Seite 1 von 2 12 LetzteLetzte
Ergebnis 1 bis 10 von 12

Thema: Bundespolizei Trojaner seit gestern

  1. #1
    Forenbenutzer
    Registriert seit
    22.08.2009
    Beiträge
    58

    Bundespolizei Trojaner seit gestern

    Hallo
    ich habe mir den Bundespolizei Trojaner eingefangen und nun im abgesicherten Modus einen WScan gemacht.

    Code:
    OTL logfile created on: 03.12.2011 13:48:18 - Run 2
    OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Peter\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
     
    4,00 Gb Total Physical Memory | 2,65 Gb Available Physical Memory | 66,35% Memory free
    8,00 Gb Paging File | 6,94 Gb Available in Paging File | 86,83% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 100,01 Gb Total Space | 44,55 Gb Free Space | 44,55% Space Free | Partition Type: NTFS
    Drive D: | 831,50 Gb Total Space | 682,12 Gb Free Space | 82,03% Space Free | Partition Type: NTFS
     
    Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
    Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Processes (SafeList) ==========
     
    PRC - [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    PRC - [2011.12.03 13:01:27 | 001,962,152 | ---- | M] (Avira GmbH) -- C:\Users\Peter\AppData\Local\Temp\decleaner\decleaner\setup\deCleaner.exe
    PRC - [2011.12.03 13:01:09 | 000,514,216 | ---- | M] (Avira GmbH) -- C:\Users\Peter\AppData\Local\Temp\decleaner\decleaner\setup\avscan.exe
    PRC - [2011.11.09 17:21:35 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2011.10.19 16:55:48 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2011.02.17 09:30:23 | 000,299,688 | ---- | M] (Avira GmbH) -- C:\Users\Peter\AppData\Local\Temp\decleaner\avwebloader.exe
     
     
    ========== Modules (No Company Name) ==========
     
    MOD - [2011.11.09 17:21:34 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    MOD - [2011.11.02 20:52:06 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    MOD - [2011.02.04 11:39:40 | 000,126,824 | ---- | M] () -- C:\Users\Peter\AppData\Local\Temp\decleaner\scewxmlw.dll
     
     
    ========== Win32 Services (SafeList) ==========
     
    SRV:64bit: - [2011.06.06 16:49:50 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
    SRV:64bit: - [2010.05.27 17:59:40 | 000,203,264 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV - [2011.10.19 16:56:01 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2011.10.19 16:55:48 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011.09.12 08:58:19 | 000,688,648 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
    SRV - [2011.08.12 16:13:26 | 000,087,040 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
    SRV - [2011.06.06 16:54:54 | 002,026,304 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
    SRV - [2011.06.06 16:49:44 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
    SRV - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
    SRV - [2010.11.20 13:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
    SRV - [2010.11.05 10:28:14 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus)
    SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009.08.10 15:01:06 | 000,206,880 | ---- | M] () [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
    SRV - [2009.08.10 15:01:04 | 000,626,208 | ---- | M] () [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
    SRV - [2009.06.18 14:19:30 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008.10.03 21:41:22 | 000,743,192 | ---- | M] (Acronis) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
    SRV - [2008.04.07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2007.05.31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
    SRV - [2007.05.31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV:64bit: - [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR162.SYS -- (SMR162)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,130,760 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
    DRV:64bit: - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
    DRV:64bit: - [2011.05.10 07:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010.12.16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
    DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010.08.12 11:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
    DRV:64bit: - [2010.07.22 16:02:35 | 001,580,576 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm140.sys -- (tdrpman140) Acronis Try&Decide and Restore Points filter (build 140)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,880,160 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,083,488 | ---- | M] (Acronis) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\tifsfilt.sys -- (tifsfilter)
    DRV:64bit: - [2010.07.22 16:02:30 | 000,237,600 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380)
    DRV:64bit: - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
    DRV:64bit: - [2010.05.27 18:39:12 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2010.05.27 17:25:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2010.04.13 08:04:38 | 001,270,784 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV:64bit: - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
    DRV:64bit: - [2009.09.25 09:13:26 | 000,205,440 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
    DRV:64bit: - [2009.07.17 00:51:54 | 000,028,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvamacpi.sys -- (nvamacpi)
    DRV:64bit: - [2009.07.16 11:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
    DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
    DRV:64bit: - [2009.06.10 21:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
    DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009.02.03 16:46:14 | 000,077,952 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfsync04.sys -- (sfsync04) StarForce Protection Synchronization Driver (version 4.x)
    DRV:64bit: - [2009.02.03 16:40:13 | 000,077,432 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
    DRV:64bit: - [2007.09.17 14:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
    DRV:64bit: - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV:64bit: - [2007.02.08 18:47:24 | 000,107,384 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
    DRV:64bit: - [2006.06.14 15:58:10 | 000,014,192 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
    DRV - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
    DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV - [2007.02.07 19:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
     
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.kiebel.de
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2206084
    IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - No CLSID value found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
     
    ========== FireFox ==========
     
     
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
    FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
     
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.02.13 14:39:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.09 17:21:35 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.10.28 22:22:57 | 000,000,000 | ---D | M]
     
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions
    [2011.02.24 21:00:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2011.11.09 17:21:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
    [2011.11.09 17:21:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2008.06.19 10:16:24 | 000,118,784 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\MyCamera.dll
    [2008.06.19 10:16:24 | 000,053,248 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\NPCIG.dll
    [2010.09.15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2011.10.08 17:38:48 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
    [2011.10.08 17:38:48 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011.10.08 17:38:48 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
    [2011.10.08 17:38:48 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
    [2011.10.08 17:38:48 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
    [2011.10.08 17:38:48 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
     
    O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
    O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
    O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
    O4 - HKCU..\Run: [Personal ID] C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE (coolspot AG, Düsseldorf)
    O4:64bit: - HKLM..\RunOnce: [GrpConv] C:\Windows\SysNative\grpconv.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKCU..\RunOnce: [*NMRUI] C:\Users\Peter\Desktop\de_cleaner.exe (Symantec Corporation)
    O4 - Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    F3:64bit: - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) - C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe ()
    F3 - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) -C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8:64bit: - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O8 - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8 - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8 - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8 - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8 - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8 - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Domains: amazon.de ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
    O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87F7A994-F44E-4345-B88E-03ECE07BAB9D}: DhcpNameServer = 192.168.178.1
    O18:64bit: - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O27:64bit: - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
     
    ========== Files/Folders - Created Within 30 Days ==========
     
    [2011.12.03 13:47:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 13:00:42 | 099,084,008 | ---- | C] (                                                            ) -- C:\Users\Peter\Desktop\setup_9.0.0.722_27.11.2011_06-22.exe
    [2011.12.03 12:59:25 | 000,090,232 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2011.12.03 12:59:22 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\NPE
    [2011.12.03 12:59:01 | 006,161,912 | ---- | C] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 01:09:34 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Avira
    [2011.12.03 01:09:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
    [2011.12.03 01:09:11 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
    [2011.12.03 01:09:11 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
    [2011.12.03 01:09:11 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
    [2011.11.23 14:54:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2011.11.23 14:52:48 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2011.11.21 15:35:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DataDesign
    [2011.11.21 15:33:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sybase
    [2011.11.20 21:20:12 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\TIPP10
    [2011.11.20 21:20:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIPP10
    [2011.11.17 17:21:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011.11.13 13:55:16 | 000,000,000 | ---D | C] -- C:\Users\Peter\Desktop\Games
     
    ========== Files - Modified Within 30 Days ==========
     
    [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 13:46:48 | 000,000,000 | ---- | M] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 13:45:50 | 000,050,477 | ---- | M] () -- C:\Users\Peter\Desktop\Defogger.exe
    [2011.12.03 13:03:13 | 099,084,008 | ---- | M] (                                                            ) -- C:\Users\Peter\Desktop\setup_9.0.0.722_27.11.2011_06-22.exe
    [2011.12.03 13:00:58 | 000,002,022 | ---- | M] () -- C:\Users\Peter\Desktop\Entfernen des Avira DE-Cleaners.lnk
    [2011.12.03 13:00:58 | 000,001,951 | ---- | M] () -- C:\Users\Peter\Desktop\Avira DE-Cleaner.lnk
    [2011.12.03 12:59:37 | 000,000,020 | ---- | M] () -- C:\Windows\SysNative\drivers\SMR162.dat
    [2011.12.03 12:59:31 | 000,000,761 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:08 | 006,161,912 | ---- | M] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 12:58:02 | 000,883,840 | ---- | M] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:15:21 | 056,877,146 | ---- | M] () -- C:\Users\Peter\Desktop\vdf_fusebundle.zip
    [2011.12.03 01:12:48 | 001,766,796 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2011.12.03 01:12:48 | 000,759,454 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
    [2011.12.03 01:12:48 | 000,703,364 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2011.12.03 01:12:48 | 000,169,072 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
    [2011.12.03 01:12:48 | 000,137,512 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2011.12.03 01:09:26 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 01:08:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011.12.03 01:02:28 | 084,419,032 | ---- | M] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.12.03 00:58:18 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.12.03 00:54:37 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011.12.03 00:19:05 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011.12.03 00:19:05 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011.12.01 16:20:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011.11.23 14:54:54 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:53:19 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2011.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | M] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | M] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | M] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.15 11:51:31 | 000,041,377 | ---- | M] () -- C:\Users\Peter\Desktop\Muster017.pdf
    [2011.11.13 13:55:12 | 000,000,628 | ---- | M] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.09 17:08:21 | 000,350,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
     
    ========== Files Created - No Company Name ==========
     
    [2011.12.03 13:46:48 | 000,000,000 | ---- | C] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 13:45:59 | 000,050,477 | ---- | C] () -- C:\Users\Peter\Desktop\Defogger.exe
    [2011.12.03 13:00:58 | 000,002,022 | ---- | C] () -- C:\Users\Peter\Desktop\Entfernen des Avira DE-Cleaners.lnk
    [2011.12.03 13:00:58 | 000,001,951 | ---- | C] () -- C:\Users\Peter\Desktop\Avira DE-Cleaner.lnk
    [2011.12.03 12:59:31 | 000,000,761 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:59:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\drivers\SMR162.dat
    [2011.12.03 12:58:09 | 000,883,840 | ---- | C] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:11:40 | 056,877,146 | ---- | C] () -- C:\Users\Peter\Desktop\vdf_fusebundle.zip
    [2011.12.03 01:09:26 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 00:58:18 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.12.03 00:57:41 | 084,419,032 | ---- | C] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.11.23 14:54:54 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | C] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | C] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | C] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.15 11:51:31 | 000,041,377 | ---- | C] () -- C:\Users\Peter\Desktop\Muster017.pdf
    [2011.11.13 13:55:12 | 000,000,628 | ---- | C] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.08 10:56:09 | 005,133,509 | ---- | C] () -- C:\Users\Peter\Desktop\IMG_8450.JPG
    [2011.09.27 11:17:26 | 000,198,144 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll
    [2011.09.27 11:16:20 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll
    [2011.09.27 11:14:14 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll
    [2011.09.27 11:13:58 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll
    [2011.06.10 11:53:49 | 001,456,640 | ---- | C] () -- C:\Program Files (x86)\Common Files\Falk Navi-Manager.msi
    [2011.04.30 15:18:32 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{D431F69B-9F80-4998-8606-16B2FF4763C2}
    [2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
    [2011.02.13 15:06:41 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
    [2010.11.03 22:34:25 | 000,000,038 | ---- | C] () -- C:\Windows\osAviSplitter.INI
    [2010.10.21 14:18:46 | 000,303,104 | ---- | C] () -- C:\Windows\SysWow64\dnt27VC8.dll
    [2010.10.21 14:16:58 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\dntvmc27VC8.dll
    [2010.10.21 14:16:34 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dntvm27VC8.dll
    [2010.10.17 19:03:42 | 001,653,284 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2010.09.24 12:27:18 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
    [2010.08.27 16:22:42 | 000,000,123 | -HS- | C] () -- C:\ProgramData\.zreglib
    [2010.08.19 16:11:13 | 000,003,314 | ---- | C] () -- C:\Windows\cdplayer.ini
    [2010.08.14 18:02:08 | 008,676,883 | ---- | C] () -- C:\Windows\SysWow64\NCMedia2.dll
    [2010.08.14 13:07:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2010.08.14 12:46:47 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
    [2010.08.11 19:14:48 | 000,015,873 | ---- | C] () -- C:\Windows\SysWow64\Inetde.dll
    [2010.08.01 15:26:08 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2010.07.25 18:27:31 | 000,027,648 | ---- | C] () -- C:\Users\Peter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010.07.25 13:49:01 | 000,000,130 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\default.rss
    [2010.07.24 20:05:40 | 000,111,932 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
    [2010.07.24 20:05:40 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
    [2010.07.24 20:05:40 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
    [2010.07.24 20:05:40 | 000,026,154 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
    [2010.07.24 20:05:40 | 000,024,903 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
    [2010.07.24 20:05:40 | 000,021,390 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
    [2010.07.24 20:05:40 | 000,020,148 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
    [2010.07.24 20:05:40 | 000,011,811 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
    [2010.07.24 20:05:40 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
    [2010.07.24 20:05:40 | 000,001,146 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
    [2010.07.24 20:05:40 | 000,001,136 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
    [2010.07.24 20:05:40 | 000,001,120 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
    [2010.07.24 20:05:40 | 000,001,107 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
    [2010.07.24 20:05:40 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
    [2010.07.24 20:05:40 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
    [2010.06.21 12:08:08 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2010.06.21 12:03:04 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
    [2010.06.21 12:03:04 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
    [2010.06.21 12:03:01 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
    [2010.06.21 12:03:01 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
    [2010.06.21 11:29:41 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010.06.21 11:29:41 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
    [2010.06.21 11:29:40 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2010.06.21 11:29:40 | 000,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2010.04.29 16:37:26 | 000,002,137 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2009.11.25 13:40:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2009.09.30 11:05:48 | 000,290,816 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v60.dll
    [2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008.10.30 17:00:22 | 000,048,640 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v60.dll
    [2008.10.30 16:59:24 | 000,025,088 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v60.dll
    [2006.04.21 09:08:22 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\HtmlHelp.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v50.dll
     
    ========== Alternate Data Streams ==========
     
    @Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:96D0C06F
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:42D9E231
    
    < End of report >
    Code:
    OTL logfile created on: 03.12.2011 13:48:18 - Run 2
    OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Peter\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
     
    4,00 Gb Total Physical Memory | 2,65 Gb Available Physical Memory | 66,35% Memory free
    8,00 Gb Paging File | 6,94 Gb Available in Paging File | 86,83% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 100,01 Gb Total Space | 44,55 Gb Free Space | 44,55% Space Free | Partition Type: NTFS
    Drive D: | 831,50 Gb Total Space | 682,12 Gb Free Space | 82,03% Space Free | Partition Type: NTFS
     
    Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
    Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Processes (SafeList) ==========
     
    PRC - [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    PRC - [2011.12.03 13:01:27 | 001,962,152 | ---- | M] (Avira GmbH) -- C:\Users\Peter\AppData\Local\Temp\decleaner\decleaner\setup\deCleaner.exe
    PRC - [2011.12.03 13:01:09 | 000,514,216 | ---- | M] (Avira GmbH) -- C:\Users\Peter\AppData\Local\Temp\decleaner\decleaner\setup\avscan.exe
    PRC - [2011.11.09 17:21:35 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2011.10.19 16:55:48 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2011.02.17 09:30:23 | 000,299,688 | ---- | M] (Avira GmbH) -- C:\Users\Peter\AppData\Local\Temp\decleaner\avwebloader.exe
     
     
    ========== Modules (No Company Name) ==========
     
    MOD - [2011.11.09 17:21:34 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    MOD - [2011.11.02 20:52:06 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    MOD - [2011.02.04 11:39:40 | 000,126,824 | ---- | M] () -- C:\Users\Peter\AppData\Local\Temp\decleaner\scewxmlw.dll
     
     
    ========== Win32 Services (SafeList) ==========
     
    SRV:64bit: - [2011.06.06 16:49:50 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
    SRV:64bit: - [2010.05.27 17:59:40 | 000,203,264 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV - [2011.10.19 16:56:01 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2011.10.19 16:55:48 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011.09.12 08:58:19 | 000,688,648 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
    SRV - [2011.08.12 16:13:26 | 000,087,040 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
    SRV - [2011.06.06 16:54:54 | 002,026,304 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
    SRV - [2011.06.06 16:49:44 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
    SRV - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
    SRV - [2010.11.20 13:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
    SRV - [2010.11.05 10:28:14 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus)
    SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009.08.10 15:01:06 | 000,206,880 | ---- | M] () [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
    SRV - [2009.08.10 15:01:04 | 000,626,208 | ---- | M] () [Auto | Stopped] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
    SRV - [2009.06.18 14:19:30 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008.10.03 21:41:22 | 000,743,192 | ---- | M] (Acronis) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
    SRV - [2008.04.07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2007.05.31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
    SRV - [2007.05.31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV:64bit: - [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR162.SYS -- (SMR162)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,130,760 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
    DRV:64bit: - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
    DRV:64bit: - [2011.05.10 07:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010.12.16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
    DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010.08.12 11:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
    DRV:64bit: - [2010.07.22 16:02:35 | 001,580,576 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm140.sys -- (tdrpman140) Acronis Try&Decide and Restore Points filter (build 140)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,880,160 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,083,488 | ---- | M] (Acronis) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\tifsfilt.sys -- (tifsfilter)
    DRV:64bit: - [2010.07.22 16:02:30 | 000,237,600 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380)
    DRV:64bit: - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
    DRV:64bit: - [2010.05.27 18:39:12 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2010.05.27 17:25:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2010.04.13 08:04:38 | 001,270,784 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV:64bit: - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
    DRV:64bit: - [2009.09.25 09:13:26 | 000,205,440 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
    DRV:64bit: - [2009.07.17 00:51:54 | 000,028,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvamacpi.sys -- (nvamacpi)
    DRV:64bit: - [2009.07.16 11:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
    DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
    DRV:64bit: - [2009.06.10 21:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
    DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009.02.03 16:46:14 | 000,077,952 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfsync04.sys -- (sfsync04) StarForce Protection Synchronization Driver (version 4.x)
    DRV:64bit: - [2009.02.03 16:40:13 | 000,077,432 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
    DRV:64bit: - [2007.09.17 14:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
    DRV:64bit: - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV:64bit: - [2007.02.08 18:47:24 | 000,107,384 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
    DRV:64bit: - [2006.06.14 15:58:10 | 000,014,192 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
    DRV - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
    DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV - [2007.02.07 19:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
     
