10:38:51 | 000,107,200 | ---- | M] () -- C:\Users\Thomas\AppData\Roaming\GDIPFONTCACHEV1.DAT 
[2010.07.08 22:26:26 | 000,020,480 | ---- | M] () -- C:\Users\Thomas\Documents\Checkliste Urlaub.xls 
[2010.06.29 11:13:49 | 003,251,031 | ---- | M] () -- C:\Users\Thomas\Documents\t4a_maps_1005_15.zip 
[2010.06.29 11:12:36 | 016,653,043 | ---- | M] () -- C:\Users\Thomas\Documents\t4a_maps_1005_10_03.zip 
[2010.06.28 11:58:50 | 000,001,853 | ---- | M] () -- C:\Users\Thomas\Desktop\MapSource.lnk 
[2010.06.28 11:33:47 | 013,293,146 | ---- | M] () -- C:\Users\Thomas\Documents\t4a_maps_1005_07_02.zip 
[2010.06.25 12:36:45 | 000,001,225 | ---- | M] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 
[2010.06.25 12:36:45 | 000,001,210 | ---- | M] () -- C:\Users\Public\Desktop\Müller Foto.lnk 
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] 
   ========== Files Created - No Company Name ========== 
  
[2010.07.24 07:27:00 | 000,025,088 | ---- | C] () -- C:\Users\Thomas\Documents\Malwarebytes.doc 
[2010.07.23 23:31:15 | 000,001,024 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2010.07.16 21:23:44 | 000,021,504 | ---- | C] () -- C:\Users\Thomas\Documents\NÜSSLEIN CHECK.xls 
[2010.06.29 11:13:34 | 003,251,031 | ---- | C] () -- C:\Users\Thomas\Documents\t4a_maps_1005_15.zip 
[2010.06.29 11:12:33 | 016,653,043 | ---- | C] () -- C:\Users\Thomas\Documents\t4a_maps_1005_10_03.zip 
[2010.06.28 11:58:50 | 000,001,853 | ---- | C] () -- C:\Users\Thomas\Desktop\MapSource.lnk 
[2010.06.28 11:33:37 | 013,293,146 | ---- | C] () -- C:\Users\Thomas\Documents\t4a_maps_1005_07_02.zip 
[2010.06.28 10:00:44 | 026,350,480 | ---- | C] () -- C:\Users\Thomas\Documents\Garmin__t4a_maps_910_10-1272297249.zip 
[2010.06.25 12:36:45 | 000,001,225 | ---- | C] () -- C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk 
[2010.06.25 12:36:45 | 000,001,210 | ---- | C] () -- C:\Users\Public\Desktop\Müller Foto.lnk 
[2010.05.25 21:29:10 | 000,000,400 | ---- | C] () -- C:\windows\ODBC.INI 
[2010.03.16 20:28:31 | 000,000,000 | ---- | C] () -- C:\windows\NDSTray.INI 
[2009.11.06 15:48:48 | 000,208,896 | ---- | C] () -- C:\windows\SysWow64\iglhsip32.dll 
[2009.11.06 15:48:48 | 000,143,360 | ---- | C] () -- C:\windows\SysWow64\iglhcp32.dll 
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll 
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll 
< End of report >   --- --- ---   
2. OTL-Log:  
OTL Logfile:   Code:  
 OTL Extras logfile created on: 24.07.2010 07:30:05 - Run 1 
OTL by OldTimer - Version 3.2.9.1     Folder = C:\Users\Thomas\Desktop 
64bit- An unknown product  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 40,00% Memory free 
4,00 Gb Paging File | 2,00 Gb Available in Paging File | 52,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 224,47 Gb Total Space | 168,54 Gb Free Space | 75,08% Space Free | Partition Type: NTFS 
D: Drive not present or media not loaded 
E: Drive not present or media not loaded 
F: Drive not present or media not loaded 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: LAPTOP-THOMAS 
Current User Name: Thomas 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: Current user 
Include 64bit Scans 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) 
   ========== Shell Spawning ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* File not found 
cmdfile [open] -- "%1" %* File not found 
comfile [open] -- "%1" %* File not found 
exefile [open] -- "%1" %* File not found 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* File not found 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" File not found 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S File not found 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found 
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\Müller Foto\Müller Foto\CEWE FOTOSCHAU.exe" -d "%1" () 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [Müller Foto] -- "C:\Program Files (x86)\Müller Foto\Müller Foto\Müller Foto.exe" "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [CEWE FOTOSCHAU] -- "C:\Program Files (x86)\Müller Foto\Müller Foto\CEWE FOTOSCHAU.exe" -d "%1" () 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [Müller Foto] -- "C:\Program Files (x86)\Müller Foto\Müller Foto\Müller Foto.exe" "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data] 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
   ========== Authorized Applications List ========== 
  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package 
"{5BCC94A1-DEF1-4AB4-8046-BC13048E929A}" = TOSHIBA ReelTime 
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator 
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center 
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 
"{94A90C69-71C1-470A-88F5-AA47ECC96B40}" = TOSHIBA HDD Protection 
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor 
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver 
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility 
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator 
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert 
"{F64684A0-754B-4637-B7F9-6E8DAA8CD5CD}" = TOSHIBA Bulletin Board 
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition 
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 2.3.0.0) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}" = RICOH R5U230 Media Driver ver.2.07.03.02 
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package 
"{09298F26-A95C-31E2-9D95-2C60F586F075}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 
"{14555947-6F14-421F-8F61-6489E0FDFAE5}" = Toshiba TEMPRO 
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer 
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = Toshiba Assist 
"{1C84AB70-7851-D03E-14B0-2CE969DD6CBA}" = Photo Service - powered by myphotobook 
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool 
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information 
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT 
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer 
"{2457326B-C110-40C3-89B0-889CC913871A}" = AVM FRITZ!DSL 
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 14 
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie 
"{2E54DAC2-BDF7-49EC-87AF-B38E3B096BC6}" = TOSHIBA 180 Degrees Rotation Utility 
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform 
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology 
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger 
"{510D2239-6C2E-457B-9590-485EC552D94D}" = Garmin USB Drivers 
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent 
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application 
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call 
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components 
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER 
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable 
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync 
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder 
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{90300407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content 
"{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = Toshiba Manuals 
"{91110407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional 
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station 
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.3 - Deutsch 
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility 
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program 
"{C4D26D60-7B43-4CE9-AE19-A380D9DF126B}" = Garmin MapSource 
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail 
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert 
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer 
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update 
"{E487EE7D-EAAA-4E2A-9116-E3B477D8A74F}" = TOSHIBA USB Sleep and Charge Utility 
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] 
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard 
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver 
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver 
"{F3529665-D75E-4D6D-98F0-745C78C68E9B}" = TOSHIBA ConfigFree 
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center 
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials 
"Adobe AIR" = Adobe AIR 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Ahnenblatt_is1" = Ahnenblatt 2.62 
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus 
"AVMFBox" = AVM FRITZ!Box Dokumentation 
"AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss 
"eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1" = Photo Service - powered by myphotobook 
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package 
"InstallShield_{2E54DAC2-BDF7-49EC-87AF-B38E3B096BC6}" = TOSHIBA 180 Degrees Rotation Utility 
"InstallShield_{5BCC94A1-DEF1-4AB4-8046-BC13048E929A}" = TOSHIBA ReelTime 
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center 
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder 
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility 
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert 
"InstallShield_{F64684A0-754B-4637-B7F9-6E8DAA8CD5CD}" = TOSHIBA Bulletin Board 
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition 
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware 
"Müller Foto" = Müller Foto 
"T4A Maps Angola" = T4A Maps Angola 
"T4A Maps Kruger National Park v7.10 (ROUTABLE)" = T4A Maps Kruger National Park v7.10 (ROUTABLE) 
"T4A Maps Namibia " = T4A Maps Namibia  
"T4A Maps Western /Northern Cape " = T4A Maps Western /Northern Cape  
"WinLiveSuite_Wave3" = Windows Live Essentials 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 08.07.2010 05:13:05 | Computer Name = Laptop-Thomas | Source = Google Update | ID = 20 
Description =  
  