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.kiebel.de
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2206084
    IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - No CLSID value found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
     
    ========== FireFox ==========
     
     
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
    FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
     
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.02.13 14:39:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.09 17:21:35 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.10.28 22:22:57 | 000,000,000 | ---D | M]
     
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions
    [2011.02.24 21:00:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2011.11.09 17:21:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
    [2011.11.09 17:21:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2008.06.19 10:16:24 | 000,118,784 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\MyCamera.dll
    [2008.06.19 10:16:24 | 000,053,248 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\NPCIG.dll
    [2010.09.15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2011.10.08 17:38:48 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
    [2011.10.08 17:38:48 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011.10.08 17:38:48 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
    [2011.10.08 17:38:48 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
    [2011.10.08 17:38:48 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
    [2011.10.08 17:38:48 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
     
    O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
    O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
    O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
    O4 - HKCU..\Run: [Personal ID] C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE (coolspot AG, Düsseldorf)
    O4:64bit: - HKLM..\RunOnce: [GrpConv] C:\Windows\SysNative\grpconv.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKCU..\RunOnce: [*NMRUI] C:\Users\Peter\Desktop\de_cleaner.exe (Symantec Corporation)
    O4 - Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    F3:64bit: - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) - C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe ()
    F3 - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) -C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8:64bit: - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O8 - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8 - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8 - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8 - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8 - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8 - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Domains: amazon.de ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
    O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87F7A994-F44E-4345-B88E-03ECE07BAB9D}: DhcpNameServer = 192.168.178.1
    O18:64bit: - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O27:64bit: - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
     
    ========== Files/Folders - Created Within 30 Days ==========
     
    [2011.12.03 13:47:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 13:00:42 | 099,084,008 | ---- | C] (                                                            ) -- C:\Users\Peter\Desktop\setup_9.0.0.722_27.11.2011_06-22.exe
    [2011.12.03 12:59:25 | 000,090,232 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2011.12.03 12:59:22 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\NPE
    [2011.12.03 12:59:01 | 006,161,912 | ---- | C] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 01:09:34 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Avira
    [2011.12.03 01:09:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
    [2011.12.03 01:09:11 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
    [2011.12.03 01:09:11 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
    [2011.12.03 01:09:11 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
    [2011.11.23 14:54:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2011.11.23 14:52:48 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2011.11.21 15:35:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DataDesign
    [2011.11.21 15:33:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sybase
    [2011.11.20 21:20:12 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\TIPP10
    [2011.11.20 21:20:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIPP10
    [2011.11.17 17:21:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011.11.13 13:55:16 | 000,000,000 | ---D | C] -- C:\Users\Peter\Desktop\Games
     
    ========== Files - Modified Within 30 Days ==========
     
    [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 13:46:48 | 000,000,000 | ---- | M] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 13:45:50 | 000,050,477 | ---- | M] () -- C:\Users\Peter\Desktop\Defogger.exe
    [2011.12.03 13:03:13 | 099,084,008 | ---- | M] (                                                            ) -- C:\Users\Peter\Desktop\setup_9.0.0.722_27.11.2011_06-22.exe
    [2011.12.03 13:00:58 | 000,002,022 | ---- | M] () -- C:\Users\Peter\Desktop\Entfernen des Avira DE-Cleaners.lnk
    [2011.12.03 13:00:58 | 000,001,951 | ---- | M] () -- C:\Users\Peter\Desktop\Avira DE-Cleaner.lnk
    [2011.12.03 12:59:37 | 000,000,020 | ---- | M] () -- C:\Windows\SysNative\drivers\SMR162.dat
    [2011.12.03 12:59:31 | 000,000,761 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:08 | 006,161,912 | ---- | M] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 12:58:02 | 000,883,840 | ---- | M] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:15:21 | 056,877,146 | ---- | M] () -- C:\Users\Peter\Desktop\vdf_fusebundle.zip
    [2011.12.03 01:12:48 | 001,766,796 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2011.12.03 01:12:48 | 000,759,454 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
    [2011.12.03 01:12:48 | 000,703,364 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2011.12.03 01:12:48 | 000,169,072 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
    [2011.12.03 01:12:48 | 000,137,512 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2011.12.03 01:09:26 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 01:08:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011.12.03 01:02:28 | 084,419,032 | ---- | M] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.12.03 00:58:18 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.12.03 00:54:37 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011.12.03 00:19:05 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011.12.03 00:19:05 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011.12.01 16:20:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011.11.23 14:54:54 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:53:19 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2011.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | M] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | M] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | M] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.15 11:51:31 | 000,041,377 | ---- | M] () -- C:\Users\Peter\Desktop\Muster017.pdf
    [2011.11.13 13:55:12 | 000,000,628 | ---- | M] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.09 17:08:21 | 000,350,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
     
    ========== Files Created - No Company Name ==========
     
    [2011.12.03 13:46:48 | 000,000,000 | ---- | C] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 13:45:59 | 000,050,477 | ---- | C] () -- C:\Users\Peter\Desktop\Defogger.exe
    [2011.12.03 13:00:58 | 000,002,022 | ---- | C] () -- C:\Users\Peter\Desktop\Entfernen des Avira DE-Cleaners.lnk
    [2011.12.03 13:00:58 | 000,001,951 | ---- | C] () -- C:\Users\Peter\Desktop\Avira DE-Cleaner.lnk
    [2011.12.03 12:59:31 | 000,000,761 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:59:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\drivers\SMR162.dat
    [2011.12.03 12:58:09 | 000,883,840 | ---- | C] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:11:40 | 056,877,146 | ---- | C] () -- C:\Users\Peter\Desktop\vdf_fusebundle.zip
    [2011.12.03 01:09:26 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 00:58:18 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.12.03 00:57:41 | 084,419,032 | ---- | C] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.11.23 14:54:54 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | C] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | C] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | C] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.15 11:51:31 | 000,041,377 | ---- | C] () -- C:\Users\Peter\Desktop\Muster017.pdf
    [2011.11.13 13:55:12 | 000,000,628 | ---- | C] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.08 10:56:09 | 005,133,509 | ---- | C] () -- C:\Users\Peter\Desktop\IMG_8450.JPG
    [2011.09.27 11:17:26 | 000,198,144 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll
    [2011.09.27 11:16:20 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll
    [2011.09.27 11:14:14 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll
    [2011.09.27 11:13:58 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll
    [2011.06.10 11:53:49 | 001,456,640 | ---- | C] () -- C:\Program Files (x86)\Common Files\Falk Navi-Manager.msi
    [2011.04.30 15:18:32 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{D431F69B-9F80-4998-8606-16B2FF4763C2}
    [2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
    [2011.02.13 15:06:41 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
    [2010.11.03 22:34:25 | 000,000,038 | ---- | C] () -- C:\Windows\osAviSplitter.INI
    [2010.10.21 14:18:46 | 000,303,104 | ---- | C] () -- C:\Windows\SysWow64\dnt27VC8.dll
    [2010.10.21 14:16:58 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\dntvmc27VC8.dll
    [2010.10.21 14:16:34 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dntvm27VC8.dll
    [2010.10.17 19:03:42 | 001,653,284 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2010.09.24 12:27:18 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
    [2010.08.27 16:22:42 | 000,000,123 | -HS- | C] () -- C:\ProgramData\.zreglib
    [2010.08.19 16:11:13 | 000,003,314 | ---- | C] () -- C:\Windows\cdplayer.ini
    [2010.08.14 18:02:08 | 008,676,883 | ---- | C] () -- C:\Windows\SysWow64\NCMedia2.dll
    [2010.08.14 13:07:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2010.08.14 12:46:47 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
    [2010.08.11 19:14:48 | 000,015,873 | ---- | C] () -- C:\Windows\SysWow64\Inetde.dll
    [2010.08.01 15:26:08 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2010.07.25 18:27:31 | 000,027,648 | ---- | C] () -- C:\Users\Peter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010.07.25 13:49:01 | 000,000,130 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\default.rss
    [2010.07.24 20:05:40 | 000,111,932 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
    [2010.07.24 20:05:40 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
    [2010.07.24 20:05:40 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
    [2010.07.24 20:05:40 | 000,026,154 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
    [2010.07.24 20:05:40 | 000,024,903 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
    [2010.07.24 20:05:40 | 000,021,390 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
    [2010.07.24 20:05:40 | 000,020,148 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
    [2010.07.24 20:05:40 | 000,011,811 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
    [2010.07.24 20:05:40 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
    [2010.07.24 20:05:40 | 000,001,146 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
    [2010.07.24 20:05:40 | 000,001,136 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
    [2010.07.24 20:05:40 | 000,001,120 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
    [2010.07.24 20:05:40 | 000,001,107 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
    [2010.07.24 20:05:40 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
    [2010.07.24 20:05:40 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
    [2010.06.21 12:08:08 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2010.06.21 12:03:04 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
    [2010.06.21 12:03:04 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
    [2010.06.21 12:03:01 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
    [2010.06.21 12:03:01 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
    [2010.06.21 11:29:41 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010.06.21 11:29:41 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
    [2010.06.21 11:29:40 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2010.06.21 11:29:40 | 000,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2010.04.29 16:37:26 | 000,002,137 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2009.11.25 13:40:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2009.09.30 11:05:48 | 000,290,816 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v60.dll
    [2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008.10.30 17:00:22 | 000,048,640 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v60.dll
    [2008.10.30 16:59:24 | 000,025,088 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v60.dll
    [2006.04.21 09:08:22 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\HtmlHelp.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v50.dll
     
    ========== Alternate Data Streams ==========
     
    @Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:96D0C06F
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:42D9E231
    
    < End of report >
    Code:
     
                            $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ 
                            º                                    º 
                                        hjtscanlist v2.0              
                            º                                    º 
                            $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ 
    
    Microsoft Windows [Version 6.1.7601]
     
     
    C:
    
      03.12.2011 14:20     C:\Program Files (x86) --------- 32768   
      03.12.2011 14:10     C:\ProgramData --------- 12288   
      03.12.2011 12:59     C:\Windows --------- 24576   
           C:\pagefile.sys ---------    
      28.11.2011 23:54     C:\System Volume Information --------- 20480   
      23.11.2011 14:59     C:\Config.Msi --------- 0   
      23.11.2011 14:54     C:\Program Files --------- 8192   
      18.11.2011 19:31     C:\$Recycle.Bin --------- 4096   
      23.09.2011 19:54     C:\Users --------- 4096   
      07.08.2011 11:37     C:\Boot --------- 4096   
      20.11.2010 13:40     C:\bootmgr --------- 383786   
      17.10.2010 19:02     C:\inetpub --------- 0   
      14.08.2010 18:02     C:\videooutput --------- 0   
      25.07.2010 11:53     C:\MSOCache --------- 0   
      22.07.2010 15:49     C:\Recovery --------- 0   
      21.06.2010 12:03     C:\ATI --------- 0   
      21.06.2010 11:56     C:\NVIDIA --------- 0   
      21.06.2010 11:24     C:\BOOTSECT.BAK --------- 8192   
      21.06.2010 10:29     C:\Programme --------- 0   
      21.06.2010 10:29     C:\Dokumente und Einstellungen --------- 0   
      14.07.2009 06:08     C:\Documents and Settings --------- 0   
      14.07.2009 04:20     C:\PerfLogs --------- 0   
    ----------------------------------------
    
     
    C:\Windows
    
      03.12.2011 12:59     C:\Windows\ntbtlog.txt.bak --------- 602030   
      03.12.2011 01:08     C:\Windows\bootstat.dat --------- 67584   
      03.12.2011 01:08     C:\Windows\PFRO.log --------- 324   
      03.12.2011 01:04     C:\Windows\WindowsUpdate.log --------- 1650342   
      03.12.2011 00:54     C:\Windows\setupact.log --------- 50355   
      21.11.2011 15:34     C:\Windows\ODBC.INI --------- 153   
      29.10.2011 16:32     C:\Windows\setuperr.log --------- 0   
      25.02.2011 07:19     C:\Windows\explorer.exe --------- 2871808   
      22.11.2010 13:29     C:\Windows\osAviSplitter.INI --------- 38   
      20.11.2010 14:25     C:\Windows\splwow64.exe --------- 67072   
      20.11.2010 14:24     C:\Windows\bfsvc.exe --------- 71168   
      20.11.2010 13:21     C:\Windows\twain_32.dll --------- 51200   
      29.10.2010 15:51     C:\Windows\NeroDigital.ini --------- 69   
      24.09.2010 12:27     C:\Windows\DEBUGSM.INI --------- 29   
      19.08.2010 17:49     C:\Windows\cdplayer.ini --------- 3314   
      14.08.2010 12:46     C:\Windows\Irremote.ini --------- 4767   
      08.08.2010 16:47     C:\Windows\setup.iss --------- 1165   
      21.06.2010 12:08     C:\Windows\ativpsrm.bin --------- 0   
      04.05.2010 19:35     C:\Windows\atiogl.xml --------- 21360   
      13.04.2010 08:04     C:\Windows\difxapi.dll --------- 414632   
      02.02.2010 19:00     C:\Windows\avisplitter.ini --------- 38   
      14.07.2009 06:09     C:\Windows\win.ini --------- 403   
      14.07.2009 05:54     C:\Windows\WindowsShell.Manifest --------- 749   
      14.07.2009 02:39     C:\Windows\write.exe --------- 10240   
      14.07.2009 02:14     C:\Windows\regedit.exe --------- 398336   
      14.07.2009 02:39     C:\Windows\notepad.exe --------- 193536   
      14.07.2009 02:39     C:\Windows\HelpPane.exe --------- 733696   
      14.07.2009 02:39     C:\Windows\hh.exe --------- 16896   
      14.07.2009 02:39     C:\Windows\fveupdate.exe --------- 15360   
      14.07.2009 02:14     C:\Windows\winhlp32.exe --------- 9728   
      14.07.2009 02:14     C:\Windows\twunk_32.exe --------- 31232   
      14.07.2009 00:06     C:\Windows\mib.bin --------- 43131   
      10.06.2009 22:41     C:\Windows\twunk_16.exe --------- 49680   
      10.06.2009 22:41     C:\Windows\twain.dll --------- 94784   
      10.06.2009 22:08     C:\Windows\system.ini --------- 219   
      10.06.2009 21:52     C:\Windows\WMSysPr9.prx --------- 316640   
      10.06.2009 21:36     C:\Windows\msdfmap.ini --------- 1405   
      10.06.2009 21:31     C:\Windows\Starter.xml --------- 48201   
      10.06.2009 21:30     C:\Windows\HomePremium.xml --------- 48265   
    ----------------------------------------
    
     
    C:\Windows\System
    
     17.02.2009 13:19      C:\Windows\System\readme.txt --------- 2082 
     02.12.2007 12:28      C:\Windows\System\PhysXLoader.dll --------- 53248 
    ----------------------------------------
    