Error - 09.07.2010 05:10:43 | Computer Name = Laptop-Thomas | Source = SideBySide | ID = 16842815 
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files 
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder 
 Richtliniendatei "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe 
 AIR.dll" in Zeile 3.  Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" 
 des "version"-Attributs im assemblyIdentity-Element ist ungültig. 
  
Error - 09.07.2010 05:40:33 | Computer Name = Laptop-Thomas | Source = Application Hang | ID = 1002 
Description = Programm PhotoScreensaver.scr, Version 6.1.7600.16385 kann nicht mehr 
 unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf 
 in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem 
 zu suchen.    Prozess-ID: 126c    Startzeit: 01cb1f41c58e8dc5    Endzeit: 16    Anwendungspfad: 
 C:\windows\system32\PhotoScreensaver.scr    Berichts-ID: 00c65853-8b3e-11df-a7be-002318eb167c   
  
Error - 11.07.2010 14:20:56 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.07.2010 14:20:58 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.07.2010 14:21:05 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.07.2010 14:21:05 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.07.2010 14:21:13 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.07.2010 14:21:18 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.07.2010 14:21:51 | Computer Name = Laptop-Thomas | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
[ System Events ] 
Error - 26.05.2010 08:04:16 | Computer Name = Laptop-Thomas | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. 
  
Error - 26.05.2010 08:04:17 | Computer Name = Laptop-Thomas | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. 
  
Error - 26.05.2010 08:04:17 | Computer Name = Laptop-Thomas | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. 
  
Error - 27.05.2010 09:25:02 | Computer Name = Laptop-Thomas | Source = EventLog | ID = 6008 
Description = Das System wurde zuvor am ?26.?05.?2010 um 14:27:55 unerwartet heruntergefahren. 
  
Error - 29.05.2010 03:07:23 | Computer Name = Laptop-Thomas | Source = EventLog | ID = 6008 
Description = Das System wurde zuvor am ?29.?05.?2010 um 09:05:18 unerwartet heruntergefahren. 
  
Error - 02.06.2010 17:31:22 | Computer Name = Laptop-Thomas | Source = Ntfs | ID = 262199 
Description = Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. 
Führen 
 Sie auf dem Volume "TI30543600A" den Befehl "chkdsk" aus. 
  
Error - 20.06.2010 07:23:44 | Computer Name = Laptop-Thomas | Source = Service Control Manager | ID = 7009 
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst 
 Windows Search erreicht. 
  
Error - 20.06.2010 07:23:44 | Computer Name = Laptop-Thomas | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht 
 gestartet:   %%1053 
  
Error - 20.06.2010 07:23:44 | Computer Name = Laptop-Thomas | Source = DCOM | ID = 10005 
Description =  
  
Error - 02.07.2010 05:05:15 | Computer Name = Laptop-Thomas | Source = EventLog | ID = 6008 
Description = Das System wurde zuvor am ?02.?07.?2010 um 11:03:40 unerwartet heruntergefahren. 
  
  
< End of report >   --- --- ---    |