     
    C:\Windows\System32
    
     03.12.2011 07:30     C:\Windows\system32\drivers --------- 4096  
     21.11.2011 15:18     C:\Windows\system32\_TraceLog.txt --------- 363  
     02.11.2011 20:52     C:\Windows\system32\FlashPlayerCPLApp.cpl --------- 414368  
     24.10.2011 13:29     C:\Windows\system32\QuickTimeVR.qtx --------- 94208  
     24.10.2011 13:29     C:\Windows\system32\QuickTime.qts --------- 69632  
     20.10.2011 17:06     C:\Windows\system32\LxXtreme100.dll --------- 4771184  
     20.10.2011 17:06     C:\Windows\system32\LxUISettingsN100.dll --------- 104304  
     20.10.2011 17:06     C:\Windows\system32\LxTPSW100.dll --------- 25968  
     20.10.2011 17:06     C:\Windows\system32\LxTool100.dll --------- 1334128  
     20.10.2011 17:05     C:\Windows\system32\LxPXTree100.dll --------- 63344  
     20.10.2011 17:05     C:\Windows\system32\LxMail100.dll --------- 127344  
     20.10.2011 17:05     C:\Windows\system32\LxBasics100.dll --------- 193904  
     19.10.2011 18:14     C:\Windows\system32\FKStampPainter20.dll --------- 44032  
     14.10.2011 12:32     C:\Windows\system32\LXCurr100.dll --------- 49520  
     14.10.2011 12:32     C:\Windows\system32\LxCI12.dll --------- 67952  
     13.10.2011 11:21     C:\Windows\system32\migration --------- 4096  
     27.09.2011 11:17     C:\Windows\system32\LXReportManage.ocx --------- 133632  
     27.09.2011 11:17     C:\Windows\system32\LXPrnUtil10.dll --------- 198144  
     27.09.2011 11:16     C:\Windows\system32\LxDNT100.dll --------- 304128  
     27.09.2011 11:14     C:\Windows\system32\LxDNTvmc100.dll --------- 133120  
     27.09.2011 11:13     C:\Windows\system32\LxDNTvm100.dll --------- 69120  
     01.09.2011 03:36     C:\Windows\system32\mshtml.dll --------- 12275200  
     01.09.2011 03:35     C:\Windows\system32\jscript9.dll --------- 1798144  
     01.09.2011 03:33     C:\Windows\system32\ieframe.dll --------- 9704960  
     01.09.2011 03:28     C:\Windows\system32\urlmon.dll --------- 1102848  
     01.09.2011 03:28     C:\Windows\system32\wininet.dll --------- 1126912  
     01.09.2011 03:27     C:\Windows\system32\url.dll --------- 231936  
     01.09.2011 03:26     C:\Windows\system32\jsproxy.dll --------- 65024  
     01.09.2011 03:24     C:\Windows\system32\jscript.dll --------- 716800  
     01.09.2011 03:23     C:\Windows\system32\iertutil.dll --------- 1791488  
     01.09.2011 03:23     C:\Windows\system32\mshtmled.dll --------- 72704  
     01.09.2011 03:22     C:\Windows\system32\mshtml.tlb --------- 2382848  
     01.09.2011 03:21     C:\Windows\system32\ieui.dll --------- 176640  
     30.08.2011 22:05     C:\Windows\system32\jdns_sd.dll --------- 50536  
     30.08.2011 22:05     C:\Windows\system32\dnssdX.dll --------- 178536  
     30.08.2011 22:05     C:\Windows\system32\dns-sd.exe --------- 83816  
     30.08.2011 22:05     C:\Windows\system32\dnssd.dll --------- 73064  
     27.08.2011 05:26     C:\Windows\system32\oleaut32.dll --------- 571904  
     27.08.2011 05:26     C:\Windows\system32\oleacc.dll --------- 233472  
     24.08.2011 17:20     C:\Windows\system32\de-DE --------- 262144  
     17.08.2011 05:24     C:\Windows\system32\psisdecd.dll --------- 465408  
     17.08.2011 05:19     C:\Windows\system32\psisrndr.ax --------- 75776  
     16.07.2011 05:29     C:\Windows\system32\ntvdm64.dll --------- 14336  
     16.07.2011 05:25     C:\Windows\system32\setup16.exe --------- 25600  
     16.07.2011 05:24     C:\Windows\system32\wow32.dll --------- 5120  
     16.07.2011 05:24     C:\Windows\system32\KernelBase.dll --------- 272384  
     16.07.2011 05:24     C:\Windows\system32\kernel32.dll --------- 1114112  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll --------- 4096  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll --------- 4096  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll --------- 4608  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll --------- 3584  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll --------- 3584  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll --------- 4096  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll --------- 3584  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll --------- 4096  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll --------- 4096  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll --------- 3584  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll --------- 3584  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll --------- 3584  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll --------- 5120  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll --------- 3072  
     16.07.2011 05:15     C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll --------- 3072  
     16.07.2011 03:21     C:\Windows\system32\instnm.exe --------- 7680  
     16.07.2011 03:21     C:\Windows\system32\user.exe --------- 2048  
     16.07.2011 03:17     C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll --------- 3584  
     16.07.2011 03:17     C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll --------- 3072  
     16.07.2011 03:17     C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll --------- 4608  
     16.07.2011 03:17     C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll --------- 6144  
     09.07.2011 05:29     C:\Windows\system32\tzres.dll --------- 2048  
     30.06.2011 13:05     C:\Windows\system32\da-DK --------- 4096  
     30.06.2011 13:05     C:\Windows\system32\oobe --------- 0  
     30.06.2011 13:05     C:\Windows\system32\AdvancedInstallers --------- 0  
     30.06.2011 13:05     C:\Windows\system32\Setup --------- 4096  
     30.06.2011 13:05     C:\Windows\system32\cs-CZ --------- 4096  
     30.06.2011 13:05     C:\Windows\system32\manifeststore --------- 4096  
     30.06.2011 13:05     C:\Windows\system32\sppui --------- 0  
     30.06.2011 13:05     C:\Windows\system32\es-ES --------- 4096  
     30.06.2011 13:05     C:\Windows\system32\inetsrv --------- 8192  
     30.06.2011 13:05     C:\Windows\system32\wbem --------- 32768  
     30.06.2011 13:05     C:\Windows\system32\migwiz --------- 4096  
     30.06.2011 13:05     C:\Windows\system32\Dism --------- 4096  
     30.06.2011 12:49     C:\Windows\system32\msclmd.dll --------- 152576  
     23.06.2011 05:33     C:\Windows\system32\ntkrnlpa.exe --------- 3967872  
     23.06.2011 05:33     C:\Windows\system32\ntoskrnl.exe --------- 3912576  
     16.06.2011 05:33     C:\Windows\system32\xmllite.dll --------- 180224  
     15.06.2011 09:55     C:\Windows\system32\odbcjt32.dll --------- 319488  
     15.06.2011 09:55     C:\Windows\system32\odbctrac.dll --------- 163840  
     15.06.2011 09:55     C:\Windows\system32\odbccu32.dll --------- 86016  
     15.06.2011 09:55     C:\Windows\system32\odbccr32.dll --------- 81920  
     15.06.2011 09:55     C:\Windows\system32\odbccp32.dll --------- 122880  
     11.06.2011 00:58     C:\Windows\system32\msvcr100.dll --------- 773968  
    ----------------------------------------
    
     
    C:\Windows\Prefetch
    
     03.12.2011 00:53     C:\Windows\Prefetch\ReadyBoot --------- 4096  
     03.12.2011 00:52     C:\Windows\Prefetch\AgGlFgAppHistory.db --------- 2251789  
     03.12.2011 00:52     C:\Windows\Prefetch\AgGlFaultHistory.db --------- 560739  
     03.12.2011 00:52     C:\Windows\Prefetch\AgGlGlobalHistory.db --------- 4948177  
     03.12.2011 00:52     C:\Windows\Prefetch\AgRobust.db --------- 299656  
     03.12.2011 00:52     C:\Windows\Prefetch\PfSvPerfStats.bin --------- 584  
     03.12.2011 00:52     C:\Windows\Prefetch\AgCx_SC3_E4C39F7CC2B52157.db --------- 429559  
     03.12.2011 00:52     C:\Windows\Prefetch\TUNEUPUTILITIESAPP64.EXE-EDBD8849.pf --------- 11594  
     03.12.2011 00:52     C:\Windows\Prefetch\DLLHOST.EXE-71214090.pf --------- 173150  
     03.12.2011 00:52     C:\Windows\Prefetch\LOGONUI.EXE-1BEE4A84.pf --------- 52704  
     03.12.2011 00:51     C:\Windows\Prefetch\TASKMGR.EXE-72398DC0.pf --------- 30508  
     03.12.2011 00:51     C:\Windows\Prefetch\ATBROKER.EXE-FF58B71D.pf --------- 8536  
     03.12.2011 00:51     C:\Windows\Prefetch\ATIECLXX.EXE-19F63085.pf --------- 16018  
     03.12.2011 00:51     C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf --------- 36660  
     03.12.2011 00:51     C:\Windows\Prefetch\CSRSS.EXE-8C04D631.pf --------- 19050  
     03.12.2011 00:51     C:\Windows\Prefetch\READER_SL.EXE-F021BC49.pf --------- 30772  
     03.12.2011 00:51     C:\Windows\Prefetch\SMSS.EXE-1DCD0EB1.pf --------- 5500  
     03.12.2011 00:51     C:\Windows\Prefetch\AgCx_S1_S-1-5-21-842238141-2409979310-1428428874-1000.snp.db --------- 2438636  
     03.12.2011 00:51     C:\Windows\Prefetch\CSC.EXE-4EF173D0.pf --------- 42178  
     03.12.2011 00:51     C:\Windows\Prefetch\CONHOST.EXE-3218E401.pf --------- 15538  
     03.12.2011 00:51     C:\Windows\Prefetch\WMPNSCFG.EXE-DF1DD51A.pf --------- 35908  
     03.12.2011 00:51     C:\Windows\Prefetch\CVTRES.EXE-419E4E46.pf --------- 15898  
     03.12.2011 00:51     C:\Windows\Prefetch\RUNDLL32.EXE-AFD98684.pf --------- 29722  
     03.12.2011 00:18     C:\Windows\Prefetch\WMIPRVSE.EXE-43972D0F.pf --------- 48952  
     03.12.2011 00:17     C:\Windows\Prefetch\SPPSVC.EXE-CBE91656.pf --------- 12080  
     03.12.2011 00:17     C:\Windows\Prefetch\MBAMSERVICE.EXE-61E9265F.pf --------- 50860  
     03.12.2011 00:17     C:\Windows\Prefetch\AVWSC.EXE-3F986FB6.pf --------- 38568  
     03.12.2011 00:17     C:\Windows\Prefetch\GOOGLEUPDATE.EXE-648FB068.pf --------- 38976  
     03.12.2011 00:17     C:\Windows\Prefetch\GOOGLECRASHHANDLER.EXE-0B9BB945.pf --------- 23846  
     03.12.2011 00:17     C:\Windows\Prefetch\MSCORSVW.EXE-98F0699A.pf --------- 21516  
     03.12.2011 00:17     C:\Windows\Prefetch\MSCORSVW.EXE-FAA88858.pf --------- 18108  
     03.12.2011 00:16     C:\Windows\Prefetch\SVCHOST.EXE-F03E4D6B.pf --------- 214494  
     03.12.2011 00:14     C:\Windows\Prefetch\SVCHOST.EXE-93CEEE07.pf --------- 8594  
     03.12.2011 00:13     C:\Windows\Prefetch\TASKHOST.EXE-437C05A8.pf --------- 122316  
     03.12.2011 00:08     C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-842238141-2409979310-1428428874-1000.db --------- 788992  
     03.12.2011 00:08     C:\Windows\Prefetch\AgGlUAD_S-1-5-21-842238141-2409979310-1428428874-1000.db --------- 2112857  
     02.12.2011 23:59     C:\Windows\Prefetch\SVCHOST.EXE-8FD92526.pf --------- 17478  
     02.12.2011 23:59     C:\Windows\Prefetch\VSSVC.EXE-04D079CC.pf --------- 26520  
     02.12.2011 23:59     C:\Windows\Prefetch\LPREMOVE.EXE-F992050D.pf --------- 2388  
     02.12.2011 23:52     C:\Windows\Prefetch\RUNDLL32.EXE-125D4518.pf --------- 271496  
     02.12.2011 23:49     C:\Windows\Prefetch\Layout.ini --------- 1164118  
     02.12.2011 23:36     C:\Windows\Prefetch\ONECLICKSTARTER.EXE-668CF5BA.pf --------- 100450  
     02.12.2011 23:36     C:\Windows\Prefetch\SVCHOST.EXE-F59CA9BD.pf --------- 17506  
     02.12.2011 23:35     C:\Windows\Prefetch\WMIADAP.EXE-369DF1CD.pf --------- 25912  
     02.12.2011 19:58     C:\Windows\Prefetch\FIREFOX.EXE-FBBD985A.pf --------- 236362  
     02.12.2011 19:57     C:\Windows\Prefetch\CTFMON.EXE-79423C0A.pf --------- 23158  
     02.12.2011 19:57     C:\Windows\Prefetch\AUDIODG.EXE-D0D776AC.pf --------- 28448  
     02.12.2011 19:57     C:\Windows\Prefetch\EXTRAC32.EXE-F25A1F4B.pf --------- 23846  
     02.12.2011 19:56     C:\Windows\Prefetch\SVCHOST.EXE-7A08330A.pf --------- 23022  
     02.12.2011 19:56     C:\Windows\Prefetch\PLUGIN-CONTAINER.EXE-78000DE6.pf --------- 517938  
     02.12.2011 19:56     C:\Windows\Prefetch\JAVA.EXE-E3C0BFD0.pf --------- 119108  
     02.12.2011 19:56     C:\Windows\Prefetch\JP2LAUNCHER.EXE-B55ED0F4.pf --------- 19318  
     02.12.2011 19:56     C:\Windows\Prefetch\NETSH.EXE-19B647C9.pf --------- 55538  
     02.12.2011 19:56     C:\Windows\Prefetch\0.749043411130123DF35.EXE-0091D18B.pf --------- 18718  
     02.12.2011 19:43     C:\Windows\Prefetch\SCRNSAVE.SCR-225A7D32.pf --------- 8586  
     02.12.2011 19:42     C:\Windows\Prefetch\WMIPRVSE.EXE-94D7CB13.pf --------- 31688  
     02.12.2011 19:41     C:\Windows\Prefetch\TUNEUPSYSTEMSTATUSCHECK.EXE-53D191D1.pf --------- 220640  
     02.12.2011 19:38     C:\Windows\Prefetch\TURATINGSYNCH.EXE-F4A529A8.pf --------- 206530  
     02.12.2011 19:38     C:\Windows\Prefetch\SDCLT.EXE-2D2C4DDD.pf --------- 18688  
     02.12.2011 19:34     C:\Windows\Prefetch\WMPNETWK.EXE-BD0344CA.pf --------- 29992  
     02.12.2011 19:34     C:\Windows\Prefetch\SVCHOST.EXE-DB4C36D7.pf --------- 41542  
     02.12.2011 17:49     C:\Windows\Prefetch\XNVIEW.EXE-0F07D516.pf --------- 154170  
     02.12.2011 17:37     C:\Windows\Prefetch\IELOWUTIL.EXE-31ED7BBC.pf --------- 5424  
     02.12.2011 12:35     C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-031B6478.pf --------- 287334  
     02.12.2011 12:32     C:\Windows\Prefetch\SVCHOST.EXE-135A30D8.pf --------- 30284  
     02.12.2011 09:37     C:\Windows\Prefetch\CCC.EXE-000FEDE2.pf --------- 328992  
     01.12.2011 16:30     C:\Windows\Prefetch\RAREXTLOADER.EXE-4B76CB3C.pf --------- 16018  
     01.12.2011 16:20     C:\Windows\Prefetch\TASKENG.EXE-5BAF290C.pf --------- 67392  
     01.12.2011 14:32     C:\Windows\Prefetch\RUNDLL32.EXE-F452D79D.pf --------- 10550  
     01.12.2011 14:20     C:\Windows\Prefetch\MSFEEDSSYNC.EXE-1F01ED17.pf --------- 2194  
     01.12.2011 13:08     C:\Windows\Prefetch\WMPLAYER.EXE-61D40ED1.pf --------- 171574  
     28.11.2011 10:15     C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf --------- 2095258  
     27.11.2011 13:37     C:\Windows\Prefetch\DISTNOTED.EXE-7270553F.pf --------- 22290  
     26.11.2011 09:21     C:\Windows\Prefetch\AgCx_SC1.db --------- 687623  
     26.11.2011 09:20     C:\Windows\Prefetch\AgCx_SC1.db.trx --------- 34592  
     30.06.2011 13:11     C:\Windows\Prefetch\AgCx_SC4.db --------- 336184  
     19.11.2010 11:06     C:\Windows\Prefetch\AgAppLaunch.db --------- 334168  
    ----------------------------------------
    
     
    C:\Windows\Tasks
    
     03.12.2011 00:54     C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job --------- 1104  
     03.12.2011 00:54     C:\Windows\Tasks\SA.DAT --------- 6  
     01.12.2011 16:20     C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job --------- 1108  
     21.11.2011 09:04     C:\Windows\Tasks\SCHEDLGU.TXT --------- 32640  
    ----------------------------------------
    
     
    C:\Windows\Temp
    
     03.12.2011 01:09     C:\Windows\Temp\AVSETUP_4ed96891 --------- 0  
     21.11.2011 16:48     C:\Windows\Temp\._msige61 --------- 24576  
    ----------------------------------------
    
     
    C:\Users\Peter\AppData\Local\Temp
    
     03.12.2011 14:27     C:\Users\Peter\AppData\Local\Temp\Rar$DI67.842 --------- 0  
     03.12.2011 14:21     C:\Users\Peter\AppData\Local\Temp\samples.sar --------- 8  
     03.12.2011 14:21     C:\Users\Peter\AppData\Local\Temp\sarscan.log --------- 286  
     03.12.2011 14:16     C:\Users\Peter\AppData\Local\Temp\hjtscanlist.zip --------- 2097  
     03.12.2011 14:10     C:\Users\Peter\AppData\Local\Temp\_iu14D2N.tmp --------- 697876  
     03.12.2011 13:00     C:\Users\Peter\AppData\Local\Temp\decleaner --------- 4096  
     03.12.2011 13:00     C:\Users\Peter\AppData\Local\Temp\aqnwnWxd.exe.part --------- 883840  
     03.12.2011 01:16     C:\Users\Peter\AppData\Local\Temp\~DF152686F7B647A29A.TMP --------- 16384  
     03.12.2011 01:09     C:\Users\Peter\AppData\Local\Temp\APNLogs --------- 0  
     03.12.2011 01:08     C:\Users\Peter\AppData\Local\Temp\APN-Stub --------- 0  
     03.12.2011 01:08     C:\Users\Peter\AppData\Local\Temp\AppRemover_Log.txt --------- 4330  
     03.12.2011 01:08     C:\Users\Peter\AppData\Local\Temp\WPDNSE --------- 0  
     03.12.2011 00:58     C:\Users\Peter\AppData\Local\Temp\~DFD50D2666978B3A64.TMP --------- 147456  
     03.12.2011 00:58     C:\Users\Peter\AppData\Local\Temp\~DFBC9183A46A750433.TMP --------- 147456  
     03.12.2011 00:56     C:\Users\Peter\AppData\Local\Temp\~DF75FE2A452BADE98C.TMP --------- 147456  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\e0964twi.out --------- 499  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\e0964twi.err --------- 0  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\e0964twi.dll --------- 0  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\e0964twi.tmp --------- 0  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\e0964twi.cmdline --------- 416  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\e0964twi.0.cs --------- 11186  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\tmp286.tmp2 --------- 0  
     03.12.2011 00:55     C:\Users\Peter\AppData\Local\Temp\tmp286.tmp1 --------- 0  
     03.12.2011 00:54     C:\Users\Peter\AppData\Local\Temp\AdobeARM.log --------- 127645  
     03.12.2011 00:54     C:\Users\Peter\AppData\Local\Temp\{AF82B87C9F73BFD328A8} --------- 1190  
     03.12.2011 00:26     C:\Users\Peter\AppData\Local\Temp\~DF4F8C8221EDFA967D.TMP --------- 147456  
     02.12.2011 19:58     C:\Users\Peter\AppData\Local\Temp\hsperfdata_Peter --------- 0  
     02.12.2011 19:56     C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe --------- 52224  
     01.12.2011 13:08     C:\Users\Peter\AppData\Local\Temp\wmplog01.sqm --------- 1416  
     30.11.2011 20:53     C:\Users\Peter\AppData\Local\Temp\Excel8.0 --------- 0  
     29.11.2011 21:14     C:\Users\Peter\AppData\Local\Temp\AdobeARM_NotLocked.log --------- 807  
     29.11.2011 18:03     C:\Users\Peter\AppData\Local\Temp\RapidSolution --------- 4096  
     29.11.2011 18:03     C:\Users\Peter\AppData\Local\Temp\trk6C59.tmp --------- 0  
     29.11.2011 17:47     C:\Users\Peter\AppData\Local\Temp\StarMoney 8.0 --------- 0  
     28.11.2011 21:05     C:\Users\Peter\AppData\Local\Temp\wmplog00.sqm --------- 1544  
     28.11.2011 21:00     C:\Users\Peter\AppData\Local\Temp\plugtmp --------- 0  
     28.11.2011 20:57     C:\Users\Peter\AppData\Local\Temp\Adobe --------- 0  
     27.11.2011 20:37     C:\Users\Peter\AppData\Local\Temp\Easy Photo Print2EPQuicker.log --------- 320  
     27.11.2011 18:05     C:\Users\Peter\AppData\Local\Temp\VBE --------- 0  
     27.11.2011 16:45     C:\Users\Peter\AppData\Local\Temp\comtypes_cache --------- 0  
     27.11.2011 11:59     C:\Users\Peter\AppData\Local\Temp\E060.dir --------- 0  
     27.11.2011 11:59     C:\Users\Peter\AppData\Local\Temp\PDFCreator --------- 0  
     27.11.2011 11:59     C:\Users\Peter\AppData\Local\Temp\{e9513610-f218-4dda-b954-2c7e6ba7cabb} --------- 0  
     24.11.2011 15:40     C:\Users\Peter\AppData\Local\Temp\winsh324 --------- 481078  
     24.11.2011 01:08     C:\Users\Peter\AppData\Local\Temp\winsh320 --------- 481078  
     24.11.2011 01:08     C:\Users\Peter\AppData\Local\Temp\winsh321 --------- 481078  
     24.11.2011 01:08     C:\Users\Peter\AppData\Local\Temp\winsh323 --------- 481078  
     24.11.2011 01:08     C:\Users\Peter\AppData\Local\Temp\winsh322 --------- 481078  
     23.11.2011 14:52     C:\Users\Peter\AppData\Local\Temp\SetupAdminC74.log --------- 86  
     21.11.2011 16:18     C:\Users\Peter\AppData\Local\Temp\hr_temp --------- 0  
     18.11.2011 17:04     C:\Users\Peter\AppData\Local\Temp\msohtmlclip1 --------- 0  
          C:\Users\Peter\AppData\Local\Temp\2011-11-07-1200337309_04-RG.PDF  ---------   
          C:\Users\Peter\AppData\Local\Temp\2011-10-07-1189921280_04-RG.PDF  ---------   
     12.05.2011 14:05     C:\Users\Peter\AppData\Local\Temp\bblvtg.exe --------- 61440  
     31.10.2010 20:26     C:\Users\Peter\AppData\Local\Temp\FXSAPIDebugLogFile.txt --------- 0  
    ----------------------------------------
    
     
    C:\Program Files (x86)
    
     23.11.2011 14:54     C:\Program Files (x86)\iTunes --------- 4096  
          C:\Program Files (x86)\iPod ---------   
     28.10.2011 22:18     C:\Program Files (x86)\Bonjour --------- 4096  
     13.10.2011 11:21     C:\Program Files (x86)\Internet Explorer --------- 4096  
     21.11.2011 15:35     C:\Program Files (x86)\Common Files --------- 8192  
     30.03.2011 19:50     C:\Program Files (x86)\NVIDIA Corporation --------- 0  
     30.06.2011 13:05     C:\Program Files (x86)\Windows Mail --------- 4096  
     30.06.2011 13:05     C:\Program Files (x86)\Windows Sidebar --------- 4096  
          C:\Program Files (x86)\DVD Maker ---------   
     30.06.2011 13:05     C:\Program Files (x86)\Windows Portable Devices --------- 0  
     30.06.2011 13:05     C:\Program Files (x86)\Windows Media Player --------- 4096  
     30.06.2011 13:05     C:\Program Files (x86)\Windows Photo Viewer --------- 4096  
          C:\Program Files (x86)\Windows Journal ---------   
     14.07.2009 18:58     C:\Program Files (x86)\Windows Defender --------- 4096  
     04.09.2010 14:03     C:\Program Files (x86)\DivX --------- 4096  
          C:\Program Files (x86)\FRITZDSL ---------   
          C:\Program Files (x86)\DIFX ---------   
     15.10.2010 16:23     C:\Program Files (x86)\Java --------- 0  
     30.06.2011 12:51     C:\Program Files (x86)\Microsoft Office --------- 4096  
     24.07.2010 19:51     C:\Program Files (x86)\Epson Software --------- 0  
     21.06.2010 12:05     C:\Program Files (x86)\ATI Technologies --------- 0  
     21.06.2010 12:05     C:\Program Files (x86)\ATI --------- 0  
     14.07.2009 06:32     C:\Program Files (x86)\Windows NT --------- 4096  
          C:\Program Files (x86)\Gemeinsame Dateien ---------   
          C:\Program Files (x86)\Realtek ---------   
     31.10.2010 20:30     C:\Program Files (x86)\Microsoft Games --------- 0  
     14.07.2009 06:32     C:\Program Files (x86)\Reference Assemblies --------- 0  
     14.07.2009 06:32     C:\Program Files (x86)\MSBuild --------- 0  
     14.07.2009 05:57     C:\Program Files (x86)\Uninstall Information --------- 0  
     14.07.2009 05:54     C:\Program Files (x86)\desktop.ini --------- 174  
    ----------------------------------------
    
     
    C:\ProgramData\.. 
    
    Peter    
    DefaultAppPool    
    Peter.V2    
    AppData    
    Default    
    Public    
    All Users    
    Default User    
    desktop.ini    
    ----------------------------------------
    
     
    C:\Windows\system32\drivers\etc\hosts
    
    
    ----------------------------------------
    
     
    
    Abbildname                     PID Sitzungsname       Sitz.-Nr. Speichernutzung
    ========================= ======== ================ =========== ===============
    System Idle Process              0 Services                   0            24 K
    System                           4 Services                   0         6.952 K
    smss.exe                       372 Services                   0         1.296 K
    csrss.exe                      456 Services                   0         4.100 K
    wininit.exe                    484 Services                   0         4.852 K
    csrss.exe                      508 Console                    1        13.308 K
    services.exe                   544 Services                   0         7.784 K
    lsass.exe                      560 Services                   0        11.792 K
    lsm.exe                        568 Services                   0         4.560 K
    winlogon.exe                   628 Console                    1         6.208 K
    svchost.exe                    716 Services                   0         9.608 K
    svchost.exe                    792 Services                   0         7.240 K
    svchost.exe                    920 Services                   0        12.680 K
    svchost.exe                    952 Services                   0        16.692 K
    svchost.exe                   1008 Services                   0        10.504 K
    svchost.exe                    360 Services                   0         7.504 K
    svchost.exe                    432 Services                   0        16.096 K
    svchost.exe                    732 Services                   0        12.988 K
    explorer.exe                  1344 Console                    1        84.240 K
    ctfmon.exe                    1408 Console                    1         4.668 K
    avgnt.exe                     1340 Console                    1         4.148 K
    LogonUI.exe                   1620 Console                    1        18.272 K
    firefox.exe                   1312 Console                    1       160.668 K
    setup_9.0.0.722_27.11.201     1540 Console                    1       207.916 K
    plugin-container.exe           896 Console                    1        29.160 K
    WinRAR.exe                     684 Console                    1        14.720 K
    sargui.exe                    1236 Console                    1        11.200 K
    bblvtg.exe                     660 Console                    1         3.632 K
    cmd.exe                       1808 Console                    1         4.364 K
    conhost.exe                   1108 Console                    1         4.224 K
    tasklist.exe                  1432 Console                    1         5.592 K
    WmiPrvSE.exe                  1260 Services                   0         6.636 K
    
     
    ***** Ende des Scans 03.12.2011 um 14:28:05,02 ***
    [CODE]

  2. #2
    Moderator Team-Mitglied Avatar von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    28.352

    AW: Bundespolizei Trojaner seit gestern

    Herzlich Willkommen hier bei uns am HijackThis Supportboard!

    **Bevor du mit Teil 1. der Aufgabe beginnst: HIER KLICKEN UND SORGFÄLTIG DURCHLESEN!** und ich bitte um kurze Bestätigung, dass du dies gelesen und akzeptiert hast!
    Ein System zu bereinigen kann ein paar Tage dauern (je nach Art der Infektion), kann aber sogar so stark kompromittiert sein, so dass eine wirkungsvolle technische Säuberung ist nicht mehr möglich bzw Du es neu installieren musst
    ► Unrechtmäßig erworbene Software (durch Keygen, Crack, Keymaker) wird hier nicht geduldet, in diesem Fall wird der Support eingestellt.!
    ANWEISUNGEN UND DEREN BEFOLGUNG, ERFOLGT AUF DEINE EIGENE VERANTWORTUNG!
    Bitte lese Dir zuerst in Ruhe die Anweisungen durch und Du sollst dabei die Reihenfolge einhalten! Ansonsten verlangsamt unsere Arbeit, wenn wir immer wieder noch an Kleinigkeiten nachschlagen müssen und dadurch eventuell die Übersicht verloren geht...

    **Vista und Win7 Verwender: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen

    1.
    ► Ein Versuch ist es Wert:
    Gibt es einen "relativ einfachen Weg",wenn eine frische Infektion vorliegt, oder mal bestimmte Probleme bekommt man auch gelöst, was man sogleich ausprobieren sollte. Dies bietet Dir die Möglichkeit, Systemänderungen am Computer ohne Auswirkung auf persönliche Dateien, wie z. B. E-Mails, Dokumente oder Fotos, rückgängig zu machen.
    -> Systemwiederherstellung
    ► Bitte wähle das älteste verfügbare Datum für die Wiederherstellung von Windows aus, wo dein Rechner noch einwandfrei funktioniert hat!
    • Du musst dich als Administrator oder als Benutzer mit Administratorrechten anmelden.
    • Die Systemwiederherstellung lässt sich unter Windows Vista/XP/7 wie folgt aufrufen:
    • StartAlle ProgrammeZubehörSystemprogrammeSystemwiederherstellung

    ->Eine Schritt-für-Schritt-Anleitung zum Einsatz der Systemwiederherstellung unter Windows XP
    ->Systemwiederherstellung unter Windows Vista
    ->Unter Win 7
    Die Systemwiederherstellung ist nur ein "Notlösung", das Problem wird damit nie 100%ig beseitigt, da dem Zeitpunkt des Eindringen des Trojaners nicht mehr feststellen kann. Aber man kann damit die Funktionsfähigkeit eines Computersystems erhöhen.
    (Kannst noch immer bis zum heutigen Zeitpunkt rückgängig machen, falls liefert nicht das gewünschte Ergebnis)
    Falls nötig, kannst Du es im abgesicherten Modus auch tun - (Link bitte unbedingt anklicken & lesen!)
    berichte mir auch, ob die SWH funktioniert hat, bzw ob Du das System auf einen früheren Wiederherstellungspunkt zurückstellen können?

    2.
    Sollte die Systemwiederherstellung nicht funktionieren (Malware kann es verhindern):
    - Du kannst auch noch die folgenden Methoden ausprobieren, um das Problem zu beheben.:-> Verwenden der letzten als funktionierend bekannten Konfiguration
    3.
    Das Program installieren und ausführen:
    Anleitung:-> Bereinigung mit Malwarebytes' Anti-Malware (Vollständiger Suchlauf)

    4.
    Systemscan mit OTL

    Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop.
    • Doppelklick auf die OTL.exe
    • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
    • Oben findest Du ein Kästchen mit Ausgabe.
      Wähle bitte Standard-Ausgabe
    • Unter Extra-Registrierung wähle bitte Benutze SafeList.
    • Mache Häckchen bei LOP- und Purity-Prüfung.
    • Klicke nun auf Scan links oben.


    • Wenn der Scan beendet wurde werden zwei Logfiles erstellt.
      Du findest die Logfiles auf Deinem Desktop => OTL.txt und Extras.txt
    • Poste die Logfiles in Code-Tags hier in den Thread.


    5.
    • Download den CCleaner
    • Software-Lizenzvereinbarung lesen, falls angeboten wird ("Füge CCleaner Yahoo! Toolbar hinzu" - abwählen!)-> starten -> Falls nötig, unter Options settings -> "german" einstellen.
    • starten-> klick auf `Extras` (um auf deinem System installierte Software zu anzeigen)-> dann auf `Als Textdatei speichern...`
    • ein Textdatei wird automatisch erstellt, poste auch dieses Logfile (also die Liste alle installierten Programme...eine Textdatei)


    Bitte alle Ergebnisse im Code-Tags posten!

    vor dein Log schreibst Du (also am Anfang des Logfiles):[code]
    hier kommt dein Logfile rein
    dahinter - also am Ende der Logdatei:[/code]
    gruß
    kira
    Warnung!:
    Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
    Anhang nicht öffnen, in unserem Forum erst nachfragen!

    Bitte diese Warnung weitergeben, wo Du nur kannst!
    Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
    Bitte diese Warnung weitergeben, wo Du nur kannst!

  3. #3
    Forenbenutzer
    Registriert seit
    22.08.2009
    Beiträge
    58

    AW: Bundespolizei Trojaner seit gestern

    Hallo

    Ich hab inzwischen wohl den Übeltäter gefundne,. In einem TEMP-Ordner unter "App Data" waren viel Dateien und u.a. auch das Bild was man von dem Trojyaner sieht (Eingabemasket etc)
    ich hab dann den ganzen TEMP-Ordner geleert und danach kam der Trojaner nicht mehr,

    ich wollte dann zur Sicherheit noch die Systemwiederherstellung machen (Habe eine vom 28.11.) daber das funktioniert nicht da die Fehlermeldung kommt das die Sys.-Wiederherstellung bloekcert ist (habe auch den ACVAntivir deaktiviert, gheht dennoch nicht).

    Das komische ist daß wenn ich dann Wiederherstellung rückgängig machen anklicke der PC dies auch macht und dann eine Erfolgreiche Rücknahme vermeledet..SIt doch unlogisch oder ? Er hat ja angeblich bei der ersten Wiederherstllung nichts ändern können...

    Anbe inoch die Logs:
    Code:
    7-Zip 4.65		20.07.2010		
    A380v2 (FSX)		05.11.2010		
    AC3Filter 1.63b	Alexander Vigovsky	31.10.2010		1.63b
    Acronis*True*Image*Home	Acronis	21.07.2010	122,3MB	12.0.9608
    ActiveTrader 5.0.0_b15		17.01.2011		
    Adobe AIR	Adobe Systems Incorporated	24.09.2011		2.7.1.19610
    Adobe Flash Player 10 ActiveX	Adobe Systems Incorporated	19.11.2010	2,68MB	10.1.82.76
    Adobe Flash Player 11 Plugin 64-bit	Adobe Systems Incorporated	01.11.2011	6,00MB	11.0.1.152
    Adobe Reader X (10.1.1) - Deutsch	Adobe Systems Incorporated	15.09.2011	119,0MB	10.1.1
    Airline Tycoon 2 Demo v1.01	Kalypso Media	27.10.2011	3.158MB	
    AnyDVD	SlySoft	11.10.2011		6.8.5.0
    Apple Application Support	Apple Inc.	27.10.2011	61,2MB	2.1.5
    Apple Mobile Device Support	Apple Inc.	22.11.2011	24,4MB	4.0.0.97
    Apple Software Update	Apple Inc.	09.10.2011	2,38MB	2.1.3.127
    ATI Catalyst Install Manager	ATI Technologies, Inc.	20.06.2010	22,3MB	3.0.778.0
    AudialsOne	RapidSolution Software AG	08.01.2011	356MB	4.2.13700.0
    Audiograbber 1.83 SE	Audiograbber Deutschland	19.08.2010		1.83 SE 
    Aura DVD Ripper Professional 1.3.8	aura4you.com	27.10.2011	100,5MB	
    Aura Software Manager 1.0.3	aura4you.com	27.10.2011	7,87MB	
    Avira Free Antivirus	Avira	02.12.2011	105,9MB	12.0.0.861
    AVM FRITZ!Box Dokumentation	AVM Berlin	12.08.2010		
    Biet-O-Matic v2.14.6	BOM Development Team	10.08.2010		Biet-O-Matic v2.14.6
    Bonjour	Apple Inc.	27.10.2011	2,04MB	3.0.0.10
    Camera RAW Plug-In for EPSON Creativity Suite	SEIKO EPSON CORPORATION	23.07.2010		2.2.0.0
    Canon G.726 WMP-Decoder	Canon Inc.	27.08.2011		1.1.0.4
    CANON iMAGE GATEWAY MyCamera Download Plugin	Canon Inc.	27.08.2011		3.1.1.2
    CANON iMAGE GATEWAY Task for ZoomBrowser EX	Canon Inc.	27.08.2011		1.9.0.9
    Canon Internet Library for ZoomBrowser EX	Canon Inc.	27.08.2011		1.6.2.7
    Canon MOV Decoder	Canon Inc.	27.08.2011		1.8.0.7
    Canon MOV Encoder	Canon Inc.	27.08.2011		1.7.0.3
    Canon MovieEdit Task for ZoomBrowser EX	Canon Inc.	27.08.2011		3.8.0.5
    Canon RAW Image Task for ZoomBrowser EX	Canon Inc.	27.08.2011		0.9.3.9
    Canon Utilities CameraWindow	Canon Inc.	27.08.2011		7.1.0.2
    Canon Utilities CameraWindow DC	Canon Inc.	27.08.2011		7.1.0.7
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX	Canon Inc.	27.08.2011		6.4.2.16
    Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX	Canon Inc.	27.08.2011		1.0.0.10
    Canon Utilities MyCamera	Canon Inc.	27.08.2011		6.4.0.5
    Canon Utilities MyCamera DC	Canon Inc.	27.08.2011		7.0.1.8
    Canon Utilities PhotoStitch	Canon Inc.	27.08.2011		3.1.21.45
    Canon Utilities RemoteCapture DC	Canon Inc.	27.08.2011		3.0.1.8
    Canon Utilities RemoteCapture Task for ZoomBrowser EX	Canon Inc.	27.08.2011		1.7.1.9
    Canon Utilities ZoomBrowser EX	Canon Inc.	27.08.2011		6.7.2.33
    Canon ZoomBrowser EX Memory Card Utility	Canon Inc.	27.08.2011		1.5.1.10
    CCleaner	Piriform	03.12.2011		3.13
    CD Audio Reader Filter (remove only)		31.10.2010		
    ClearProg 1.6.0 Final	Sven Hoffman	18.11.2010		1.6.0 Final
    CloneCD	SlySoft	26.08.2010		
    CloneDVD2	Elaborate Bytes	26.08.2010		
    Crysis® 2	Electronic Arts	17.06.2011	7.757MB	1.0.0.0
    DCoder Image Source (remove only)		31.10.2010		
    DivX-Setup	DivX, Inc. 	03.09.2010		2.0.4.2
    Dropbox	Dropbox, Inc.	20.07.2011		1.1.35
    DScaler 5 Mpeg Decoders		31.10.2010		
    ElsterFormular	Landesfinanzdirektion Thüringen	03.10.2011	140.139MB	12.4.0.7094k
    Emergency 3		15.08.2011		1.00.000
    Emergency4		24.06.2011		1.03.001
    EPSON Attach To Email	SEIKO EPSON	23.07.2010	1,08MB	1.01.0000
    EPSON Copy Utility 3		23.07.2010		3.3.0.0
    Epson Easy Photo Print 2	SEIKO EPSON CORPORATION	23.07.2010		2.2.0.0
    Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)	SEIKO EPSON CORPORATION	23.07.2010		1.00.0000
    EPSON File Manager		23.07.2010		1.3.0.0
    EPSON Print CD		23.07.2010		1.60.000
    EPSON Scan		23.07.2010		
    EPSON Scan Assistant		23.07.2010		1.10.00
    EPSON-Drucker-Software	SEIKO EPSON Corporation	23.07.2010		
    EPU-4 Engine		20.07.2010		1.01.02
    Eudora		31.07.2010		7.0
    EudoraProject.de		20.06.2010		
    Falk Navi-Manager	Falk Navigation GmbH	09.06.2011		2.6.2
    FFMPEG Core Files (remove only)		31.10.2010		
    FIFA Fussball-Weltmeisterschaft 2006 (TM)		24.07.2010		
    FormatFactory 2.60	Free Time	12.02.2011		2.60
    Foxit Reader	Foxit Corporation	16.07.2011	11,2MB	4.3.1.118
    Free Download Manager 3.0	FreeDownloadManager.ORG	11.06.2011		
    Free Studio version 5.2.0	DVDVideoSoft Ltd.	09.09.2011	333MB	
    Free Video Dub version 1.8	DVDVideoSoft Limited.	07.09.2010	22,8MB	
    Freez FLV to AVI/MPEG/WMV Converter	www.smallvideosoft.com	13.08.2010		1.6
    GameCenter		24.07.2010		
    GetFoldersize 2.3.2	Michael Thummerer Software Design	30.10.2010	6,54MB	2.3.2
    Google Earth	Google	16.11.2011	92,7MB	6.1.0.5001
    Haufe iDesk-Browser	Haufe-Lexware GmbH & Co. KG	19.11.2010	26,7MB	10.10.14.0000
    Haufe iDesk-Service	Haufe	20.11.2011	137,3MB	11.07.19.8023
    HijackThis 2.0.2	TrendMicro	14.10.2010		2.0.2
    HTC BMP USB Driver	HTC	20.02.2011	0,28MB	1.0.5375
    HTC Driver Installer	HTC Corporation	24.09.2011	1,90MB	3.0.0.013
    HTC Sync	HTC Corporation	24.09.2011	44,4MB	3.0.5579
    iCloud	Apple Inc.	12.11.2011	32,4MB	1.0.1.29
    IrfanView (remove only)	Irfan Skiljan	24.07.2010	1,50MB	4.27
    iTunes	Apple Inc.	22.11.2011	170,5MB	10.5.1.42
    Java(TM) 6 Update 21 (64-bit)	Oracle	24.07.2010	90,5MB	6.0.210
    Java(TM) 6 Update 22	Oracle	17.08.2010	94,9MB	6.0.220
    K-Lite Codec Pack 5.7.0 (Full)		20.06.2010	47,9MB	5.7.0
    Lexware buchhalter 2012	Haufe-Lexware GmbH & Co.KG	20.11.2011	323MB	17.00.00.0109
    Lexware Datenbank plus 2011	Haufe-Lexware GmbH & Co.KG	20.11.2011	243MB	11.00.00.0074
    Lexware Elster	Haufe-Lexware GmbH & Co.KG	20.11.2011	76,8MB	11.00.00.0109
    Lexware Info Service	Haufe-Lexware GmbH & Co.KG	20.11.2011	15,8MB	2.80.00.0007
    Lexware online banking	Haufe-Lexware GmbH & Co.KG	20.11.2011	25,2MB	11.00.00.0039
    Lexware reisekosten plus 2011	Haufe-Lexware GmbH & Co.KG	20.11.2011	427MB	11.22.00.0124
    Malwarebytes' Anti-Malware Version 1.51.2.1300	Malwarebytes Corporation	02.12.2011	13,8MB	1.51.2.1300
    Microsoft .NET Framework 4 Client Profile	Microsoft Corporation	20.07.2010	38,8MB	4.0.30319
    Microsoft .NET Framework 4 Client Profile DEU Language Pack	Microsoft Corporation	20.07.2010	2,94MB	4.0.30319
    Microsoft Flight Simulator X: Acceleration	Microsoft Game Studios	26.01.2011		10.0.61637.0
    Microsoft Games for Windows - LIVE Redistributable	Microsoft Corporation	05.05.2011	31,3MB	3.5.88.0
    Microsoft Games for Windows Marketplace	Microsoft Corporation	05.05.2011	6,04MB	3.5.50.0
    Microsoft Office File Validation Add-In	Microsoft Corporation	14.09.2011	7,95MB	14.0.5130.5003
    Microsoft Office Home and Student 2007	Microsoft Corporation	24.07.2010		12.0.6425.1000
    Microsoft Office Word Viewer 2003	Microsoft Corporation	14.09.2011	63,8MB	11.0.8173.0
    Microsoft Silverlight	Microsoft Corporation	12.10.2011	40,5MB	4.0.60831.0
    Microsoft Visual C++ 2005 Redistributable	Microsoft Corporation	15.06.2011	0,29MB	8.0.56336
    Microsoft Visual C++ 2005 Redistributable (x64)	Microsoft Corporation	24.09.2011	0,68MB	8.0.61000
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148	Microsoft Corporation	25.07.2010	0,20MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729	Microsoft Corporation	26.07.2010	0,25MB	9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148	Microsoft Corporation	20.06.2010	0,77MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161	Microsoft Corporation	15.06.2011	0,77MB	9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022	Microsoft Corporation	06.04.2011	1,42MB	9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729	Microsoft Corporation	24.07.2010	0,59MB	9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17	Microsoft Corporation	20.11.2011	0,22MB	9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148	Microsoft Corporation	28.07.2010	0,58MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161	Microsoft Corporation	15.06.2011	0,59MB	9.0.30729.6161
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219	Microsoft Corporation	10.08.2011	13,8MB	10.0.40219
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219	Microsoft Corporation	10.08.2011	15,0MB	10.0.40219
    Microsoft WSE 3.0 Runtime	Microsoft Corp.	19.11.2010	0,92MB	3.0.5305.0
    Mozilla Firefox 8.0 (x86 de)	Mozilla	08.11.2011	37,4MB	8.0
    Mp3tag v2.48	Florian Heidenreich	23.02.2011		v2.48
    MSXML 4.0 SP2 (KB954430)	Microsoft Corporation	20.06.2010	1,28MB	4.20.9870.0
    MSXML 4.0 SP2 (KB973688)	Microsoft Corporation	20.06.2010	1,33MB	4.20.9876.0
    MSXML 4.0 SP2 Parser und SDK	Microsoft Corporation	24.07.2010	48,00KB	4.20.9818.0
    MSXML 4.0 SP3 Parser	Microsoft Corporation	20.02.2011	1,48MB	4.30.2100.0
    MSXML 4.0 SP3 Parser (KB973685)	Microsoft Corporation	21.02.2011	1,53MB	4.30.2107.0
    MyPhoneExplorer	F.J. Wechselberger	20.02.2011		1.8.0
    Nero 9	Nero AG	13.08.2010		
    NVIDIA Drivers	NVIDIA Corporation	27.08.2011	5,26MB	1.10.62.40
    NVIDIA ForceWare Network Access Manager	NVIDIA Corporation	10.08.2010	34,2MB	1.00.7316
    NVIDIA PhysX	NVIDIA Corporation	29.03.2011	80,1MB	9.10.0222
    OpenSource AVI Splitter (remove only)		31.10.2010		
    OpenSource DTS/AC3/DD+ Source Filter (remove only)		31.10.2010		
    Origin	Electronic Arts, Inc.	17.06.2011		8.1.2.444
    PC Connectivity Solution	Nokia	07.08.2010	15,0MB	8.15.0.0
    PDFCreator	Frank Heindörfer, Philip Chinery	14.08.2010		1.0.1
    PixiePack Codec Pack	None	08.01.2011	17,2MB	1.1.1200.0
    PMDG 747-400/400F for FSX	Precision Manuals Development Group	06.04.2011		2.10.0000
    PMDG744X_GE_KL	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744X_GE_LH	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744X_PW_NW3	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744X_RR_BA	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744XF_PW_FXF	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744XF_RR_CXF	Precision Manuals Development Group	06.04.2011		1.00.0000
    QuickTime	Apple Inc.	27.10.2011	73,3MB	7.71.80.42
    RealMedia (remove only)		31.10.2010		
    RealPlayer	RealNetworks	12.02.2011		
    Realtek HDMI Audio Driver for ATI	Realtek Semiconductor Corp.	20.07.2010		6.0.1.5945
    RENESIS® Player Browser Plugins	examotion® GmbH	26.09.2010	1,83MB	1.1.1
    Revo Uninstaller 1.93	VS Revo Group	09.10.2011		1.93
    Safari	Apple Inc.	27.10.2011	43,2MB	5.34.51.22
    Secure Eraser v4.0	ASCOMP Software GmbH	30.07.2011	10,5MB	
    SHOUTcast Source (remove only)		31.10.2010		
    Sophos Anti-Rootkit 1.5.20	Sophos Plc	02.12.2011		1.5.20
    SpeedFan (remove only)		24.07.2010		
    StarMoney 8.0	Star Finanz GmbH	04.04.2011		8.0
    TAXMAN 2010	Haufe-Lexware GmbH & Co. KG	20.11.2011	473MB	16.12.00.0003
    TAXMAN 2011	Haufe-Lexware GmbH & Co.KG	20.11.2011	669MB	17.05.00.0003
    TAXMAN 2012	Haufe-Lexware GmbH & Co.KG	20.11.2011	487MB	18.00.00.0061
    TAXMAN Bibliothek 2011	Haufe-Lexware GmbH & Co. KG	01.02.2011	444MB	17.10.0.0
    TAXMAN Bibliothek 2012	Haufe-Lexware GmbH & Co. KG	20.11.2011	464MB	18.0.0.0
    TIPP10 Version 2.1.0	(c) 2006-2011, Tom Thielicke IT Solutions	19.11.2011		
    TuneUp Utilities 2011	TuneUp Software	15.06.2011		10.0.4200.96
    TV-Browser 3.0-beta2		24.07.2010		3.0-beta2
    UBitMenuDE	UBit Schweiz AG	08.08.2010		01.04
    Uninstall 1.0.0.1		23.02.2011	10,4MB	
    UpdateYeti	Abelssoft GmbH	26.08.2011	17,9MB	2.0
    VIA Plattform-Geräte-Manager	VIA Technologies, Inc.	20.06.2010	2,62MB	1.34
    Visual C++ 8.0 Runtime Setup Package (x64)	AVG Technologies CZ, s.r.o.	20.06.2010	2,24MB	9.0.0.623
    VLC media player 1.0.5	VideoLAN Team	20.07.2010		1.0.5
    Windows Live ID Sign-in Assistant	Microsoft Corporation	28.01.2011	10,0MB	6.500.3165.0
    Windows Media Player Firefox Plugin	Microsoft Corp	24.07.2010	0,29MB	1.0.0.8
    Windows Mobile-Gerätecenter	Microsoft Corporation	09.06.2011	27,4MB	6.1.6965.0
    Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)	Nokia	07.08.2010		10/12/2007 6.85.4.0
    WinRAR		02.11.2010		
    XMedia Recode 3.0.2.5	Sebastian Dörfler	09.09.2011		3.0.2.5
    XnView 1.97	Gougelet Pierre-e	20.06.2010		1.97
    Zoom Player (remove only)		31.10.2010		
    Zoom Player deutsche Sprachdateien (entfernen)		31.10.2010
    Code:
    OTL logfile created on: 04.12.2011 13:49:04 - Run 3
    OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Peter\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
     
    4,00 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 59,58% Memory free
    8,00 Gb Paging File | 6,07 Gb Available in Paging File | 75,92% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 100,01 Gb Total Space | 44,07 Gb Free Space | 44,07% Space Free | Partition Type: NTFS
    Drive D: | 831,50 Gb Total Space | 682,19 Gb Free Space | 82,04% Space Free | Partition Type: NTFS
     
    Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Processes (SafeList) ==========
     
    PRC - [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    PRC - [2011.11.09 17:21:35 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2011.10.19 16:56:01 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    PRC - [2011.10.19 16:55:48 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2011.10.19 16:55:48 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    PRC - [2011.10.06 03:34:56 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    PRC - [2011.09.12 08:58:19 | 000,688,648 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) -- C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
    PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2011.08.22 09:01:00 | 000,593,920 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    PRC - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2011.05.25 21:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2010.11.05 10:28:14 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
     
     
    ========== Modules (No Company Name) ==========
     
    MOD - [2011.11.09 17:21:34 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    MOD - [2011.11.02 20:52:06 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    MOD - [2011.10.13 11:24:10 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f8196c3588c2229e84516af4b6a0ee60\System.Data.ni.dll
    MOD - [2011.10.13 11:23:35 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
    MOD - [2011.10.13 11:23:32 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
    MOD - [2011.10.13 11:23:32 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
    MOD - [2011.10.13 11:23:28 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
    MOD - [2011.09.27 06:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011.09.27 06:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011.08.22 09:01:00 | 001,515,520 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll
    MOD - [2011.08.22 09:01:00 | 000,593,920 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    MOD - [2011.08.22 09:01:00 | 000,559,244 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dll
    MOD - [2011.08.22 09:01:00 | 000,516,599 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll
    MOD - [2011.08.22 09:01:00 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\HtcDetect.dll
    MOD - [2011.08.22 09:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll
    MOD - [2011.08.22 09:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll
    MOD - [2011.08.22 09:01:00 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll
    MOD - [2010.11.13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
    MOD - [2010.11.05 02:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
     
     
    ========== Win32 Services (SafeList) ==========
     
    SRV:64bit: - [2011.06.06 16:49:50 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
    SRV:64bit: - [2010.05.27 17:59:40 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV - [2011.10.19 16:56:01 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2011.10.19 16:55:48 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011.09.12 08:58:19 | 000,688,648 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Running] -- C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
    SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2011.08.12 16:13:26 | 000,087,040 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
    SRV - [2011.06.06 16:54:54 | 002,026,304 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
    SRV - [2011.06.06 16:49:44 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
    SRV - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
    SRV - [2010.11.20 13:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
    SRV - [2010.11.05 10:28:14 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus)
    SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009.08.10 15:01:06 | 000,206,880 | ---- | M] () [Auto | Running] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
    SRV - [2009.08.10 15:01:04 | 000,626,208 | ---- | M] () [Auto | Running] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
    SRV - [2009.06.18 14:19:30 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008.10.03 21:41:22 | 000,743,192 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
    SRV - [2008.04.07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2007.05.31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
    SRV - [2007.05.31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV:64bit: - [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR162.SYS -- (SMR162)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,130,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
    DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
    DRV:64bit: - [2011.05.12 14:03:12 | 000,006,144 | ---- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\9645.tmp -- (MEMSWEEP2)
    DRV:64bit: - [2011.05.10 07:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010.12.16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
    DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010.08.12 11:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
    DRV:64bit: - [2010.07.22 16:02:35 | 001,580,576 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm140.sys -- (tdrpman140) Acronis Try&Decide and Restore Points filter (build 140)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,880,160 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,083,488 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\tifsfilt.sys -- (tifsfilter)
    DRV:64bit: - [2010.07.22 16:02:30 | 000,237,600 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380)
    DRV:64bit: - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
    DRV:64bit: - [2010.05.27 18:39:12 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2010.05.27 17:25:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2010.04.13 08:04:38 | 001,270,784 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV:64bit: - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
    DRV:64bit: - [2009.09.25 09:13:26 | 000,205,440 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
    DRV:64bit: - [2009.07.17 00:51:54 | 000,028,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvamacpi.sys -- (nvamacpi)
    DRV:64bit: - [2009.07.16 11:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
    DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
    DRV:64bit: - [2009.06.10 21:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
    DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009.02.03 16:46:14 | 000,077,952 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfsync04.sys -- (sfsync04) StarForce Protection Synchronization Driver (version 4.x)
    DRV:64bit: - [2009.02.03 16:40:13 | 000,077,432 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
    DRV:64bit: - [2007.09.17 14:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
    DRV:64bit: - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV:64bit: - [2007.02.08 18:47:24 | 000,107,384 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
    DRV:64bit: - [2006.06.14 15:58:10 | 000,014,192 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
    DRV - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
    DRV - [2010.08.19 21:08:04 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
    DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV - [2007.02.07 19:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
     
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.kiebel.de
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2206084
    IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - No CLSID value found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
     
    ========== FireFox ==========
     
     
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
    FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
     
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.02.13 14:39:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.09 17:21:35 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.10.28 22:22:57 | 000,000,000 | ---D | M]
     
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions
    [2011.02.24 21:00:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2011.11.09 17:21:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
    [2011.11.09 17:21:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2008.06.19 10:16:24 | 000,118,784 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\MyCamera.dll
    [2008.06.19 10:16:24 | 000,053,248 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\NPCIG.dll
    [2010.09.15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2011.10.08 17:38:48 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
    [2011.10.08 17:38:48 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011.10.08 17:38:48 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
    [2011.10.08 17:38:48 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
    [2011.10.08 17:38:48 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
    [2011.10.08 17:38:48 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
     
    O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
    O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
    O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
    O4 - HKCU..\Run: [Personal ID] C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE (coolspot AG, Düsseldorf)
    O4 - Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    F3:64bit: - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) -  File not found
    F3 - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) - File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8:64bit: - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O8 - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8 - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8 - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8 - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8 - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8 - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Domains: amazon.de ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
    O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87F7A994-F44E-4345-B88E-03ECE07BAB9D}: DhcpNameServer = 192.168.178.1
    O18:64bit: - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O27:64bit: - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
     
    ========== Files/Folders - Created Within 30 Days ==========
     
    [2011.12.03 17:13:07 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\Temp
    [2011.12.03 17:11:18 | 000,000,000 | ---D | C] -- C:\.Trash-999
    [2011.12.03 14:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
    [2011.12.03 14:20:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
    [2011.12.03 14:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2011.12.03 13:47:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 12:59:25 | 000,090,232 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2011.12.03 12:59:22 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\NPE
    [2011.12.03 12:59:01 | 006,161,912 | ---- | C] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 01:09:34 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Avira
    [2011.12.03 01:09:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
    [2011.12.03 01:09:11 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
    [2011.12.03 01:09:11 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
    [2011.12.03 01:09:11 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
    [2011.11.23 14:54:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2011.11.23 14:52:48 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2011.11.21 15:35:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DataDesign
    [2011.11.21 15:33:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sybase
    [2011.11.20 21:20:12 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\TIPP10
    [2011.11.20 21:20:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIPP10
    [2011.11.17 17:21:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011.11.13 13:55:16 | 000,000,000 | ---D | C] -- C:\Users\Peter\Desktop\Games
    [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
     
    ========== Files - Modified Within 30 Days ==========
     
    [2011.12.04 13:52:17 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    [2011.12.04 13:51:33 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011.12.04 13:51:33 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011.12.04 13:48:22 | 001,766,796 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2011.12.04 13:48:22 | 000,759,454 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
    [2011.12.04 13:48:22 | 000,703,364 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2011.12.04 13:48:22 | 000,169,072 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
    [2011.12.04 13:48:22 | 000,137,512 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2011.12.04 13:44:04 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011.12.04 13:44:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011.12.04 13:41:22 | 000,080,709 | ---- | M] () -- C:\Users\Peter\Desktop\warn.jpg
    [2011.12.03 17:20:14 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 13:46:48 | 000,000,000 | ---- | M] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 12:59:31 | 000,000,761 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:08 | 006,161,912 | ---- | M] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 12:58:02 | 000,883,840 | ---- | M] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:09:26 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 01:02:28 | 084,419,032 | ---- | M] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.12.03 00:58:18 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.11.23 14:54:54 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:53:19 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2011.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | M] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | M] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | M] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.13 13:55:12 | 000,000,628 | ---- | M] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.09 17:08:21 | 000,350,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
     
    ========== Files Created - No Company Name ==========
     
    [2011.12.04 13:41:22 | 000,080,709 | ---- | C] () -- C:\Users\Peter\Desktop\warn.jpg
    [2011.12.03 13:46:48 | 000,000,000 | ---- | C] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 12:59:31 | 000,000,761 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:58:09 | 000,883,840 | ---- | C] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:09:26 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 00:58:18 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.12.03 00:57:41 | 084,419,032 | ---- | C] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.11.23 14:54:54 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | C] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | C] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | C] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.13 13:55:12 | 000,000,628 | ---- | C] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.08 10:56:09 | 005,133,509 | ---- | C] () -- C:\Users\Peter\Desktop\IMG_8450.JPG
    [2011.09.27 11:17:26 | 000,198,144 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll
    [2011.09.27 11:16:20 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll
    [2011.09.27 11:14:14 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll
    [2011.09.27 11:13:58 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll
    [2011.06.10 11:53:49 | 001,456,640 | ---- | C] () -- C:\Program Files (x86)\Common Files\Falk Navi-Manager.msi
    [2011.04.30 15:18:32 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{D431F69B-9F80-4998-8606-16B2FF4763C2}
    [2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
    [2011.02.13 15:06:41 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
    [2010.11.03 22:34:25 | 000,000,038 | ---- | C] () -- C:\Windows\osAviSplitter.INI
    [2010.10.21 14:18:46 | 000,303,104 | ---- | C] () -- C:\Windows\SysWow64\dnt27VC8.dll
    [2010.10.21 14:16:58 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\dntvmc27VC8.dll
    [2010.10.21 14:16:34 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dntvm27VC8.dll
    [2010.10.17 19:03:42 | 001,653,284 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2010.09.24 12:27:18 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
    [2010.08.27 16:22:42 | 000,000,123 | -HS- | C] () -- C:\ProgramData\.zreglib
    [2010.08.19 16:11:13 | 000,003,314 | ---- | C] () -- C:\Windows\cdplayer.ini
    [2010.08.14 18:02:08 | 008,676,883 | ---- | C] () -- C:\Windows\SysWow64\NCMedia2.dll
    [2010.08.14 13:07:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2010.08.14 12:46:47 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
    [2010.08.11 19:14:48 | 000,015,873 | ---- | C] () -- C:\Windows\SysWow64\Inetde.dll
    [2010.08.01 15:26:08 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2010.07.25 18:27:31 | 000,027,648 | ---- | C] () -- C:\Users\Peter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010.07.25 13:49:01 | 000,000,130 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\default.rss
    [2010.07.24 20:05:40 | 000,111,932 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
    [2010.07.24 20:05:40 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
    [2010.07.24 20:05:40 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
    [2010.07.24 20:05:40 | 000,026,154 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
    [2010.07.24 20:05:40 | 000,024,903 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
    [2010.07.24 20:05:40 | 000,021,390 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
    [2010.07.24 20:05:40 | 000,020,148 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
    [2010.07.24 20:05:40 | 000,011,811 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
    [2010.07.24 20:05:40 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
    [2010.07.24 20:05:40 | 000,001,146 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
    [2010.07.24 20:05:40 | 000,001,136 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
    [2010.07.24 20:05:40 | 000,001,120 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
    [2010.07.24 20:05:40 | 000,001,107 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
    [2010.07.24 20:05:40 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
    [2010.07.24 20:05:40 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
    [2010.06.21 12:08:08 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2010.06.21 12:03:04 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
    [2010.06.21 12:03:04 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
    [2010.06.21 12:03:01 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
    [2010.06.21 12:03:01 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
    [2010.06.21 11:29:41 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010.06.21 11:29:41 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
    [2010.06.21 11:29:40 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2010.06.21 11:29:40 | 000,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2010.04.29 16:37:26 | 000,002,137 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2009.11.25 13:40:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2009.09.30 11:05:48 | 000,290,816 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v60.dll
    [2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008.10.30 17:00:22 | 000,048,640 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v60.dll
    [2008.10.30 16:59:24 | 000,025,088 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v60.dll
    [2006.04.21 09:08:22 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\HtmlHelp.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v50.dll
     
    ========== LOP Check ==========
     
    [2011.08.27 09:53:16 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Abelssoft
    [2010.08.23 18:44:52 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Acronis
    [2010.11.04 20:14:37 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\ASCOMP Software
    [2011.10.28 21:04:07 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Aura4You
    [2010.10.20 16:37:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Bioshock2
    [2010.08.12 23:07:50 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\BOM
    [2011.12.04 13:44:46 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Dropbox
    [2011.10.28 20:44:03 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DVDVideoSoft
    [2011.02.24 21:00:08 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers
    [2011.10.28 20:40:05 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\E-Zsoft
    [2011.10.04 17:49:02 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\elsterformular
    [2010.07.24 20:16:41 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\EPSON
    [2011.07.17 20:04:06 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Foxit Software
    [2011.10.29 15:58:57 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Free Download Manager
    [2011.10.25 20:26:07 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Free iPad Video Converter
    [2010.10.31 19:56:53 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GetFoldersize
    [2010.11.19 11:07:17 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GetRightToGo
    [2011.02.25 17:02:48 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\HandBrake
    [2010.11.20 19:32:46 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Haufe Mediengruppe
    [2011.09.25 13:32:09 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\HTC
    [2011.02.21 21:43:44 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
    [2010.07.25 16:54:20 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\IrfanView
    [2011.01.31 19:43:31 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Lexware
    [2011.02.24 21:21:48 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Mp3tag
    [2011.10.28 20:34:52 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\MPEG Streamclip
    [2011.02.21 21:58:18 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\MyPhoneExplorer
    [2010.11.04 23:24:35 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\OfficeRecovery
    [2010.07.22 15:51:03 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\OpenOffice.org
    [2010.08.08 16:42:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\PC Suite
    [2010.11.19 19:48:37 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Privacy Guardian
    [2010.07.25 13:17:54 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Qualcomm
    [2010.08.08 16:42:31 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Samsung
    [2011.11.20 21:22:39 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TIPP10
    [2010.11.24 19:26:40 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TuneUp Software
    [2011.11.25 13:24:39 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TV-Browser
    [2010.08.09 19:35:55 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\UBitMenu
    [2011.08.26 15:15:38 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Utherverse
    [2011.09.10 17:43:06 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\XMedia Recode
    [2011.11.30 20:53:41 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\XnView
    [2011.11.21 09:04:43 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
     
    ========== Purity Check ==========
     
     
     
    ========== Alternate Data Streams ==========
     
    @Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:96D0C06F
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:42D9E231
    
    < End of report >
    Code:
    OTL Extras logfile created on: 04.12.2011 13:49:04 - Run 3
    OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Peter\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
     
    4,00 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 59,58% Memory free
    8,00 Gb Paging File | 6,07 Gb Available in Paging File | 75,92% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 100,01 Gb Total Space | 44,07 Gb Free Space | 44,07% Space Free | Partition Type: NTFS
    Drive D: | 831,50 Gb Total Space | 682,19 Gb Free Space | 82,04% Space Free | Partition Type: NTFS
     
    Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Extra Registry (SafeList) ==========
     
     
    ========== File Associations ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
     
    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
     
    ========== Shell Spawning ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
     
    ========== Security Center Settings ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
     
    ========== Firewall Settings ==========
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
     
    ========== Authorized Applications List ==========
     
     
    ========== HKEY_LOCAL_MACHINE Uninstall List ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
    "{2016B2AD-0051-05C7-9CCB-CE9F05659CB7}" = ccc-utility64
    "{25D04DBB-FE9D-E3BA-C2F3-F1BE9B8C0709}" = ATI Catalyst Install Manager
    "{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java(TM) 6 Update 21 (64-bit)
    "{4B55F339-396E-29A9-B6D0-24B6D251C90A}" = AMD Drag and Drop Transcoding
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
    "{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
    "{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
    "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
    "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
    "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{D285FC5F-3021-32E9-9C59-24CA325BDC5C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
    "{EC8A40B2-096A-4EA4-B11A-167F87F293A7}" = iCloud
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
    "BC15EA930074932BB2C4B4493C9FD4EA95087D1A" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
    "CCleaner" = CCleaner
    "EPSON Printer and Utilities" = EPSON-Drucker-Software
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
    "NVIDIA Drivers" = NVIDIA Drivers
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{0197D136-598D-4968-BEEA-91C1B764F05D}" = Lexware buchhalter 2012
    "{02627EE5-EACA-4742-A9CC-E687631773E4}" = Nero ShowTime
    "{086A7D8C-0A38-4C7F-819A-620275550D5C}" = Nero Burning ROM Help
    "{0CA1005F-B640-0354-EC82-F8F7447A8E8A}" = CCC Help Hungarian
    "{0F32914F-A633-4516-B531-7084C8F19F93}" = Haufe iDesk-Browser
    "{0FC472C3-6A2A-969F-10E7-E8F61B18117C}" = Catalyst Control Center Localization All
    "{1923679F-C14B-4790-BC54-EFA3FCDE147B}" = Lexware Elster
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{1C00C7C5-E615-4139-B817-7F4003DE68C0}" = Nero PhotoSnap Help
    "{1D081AB0-B1CC-11E0-80C0-005056B12123}" = Haufe iDesk-Service
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1FCBD504-AB7D-4757-9A14-850348384B08}" = StarMoney
    "{20372FAA-3AF4-4B3D-9B1D-564CDEA5957C}" = PMDG744X_GE_LH
    "{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
    "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
    "{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
    "{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
    "{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 22
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
    "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
    "{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
    "{31405CA2-F009-D91B-FEFF-35924343CB14}" = Catalyst Control Center InstallProxy
    "{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
    "{31B75145-DF24-C759-E735-9C129956961E}" = CCC Help Spanish
    "{3222B0CE-59C5-4CA0-B545-2B88F200756B}" = Falk Navi-Manager
    "{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
    "{3526C5B8-60EE-4199-BEFD-6BCC86F051B9}" = TAXMAN 2011
    "{3563500D-85F7-48AE-A91D-811E92BA49BB}" = TAXMAN Bibliothek 2011
    "{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
    "{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
    "{37BC8FCE-15B1-456E-A62C-EEB175B71340}" = Lexware reisekosten plus 2011
    "{37C8899D-FD70-481F-94AA-1F1B08765E22}" = Acronis*True*Image*Home
    "{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}" = Epson Easy Photo Print 2
    "{406A89D6-09E6-4550-B370-8D376DDB56BE}" = Adobe Flash Player 10 ActiveX
    "{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
    "{50DFE454-6234-4BEB-BADF-0571CB9D2F13}" = AudialsOne
    "{54194F60-988C-4D03-B922-C2B00EFDA39A}" = NVIDIA PhysX
    "{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
    "{5454085C-840F-4070-8FAA-441000038301}" = BioShock 2
    "{5454085C-840F-4070-8FAA-441000038302}" = BioShock 2
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
    "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
    "{5C5B0836-9648-4057-8044-2DF181E073E2}" = TAXMAN 2010
    "{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE)
    "{5D9BE3C1-8BA4-4E7E-82FD-9F74FA6815D1}" = Nero Vision Help
    "{5E08ECD1-C98E-4711-BF65-8FD736B3F969}" = Nero RescueAgent Help
    "{5E453519-60F6-4A4D-A0BF-16663F9B3536}" = Safari
    "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
    "{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2
    "{60C731FB-C951-41CE-AD41-8E54C8594609}" = Nero Disc Copy Gadget Help
    "{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
    "{62B7C52C-CAB6-48B1-8245-52356C141C92}" = RENESIS® Player Browser Plugins
    "{63B9224A-89C9-44E6-8252-5F2F73A71C54}" = StarMoney
    "{641C1B16-FD4C-0F97-47AE-76637FC64225}" = CCC Help English
    "{65415AC9-0D2B-4A0F-9786-28748640F781}" = Falk Navi-Manager
    "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    "{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{77E33D87-255E-413E-9C8D-EED2A7F9BEBF}" = Nero Live Help
    "{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79C2D7F9-3BF8-52C1-6A7A-84C9296171F8}" = CCC Help German
    "{7B29E627-71A5-6824-3F85-DBEF19624BD0}" = ccc-core-static
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
    "{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
    "{85243696-5E58-4357-9CF8-3498C609941D}" = NeroLiveGadget Help
    "{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
    "{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
    "{879C52A2-FF9A-4CB5-BB74-B0DA994ABB2A}" = StarMoney
    "{88B2BB7B-A684-E8E3-65C6-DDC5DC152C2A}" = CCC Help French
    "{89196F9A-2E0B-4197-A3DF-6EF78731EB35}" = Lexware online banking
    "{89E0B0D4-DFC3-49B9-8E88-F1B801325C8A}" = Emergency 3
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial 
    "{8CB77076-DB66-5D92-7886-807226C9CE4B}" = CCC Help Italian
    "{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine
    "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
    "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
    "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
    "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
    "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
    "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
    "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
    "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
    "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{90850407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
    "{90C67C7D-E918-402C-9856-7B13999E1786}" = StarMoney
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{92633C0F-C9BE-41E3-B439-0B508F859DB5}" = StarMoney
    "{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite
    "{96E1C9EE-5109-41FA-B412-E3358626051D}" = PMDG744X_PW_NW3
    "{98A67610-A3B5-4098-A423-3708040026D3}" = "Nero SoundTrax Help
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9A4C534E-431F-4A17-97D4-D1682B19A054}" = Emergency4
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9C6F56DA-7051-6677-4E5A-9DC6C573F2B5}" = CCC Help Portuguese
    "{9C979BC5-0B86-47A1-B6C1-6057297DB61C}" = PMDG744X_RR_BA
    "{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
    "{9E9FDDE6-2C26-492A-85A0-05646B3F2795}" = NeroLiveGadget
    "{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}" = PixiePack Codec Pack
    "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{ABD462F9-7436-4086-A65B-AC6360ED45FC}" = PMDG744XF_RR_CXF
    "{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
    "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch
    "{AD6BC5CC-2EF0-49C4-B33D-CDC8B2C4DC80}" = Nero Recode Help
    "{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
    "{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
    "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
    "{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
    "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
    "{C3FA3CCE-2A88-0976-B875-4B3E9D41204D}" = Catalyst Control Center Graphics Previews Common
    "{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
    "{CBCFD97D-FE82-43F4-A978-996CACF71E6B}_is1" = UBitMenuDE
    "{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
    "{CE96F5A5-584D-4F8F-AA3E-9BAED413DB72}" = Nero CoverDesigner Help
    "{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
    "{D34A78EB-78F2-48ab-8CAE-5D4DC255A491}" = Lexware reisekosten plus 2011
    "{D4CF23EE-B0B6-4E5F-A335-8E63F8AFAC98}" = PMDG744X_GE_KL
    "{D54A0D86-35B0-BFC8-174B-D991EDF903B8}" = Catalyst Control Center Graphics Previews Vista
    "{D5610369-AF78-386F-4985-9822654973A3}" = CCC Help Polish
    "{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync
    "{d881334f-9d80-46b0-8374-d8f1145baeba}" = Nero 9
    "{D92F1880-822A-41CA-0090-451FBB89BF4C}" = FIFA Fussball-Weltmeisterschaft 2006 (TM)
    "{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
    "{DAF15921-FA90-4427-82A2-1852A9BAC99A}" = Lexware Datenbank plus 2011
    "{DF344785-0900-471E-B9F5-6F28C89AF638}" = TAXMAN Bibliothek 2012
    "{DF6A95F5-ADC1-406A-BDC6-2AA7CC0182AA}" = Nero Live
    "{E2062054-90AC-44F1-800E-DC4930F4DC9E}" = StarMoney 8.0 
    "{E2F2B987-F2BC-4969-95F2-92099486B811}" = StarMoney
    "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
    "{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
    "{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
    "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
    "{EDCEE320-0FB3-4197-9F86-8C1CCF2278FB}" = PMDG 747-400/400F for FSX
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
    "{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
    "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
    "{F3C2ECAA-1B4D-4B75-9105-106B0D03EF02}" = Lexware Info Service
    "{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
    "{F4443656-4EE4-42F8-81C4-709313BB3688}" = Eudora
    "{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
    "{F6BDD7C5-89ED-4569-9318-469AA9732572}" = Nero BurnRights Help
    "{F722209B-739E-40E4-ADB1-062BD032A0DB}" = Personal ID
    "{F77ABA68-8AC4-497E-9FFA-9CA4506B78FC}" = PMDG744XF_PW_FXF
    "{F77D44EB-2A6E-E2EE-7C30-40A5409B2650}" = CCC Help Greek
    "{FA3FDB06-3368-4579-B2F2-5AE8AD6E7871}" = TAXMAN 2012
    "{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
    "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
    "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "7-Zip" = 7-Zip 4.65
    "AC3Filter_is1" = AC3Filter 1.63b
    "Adobe AIR" = Adobe AIR
    "AirlineTycoon2-Demo_is1" = Airline Tycoon 2 Demo v1.01
    "AnyDVD" = AnyDVD
    "Audiograbber" = Audiograbber 1.83 SE 
    "Aura DVD Ripper Professional_is1" = Aura DVD Ripper Professional 1.3.8
    "Aura Software Manager_is1" = Aura Software Manager 1.0.3
    "Avira AntiVir Desktop" = Avira Free Antivirus
    "AVMFBox" = AVM FRITZ!Box Dokumentation
    "Biet-O-Matic v2.14.6" = Biet-O-Matic v2.14.6
    "CameraWindowDC" = Canon Utilities CameraWindow DC
    "CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    "CameraWindowLauncher" = Canon Utilities CameraWindow
    "Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
    "CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
    "Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
    "Canon MOV Decoder" = Canon MOV Decoder
    "Canon MOV Encoder" = Canon MOV Encoder
    "CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
    "ClearProg" = ClearProg 1.6.0 Final
    "CloneCD" = CloneCD
    "CloneDVD2" = CloneDVD2
    "DCoder Image Source" = DCoder Image Source (remove only)
    "DivX Setup.divx.com" = DivX-Setup
    "DScaler 5 Mpeg Decoders_is1" = DScaler 5 Mpeg Decoders
    "ElsterFormular 11.5.0.4546" = ElsterFormular
    "EOS Video Snapshot Task" = Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX
    "EPSON Scanner" = EPSON Scan
    "FFMPEG Core Files" = FFMPEG Core Files (remove only)
    "FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
    "FormatFactory" = FormatFactory 2.60
    "Foxit Reader" = Foxit Reader
    "Free Download Manager_is1" = Free Download Manager 3.0
    "Free Studio_is1" = Free Studio version 5.2.0
    "Free Video Dub_is1" = Free Video Dub version 1.8
    "Freez FLV to AVI/MPEG/WMV Converter v1.6_is1" = Freez FLV to AVI/MPEG/WMV Converter
    "GameCenter" = GameCenter
    "GetFoldersize_is1" = GetFoldersize 2.3.2
    "HijackThis" = HijackThis 2.0.2
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
    "InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
    "InstallShield_{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
    "IrfanView" = IrfanView (remove only)
    "KLiteCodecPack_is1" = K-Lite Codec Pack 5.7.0 (Full)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
    "MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
    "Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
    "Mp3tag" = Mp3tag v2.48
    "MPE" = MyPhoneExplorer
    "MyCamera" = Canon Utilities MyCamera
    "MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
    "MyCameraDC" = Canon Utilities MyCamera DC
    "OpenSource AVI Splitter" = OpenSource AVI Splitter (remove only)
    "OpenSource DTS/AC3/DD+ Source Filter" = OpenSource DTS/AC3/DD+ Source Filter (remove only)
    "Origin" = Origin
    "PhotoStitch" = Canon Utilities PhotoStitch
    "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
    "RealMedia" = RealMedia (remove only)
    "RealPlayer 12.0" = RealPlayer
    "RemoteCaptureDC" = Canon Utilities RemoteCapture DC
    "RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X
    "Secure Eraser_is1" = Secure Eraser v4.0
    "SHOUTcast Source" = SHOUTcast Source (remove only)
    "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.20
    "SP1_F535B2CF-C9BB-4162-B03A-02D6971F32CC" = Microsoft Flight Simulator X Service Pack 1
    "SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X Service Pack 1
    "SpeedFan" = SpeedFan (remove only)
    "TIPP10_is1" = TIPP10 Version 2.1.0
    "TuneUp Utilities 2011" = TuneUp Utilities 2011
    "tvbrowser" = TV-Browser 3.0-beta2
    "Uninstall_is1" = Uninstall 1.0.0.1
    "UpdateYeti_is1" = UpdateYeti
    "VLC media player" = VLC media player 1.0.5
    "WinRAR archiver" = WinRAR
    "XMedia Recode" = XMedia Recode 3.0.2.5
    "XnView_is1" = XnView 1.97
    "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
    "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
    "ZoomPlayer" = Zoom Player (remove only)
    "ZoomPlayerLang" = Zoom Player deutsche Sprachdateien (entfernen)
     
    ========== HKEY_CURRENT_USER Uninstall List ==========
     
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "A380v2 (FSX)" = A380v2 (FSX)
    "ActiveTrader 5.0.0_b15" = ActiveTrader 5.0.0_b15
    "Airbus Series Vol.2 (FS X)" = Airbus Series Vol.2 (FS X) ActiveTrader 5.0.0_b15
    
    "Dropbox" = Dropbox
     
    ========== Last 10 Event Log Errors ==========
     
    [ Application Events ]
    Error - 30.03.2011 14:53:01 | Computer Name = Peter-PC | Source = Application Error | ID = 1000
    Description = Name der fehlerhaften Anwendung: Metro2033.exe, Version: 1.0.0.1, 
    Zeitstempel: 0x4c7775b7  Name des fehlerhaften Moduls: Metro2033.exe, Version: 1.0.0.1,
     Zeitstempel: 0x4c7775b7  Ausnahmecode: 0xc0000005  Fehleroffset: 0x003e7ccb  ID des fehlerhaften
     Prozesses: 0xff8  Startzeit der fehlerhaften Anwendung: 0x01cbef0bab09bd20  Pfad der
     fehlerhaften Anwendung: D:\program files (x86)\steam\steamapps\common\metro 2033\Metro2033.exe
    Pfad
     des fehlerhaften Moduls: D:\program files (x86)\steam\steamapps\common\metro 2033\Metro2033.exe
    Berichtskennung:
     ef87a480-5afe-11e0-8e21-485b39af178a
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    [ System Events ]
    Error - 02.12.2011 20:08:42 | Computer Name = Peter-PC | Source = Service Control Manager | ID = 7001
    Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der
     aufgrund folgenden Fehlers nicht gestartet wurde:   %%1068
     
    Error - 02.12.2011 20:08:49 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 02.12.2011 20:09:19 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 02.12.2011 20:11:43 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 02.12.2011 20:11:43 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 03.12.2011 08:15:35 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 03.12.2011 12:03:25 | Computer Name = Peter-PC | Source = DCOM | ID = 10010
    Description = 
     
    Error - 03.12.2011 12:14:42 | Computer Name = Peter-PC | Source = Service Control Manager | ID = 7009
    Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
     Windows Mobile-basierte Geräteverbindungen erreicht.
     
    Error - 03.12.2011 12:14:42 | Computer Name = Peter-PC | Source = Service Control Manager | ID = 7000
    Description = Der Dienst "Windows Mobile-basierte Geräteverbindungen" wurde aufgrund
     folgenden Fehlers nicht gestartet:   %%1053
     
    Error - 03.12.2011 12:14:42 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    [ TuneUp Events ]
    Error - 04.12.2010 06:43:07 | Computer Name = Peter-PC | Source = TuneUp.UtilitiesSvc | ID = 300
    Description = 
     
    Error - 04.12.2010 06:43:07 | Computer Name = Peter-PC | Source = TuneUp.UtilitiesSvc | ID = 300
    Description = 
     
    Error - 04.12.2010 06:43:07 | Computer Name = Peter-PC | Source = TuneUp.UtilitiesSvc | ID = 300
    Description = 
     
     
    < End of report >
    Malewarebyte: Kein Fund

  4. #4
    Forenbenutzer
    Registriert seit
    22.08.2009
    Beiträge
    58

    AW: Bundespolizei Trojaner seit gestern

    Hallo

    Ich hab inzwischen wohl den Übeltäter gefundne,. In einem TEMP-Ordner unter "App Data" waren viel Dateien und u.a. auch das Bild was man von dem Trojyaner sieht (Eingabemasket etc)
    ich hab dann den ganzen TEMP-Ordner geleert und danach kam der Trojaner nicht mehr,

    ich wollte dann zur Sicherheit noch die Systemwiederherstellung machen (Habe eine vom 28.11.) daber das funktioniert nicht da die Fehlermeldung kommt das die Sys.-Wiederherstellung bloekcert ist (habe auch den ACVAntivir deaktiviert, gheht dennoch nicht).

    Das komische ist daß wenn ich dann Wiederherstellung rückgängig machen anklicke der PC dies auch macht und dann eine Erfolgreiche Rücknahme vermeledet..SIt doch unlogisch oder ? Er hat ja angeblich bei der ersten Wiederherstllung nichts ändern können...

    Anbe inoch die Logs:
    Code:
    7-Zip 4.65		20.07.2010		
    A380v2 (FSX)		05.11.2010		
    AC3Filter 1.63b	Alexander Vigovsky	31.10.2010		1.63b
    Acronis*True*Image*Home	Acronis	21.07.2010	122,3MB	12.0.9608
    ActiveTrader 5.0.0_b15		17.01.2011		
    Adobe AIR	Adobe Systems Incorporated	24.09.2011		2.7.1.19610
    Adobe Flash Player 10 ActiveX	Adobe Systems Incorporated	19.11.2010	2,68MB	10.1.82.76
    Adobe Flash Player 11 Plugin 64-bit	Adobe Systems Incorporated	01.11.2011	6,00MB	11.0.1.152
    Adobe Reader X (10.1.1) - Deutsch	Adobe Systems Incorporated	15.09.2011	119,0MB	10.1.1
    Airline Tycoon 2 Demo v1.01	Kalypso Media	27.10.2011	3.158MB	
    AnyDVD	SlySoft	11.10.2011		6.8.5.0
    Apple Application Support	Apple Inc.	27.10.2011	61,2MB	2.1.5
    Apple Mobile Device Support	Apple Inc.	22.11.2011	24,4MB	4.0.0.97
    Apple Software Update	Apple Inc.	09.10.2011	2,38MB	2.1.3.127
    ATI Catalyst Install Manager	ATI Technologies, Inc.	20.06.2010	22,3MB	3.0.778.0
    AudialsOne	RapidSolution Software AG	08.01.2011	356MB	4.2.13700.0
    Audiograbber 1.83 SE	Audiograbber Deutschland	19.08.2010		1.83 SE 
    Aura DVD Ripper Professional 1.3.8	aura4you.com	27.10.2011	100,5MB	
    Aura Software Manager 1.0.3	aura4you.com	27.10.2011	7,87MB	
    Avira Free Antivirus	Avira	02.12.2011	105,9MB	12.0.0.861
    AVM FRITZ!Box Dokumentation	AVM Berlin	12.08.2010		
    Biet-O-Matic v2.14.6	BOM Development Team	10.08.2010		Biet-O-Matic v2.14.6
    Bonjour	Apple Inc.	27.10.2011	2,04MB	3.0.0.10
    Camera RAW Plug-In for EPSON Creativity Suite	SEIKO EPSON CORPORATION	23.07.2010		2.2.0.0
    Canon G.726 WMP-Decoder	Canon Inc.	27.08.2011		1.1.0.4
    CANON iMAGE GATEWAY MyCamera Download Plugin	Canon Inc.	27.08.2011		3.1.1.2
    CANON iMAGE GATEWAY Task for ZoomBrowser EX	Canon Inc.	27.08.2011		1.9.0.9
    Canon Internet Library for ZoomBrowser EX	Canon Inc.	27.08.2011		1.6.2.7
    Canon MOV Decoder	Canon Inc.	27.08.2011		1.8.0.7
    Canon MOV Encoder	Canon Inc.	27.08.2011		1.7.0.3
    Canon MovieEdit Task for ZoomBrowser EX	Canon Inc.	27.08.2011		3.8.0.5
    Canon RAW Image Task for ZoomBrowser EX	Canon Inc.	27.08.2011		0.9.3.9
    Canon Utilities CameraWindow	Canon Inc.	27.08.2011		7.1.0.2
    Canon Utilities CameraWindow DC	Canon Inc.	27.08.2011		7.1.0.7
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX	Canon Inc.	27.08.2011		6.4.2.16
    Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX	Canon Inc.	27.08.2011		1.0.0.10
    Canon Utilities MyCamera	Canon Inc.	27.08.2011		6.4.0.5
    Canon Utilities MyCamera DC	Canon Inc.	27.08.2011		7.0.1.8
    Canon Utilities PhotoStitch	Canon Inc.	27.08.2011		3.1.21.45
    Canon Utilities RemoteCapture DC	Canon Inc.	27.08.2011		3.0.1.8
    Canon Utilities RemoteCapture Task for ZoomBrowser EX	Canon Inc.	27.08.2011		1.7.1.9
    Canon Utilities ZoomBrowser EX	Canon Inc.	27.08.2011		6.7.2.33
    Canon ZoomBrowser EX Memory Card Utility	Canon Inc.	27.08.2011		1.5.1.10
    CCleaner	Piriform	03.12.2011		3.13
    CD Audio Reader Filter (remove only)		31.10.2010		
    ClearProg 1.6.0 Final	Sven Hoffman	18.11.2010		1.6.0 Final
    CloneCD	SlySoft	26.08.2010		
    CloneDVD2	Elaborate Bytes	26.08.2010		
    Crysis® 2	Electronic Arts	17.06.2011	7.757MB	1.0.0.0
    DCoder Image Source (remove only)		31.10.2010		
    DivX-Setup	DivX, Inc. 	03.09.2010		2.0.4.2
    Dropbox	Dropbox, Inc.	20.07.2011		1.1.35
    DScaler 5 Mpeg Decoders		31.10.2010		
    ElsterFormular	Landesfinanzdirektion Thüringen	03.10.2011	140.139MB	12.4.0.7094k
    Emergency 3		15.08.2011		1.00.000
    Emergency4		24.06.2011		1.03.001
    EPSON Attach To Email	SEIKO EPSON	23.07.2010	1,08MB	1.01.0000
    EPSON Copy Utility 3		23.07.2010		3.3.0.0
    Epson Easy Photo Print 2	SEIKO EPSON CORPORATION	23.07.2010		2.2.0.0
    Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)	SEIKO EPSON CORPORATION	23.07.2010		1.00.0000
    EPSON File Manager		23.07.2010		1.3.0.0
    EPSON Print CD		23.07.2010		1.60.000
    EPSON Scan		23.07.2010		
    EPSON Scan Assistant		23.07.2010		1.10.00
    EPSON-Drucker-Software	SEIKO EPSON Corporation	23.07.2010		
    EPU-4 Engine		20.07.2010		1.01.02
    Eudora		31.07.2010		7.0
    EudoraProject.de		20.06.2010		
    Falk Navi-Manager	Falk Navigation GmbH	09.06.2011		2.6.2
    FFMPEG Core Files (remove only)		31.10.2010		
    FIFA Fussball-Weltmeisterschaft 2006 (TM)		24.07.2010		
    FormatFactory 2.60	Free Time	12.02.2011		2.60
    Foxit Reader	Foxit Corporation	16.07.2011	11,2MB	4.3.1.118
    Free Download Manager 3.0	FreeDownloadManager.ORG	11.06.2011		
    Free Studio version 5.2.0	DVDVideoSoft Ltd.	09.09.2011	333MB	
    Free Video Dub version 1.8	DVDVideoSoft Limited.	07.09.2010	22,8MB	
    Freez FLV to AVI/MPEG/WMV Converter	www.smallvideosoft.com	13.08.2010		1.6
    GameCenter		24.07.2010		
    GetFoldersize 2.3.2	Michael Thummerer Software Design	30.10.2010	6,54MB	2.3.2
    Google Earth	Google	16.11.2011	92,7MB	6.1.0.5001
    Haufe iDesk-Browser	Haufe-Lexware GmbH & Co. KG	19.11.2010	26,7MB	10.10.14.0000
    Haufe iDesk-Service	Haufe	20.11.2011	137,3MB	11.07.19.8023
    HijackThis 2.0.2	TrendMicro	14.10.2010		2.0.2
    HTC BMP USB Driver	HTC	20.02.2011	0,28MB	1.0.5375
    HTC Driver Installer	HTC Corporation	24.09.2011	1,90MB	3.0.0.013
    HTC Sync	HTC Corporation	24.09.2011	44,4MB	3.0.5579
    iCloud	Apple Inc.	12.11.2011	32,4MB	1.0.1.29
    IrfanView (remove only)	Irfan Skiljan	24.07.2010	1,50MB	4.27
    iTunes	Apple Inc.	22.11.2011	170,5MB	10.5.1.42
    Java(TM) 6 Update 21 (64-bit)	Oracle	24.07.2010	90,5MB	6.0.210
    Java(TM) 6 Update 22	Oracle	17.08.2010	94,9MB	6.0.220
    K-Lite Codec Pack 5.7.0 (Full)		20.06.2010	47,9MB	5.7.0
    Lexware buchhalter 2012	Haufe-Lexware GmbH & Co.KG	20.11.2011	323MB	17.00.00.0109
    Lexware Datenbank plus 2011	Haufe-Lexware GmbH & Co.KG	20.11.2011	243MB	11.00.00.0074
    Lexware Elster	Haufe-Lexware GmbH & Co.KG	20.11.2011	76,8MB	11.00.00.0109
    Lexware Info Service	Haufe-Lexware GmbH & Co.KG	20.11.2011	15,8MB	2.80.00.0007
    Lexware online banking	Haufe-Lexware GmbH & Co.KG	20.11.2011	25,2MB	11.00.00.0039
    Lexware reisekosten plus 2011	Haufe-Lexware GmbH & Co.KG	20.11.2011	427MB	11.22.00.0124
    Malwarebytes' Anti-Malware Version 1.51.2.1300	Malwarebytes Corporation	02.12.2011	13,8MB	1.51.2.1300
    Microsoft .NET Framework 4 Client Profile	Microsoft Corporation	20.07.2010	38,8MB	4.0.30319
    Microsoft .NET Framework 4 Client Profile DEU Language Pack	Microsoft Corporation	20.07.2010	2,94MB	4.0.30319
    Microsoft Flight Simulator X: Acceleration	Microsoft Game Studios	26.01.2011		10.0.61637.0
    Microsoft Games for Windows - LIVE Redistributable	Microsoft Corporation	05.05.2011	31,3MB	3.5.88.0
    Microsoft Games for Windows Marketplace	Microsoft Corporation	05.05.2011	6,04MB	3.5.50.0
    Microsoft Office File Validation Add-In	Microsoft Corporation	14.09.2011	7,95MB	14.0.5130.5003
    Microsoft Office Home and Student 2007	Microsoft Corporation	24.07.2010		12.0.6425.1000
    Microsoft Office Word Viewer 2003	Microsoft Corporation	14.09.2011	63,8MB	11.0.8173.0
    Microsoft Silverlight	Microsoft Corporation	12.10.2011	40,5MB	4.0.60831.0
    Microsoft Visual C++ 2005 Redistributable	Microsoft Corporation	15.06.2011	0,29MB	8.0.56336
    Microsoft Visual C++ 2005 Redistributable (x64)	Microsoft Corporation	24.09.2011	0,68MB	8.0.61000
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148	Microsoft Corporation	25.07.2010	0,20MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729	Microsoft Corporation	26.07.2010	0,25MB	9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148	Microsoft Corporation	20.06.2010	0,77MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161	Microsoft Corporation	15.06.2011	0,77MB	9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022	Microsoft Corporation	06.04.2011	1,42MB	9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729	Microsoft Corporation	24.07.2010	0,59MB	9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17	Microsoft Corporation	20.11.2011	0,22MB	9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148	Microsoft Corporation	28.07.2010	0,58MB	9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161	Microsoft Corporation	15.06.2011	0,59MB	9.0.30729.6161
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219	Microsoft Corporation	10.08.2011	13,8MB	10.0.40219
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219	Microsoft Corporation	10.08.2011	15,0MB	10.0.40219
    Microsoft WSE 3.0 Runtime	Microsoft Corp.	19.11.2010	0,92MB	3.0.5305.0
    Mozilla Firefox 8.0 (x86 de)	Mozilla	08.11.2011	37,4MB	8.0
    Mp3tag v2.48	Florian Heidenreich	23.02.2011		v2.48
    MSXML 4.0 SP2 (KB954430)	Microsoft Corporation	20.06.2010	1,28MB	4.20.9870.0
    MSXML 4.0 SP2 (KB973688)	Microsoft Corporation	20.06.2010	1,33MB	4.20.9876.0
    MSXML 4.0 SP2 Parser und SDK	Microsoft Corporation	24.07.2010	48,00KB	4.20.9818.0
    MSXML 4.0 SP3 Parser	Microsoft Corporation	20.02.2011	1,48MB	4.30.2100.0
    MSXML 4.0 SP3 Parser (KB973685)	Microsoft Corporation	21.02.2011	1,53MB	4.30.2107.0
    MyPhoneExplorer	F.J. Wechselberger	20.02.2011		1.8.0
    Nero 9	Nero AG	13.08.2010		
    NVIDIA Drivers	NVIDIA Corporation	27.08.2011	5,26MB	1.10.62.40
    NVIDIA ForceWare Network Access Manager	NVIDIA Corporation	10.08.2010	34,2MB	1.00.7316
    NVIDIA PhysX	NVIDIA Corporation	29.03.2011	80,1MB	9.10.0222
    OpenSource AVI Splitter (remove only)		31.10.2010		
    OpenSource DTS/AC3/DD+ Source Filter (remove only)		31.10.2010		
    Origin	Electronic Arts, Inc.	17.06.2011		8.1.2.444
    PC Connectivity Solution	Nokia	07.08.2010	15,0MB	8.15.0.0
    PDFCreator	Frank Heindörfer, Philip Chinery	14.08.2010		1.0.1
    PixiePack Codec Pack	None	08.01.2011	17,2MB	1.1.1200.0
    PMDG 747-400/400F for FSX	Precision Manuals Development Group	06.04.2011		2.10.0000
    PMDG744X_GE_KL	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744X_GE_LH	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744X_PW_NW3	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744X_RR_BA	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744XF_PW_FXF	Precision Manuals Development Group	06.04.2011		1.00.0000
    PMDG744XF_RR_CXF	Precision Manuals Development Group	06.04.2011		1.00.0000
    QuickTime	Apple Inc.	27.10.2011	73,3MB	7.71.80.42
    RealMedia (remove only)		31.10.2010		
    RealPlayer	RealNetworks	12.02.2011		
    Realtek HDMI Audio Driver for ATI	Realtek Semiconductor Corp.	20.07.2010		6.0.1.5945
    RENESIS® Player Browser Plugins	examotion® GmbH	26.09.2010	1,83MB	1.1.1
    Revo Uninstaller 1.93	VS Revo Group	09.10.2011		1.93
    Safari	Apple Inc.	27.10.2011	43,2MB	5.34.51.22
    Secure Eraser v4.0	ASCOMP Software GmbH	30.07.2011	10,5MB	
    SHOUTcast Source (remove only)		31.10.2010		
    Sophos Anti-Rootkit 1.5.20	Sophos Plc	02.12.2011		1.5.20
    SpeedFan (remove only)		24.07.2010		
    StarMoney 8.0	Star Finanz GmbH	04.04.2011		8.0
    TAXMAN 2010	Haufe-Lexware GmbH & Co. KG	20.11.2011	473MB	16.12.00.0003
    TAXMAN 2011	Haufe-Lexware GmbH & Co.KG	20.11.2011	669MB	17.05.00.0003
    TAXMAN 2012	Haufe-Lexware GmbH & Co.KG	20.11.2011	487MB	18.00.00.0061
    TAXMAN Bibliothek 2011	Haufe-Lexware GmbH & Co. KG	01.02.2011	444MB	17.10.0.0
    TAXMAN Bibliothek 2012	Haufe-Lexware GmbH & Co. KG	20.11.2011	464MB	18.0.0.0
    TIPP10 Version 2.1.0	(c) 2006-2011, Tom Thielicke IT Solutions	19.11.2011		
    TuneUp Utilities 2011	TuneUp Software	15.06.2011		10.0.4200.96
    TV-Browser 3.0-beta2		24.07.2010		3.0-beta2
    UBitMenuDE	UBit Schweiz AG	08.08.2010		01.04
    Uninstall 1.0.0.1		23.02.2011	10,4MB	
    UpdateYeti	Abelssoft GmbH	26.08.2011	17,9MB	2.0
    VIA Plattform-Geräte-Manager	VIA Technologies, Inc.	20.06.2010	2,62MB	1.34
    Visual C++ 8.0 Runtime Setup Package (x64)	AVG Technologies CZ, s.r.o.	20.06.2010	2,24MB	9.0.0.623
    VLC media player 1.0.5	VideoLAN Team	20.07.2010		1.0.5
    Windows Live ID Sign-in Assistant	Microsoft Corporation	28.01.2011	10,0MB	6.500.3165.0
    Windows Media Player Firefox Plugin	Microsoft Corp	24.07.2010	0,29MB	1.0.0.8
    Windows Mobile-Gerätecenter	Microsoft Corporation	09.06.2011	27,4MB	6.1.6965.0
    Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)	Nokia	07.08.2010		10/12/2007 6.85.4.0
    WinRAR		02.11.2010		
    XMedia Recode 3.0.2.5	Sebastian Dörfler	09.09.2011		3.0.2.5
    XnView 1.97	Gougelet Pierre-e	20.06.2010		1.97
    Zoom Player (remove only)		31.10.2010		
    Zoom Player deutsche Sprachdateien (entfernen)		31.10.2010
    Code:
    OTL logfile created on: 04.12.2011 13:49:04 - Run 3
    OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Peter\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
     
    4,00 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 59,58% Memory free
    8,00 Gb Paging File | 6,07 Gb Available in Paging File | 75,92% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 100,01 Gb Total Space | 44,07 Gb Free Space | 44,07% Space Free | Partition Type: NTFS
    Drive D: | 831,50 Gb Total Space | 682,19 Gb Free Space | 82,04% Space Free | Partition Type: NTFS
     
    Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Processes (SafeList) ==========
     
    PRC - [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    PRC - [2011.11.09 17:21:35 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2011.10.19 16:56:01 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    PRC - [2011.10.19 16:55:48 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2011.10.19 16:55:48 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    PRC - [2011.10.06 03:34:56 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    PRC - [2011.09.12 08:58:19 | 000,688,648 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) -- C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
    PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2011.08.22 09:01:00 | 000,593,920 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    PRC - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2011.05.25 21:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2010.11.05 10:28:14 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
     
     
    ========== Modules (No Company Name) ==========
     
    MOD - [2011.11.09 17:21:34 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    MOD - [2011.11.02 20:52:06 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    MOD - [2011.10.13 11:24:10 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f8196c3588c2229e84516af4b6a0ee60\System.Data.ni.dll
    MOD - [2011.10.13 11:23:35 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
    MOD - [2011.10.13 11:23:32 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
    MOD - [2011.10.13 11:23:32 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
    MOD - [2011.10.13 11:23:28 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
    MOD - [2011.09.27 06:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011.09.27 06:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011.08.22 09:01:00 | 001,515,520 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll
    MOD - [2011.08.22 09:01:00 | 000,593,920 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    MOD - [2011.08.22 09:01:00 | 000,559,244 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dll
    MOD - [2011.08.22 09:01:00 | 000,516,599 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll
    MOD - [2011.08.22 09:01:00 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\HtcDetect.dll
    MOD - [2011.08.22 09:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll
    MOD - [2011.08.22 09:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll
    MOD - [2011.08.22 09:01:00 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll
    MOD - [2010.11.13 01:08:41 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
    MOD - [2010.11.05 02:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
     
     
    ========== Win32 Services (SafeList) ==========
     
    SRV:64bit: - [2011.06.06 16:49:50 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
    SRV:64bit: - [2010.05.27 17:59:40 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV - [2011.10.19 16:56:01 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2011.10.19 16:55:48 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2011.09.12 08:58:19 | 000,688,648 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Running] -- C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
    SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2011.08.12 16:13:26 | 000,087,040 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
    SRV - [2011.06.06 16:54:54 | 002,026,304 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
    SRV - [2011.06.06 16:49:44 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
    SRV - [2011.06.06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
    SRV - [2010.11.20 13:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
    SRV - [2010.11.20 13:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
    SRV - [2010.11.05 10:28:14 | 000,083,248 | ---- | M] (iAnywhere Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -- (Lexware_Datenbank_Plus)
    SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009.08.10 15:01:06 | 000,206,880 | ---- | M] () [Auto | Running] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
    SRV - [2009.08.10 15:01:04 | 000,626,208 | ---- | M] () [Auto | Running] -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
    SRV - [2009.06.18 14:19:30 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008.10.03 21:41:22 | 000,743,192 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
    SRV - [2008.04.07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2007.05.31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
    SRV - [2007.05.31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV:64bit: - [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR162.SYS -- (SMR162)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,130,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
    DRV:64bit: - [2011.10.19 16:56:15 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
    DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
    DRV:64bit: - [2011.05.12 14:03:12 | 000,006,144 | ---- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\9645.tmp -- (MEMSWEEP2)
    DRV:64bit: - [2011.05.10 07:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010.12.16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
    DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010.08.12 11:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
    DRV:64bit: - [2010.07.22 16:02:35 | 001,580,576 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm140.sys -- (tdrpman140) Acronis Try&Decide and Restore Points filter (build 140)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,880,160 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
    DRV:64bit: - [2010.07.22 16:02:32 | 000,083,488 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\tifsfilt.sys -- (tifsfilter)
    DRV:64bit: - [2010.07.22 16:02:30 | 000,237,600 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380)
    DRV:64bit: - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
    DRV:64bit: - [2010.05.27 18:39:12 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2010.05.27 17:25:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2010.04.13 08:04:38 | 001,270,784 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
    DRV:64bit: - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
    DRV:64bit: - [2009.09.25 09:13:26 | 000,205,440 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
    DRV:64bit: - [2009.07.17 00:51:54 | 000,028,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvamacpi.sys -- (nvamacpi)
    DRV:64bit: - [2009.07.16 11:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
    DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
    DRV:64bit: - [2009.06.10 21:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
    DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009.02.03 16:46:14 | 000,077,952 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfsync04.sys -- (sfsync04) StarForce Protection Synchronization Driver (version 4.x)
    DRV:64bit: - [2009.02.03 16:40:13 | 000,077,432 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
    DRV:64bit: - [2007.09.17 14:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
    DRV:64bit: - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV:64bit: - [2007.02.08 18:47:24 | 000,107,384 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
    DRV:64bit: - [2006.06.14 15:58:10 | 000,014,192 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
    DRV - [2011.07.28 11:27:17 | 000,138,872 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
    DRV - [2010.08.19 21:08:04 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
    DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2007.02.16 01:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys -- (ElbyCDFL)
    DRV - [2007.02.07 19:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
     
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.kiebel.de
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2206084
    IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - No CLSID value found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
     
    ========== FireFox ==========
     
     
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
    FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
     
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.02.13 14:39:39 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.09 17:21:35 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.10.28 22:22:57 | 000,000,000 | ---D | M]
     
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions
    [2010.11.20 19:32:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions
    [2011.02.24 21:00:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    [2011.11.11 11:47:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\jyhzdx6r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2011.11.09 17:21:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
    [2011.11.09 17:21:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2008.06.19 10:16:24 | 000,118,784 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\MyCamera.dll
    [2008.06.19 10:16:24 | 000,053,248 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\mozilla firefox\plugins\NPCIG.dll
    [2010.09.15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2011.10.08 17:38:48 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
    [2011.10.08 17:38:48 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011.10.08 17:38:48 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
    [2011.10.08 17:38:48 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
    [2011.10.08 17:38:48 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
    [2011.10.08 17:38:48 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
     
    O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
    O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
    O3:64bit: - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
    O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
    O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
    O4 - HKCU..\Run: [Personal ID] C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE (coolspot AG, Düsseldorf)
    O4 - Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    F3:64bit: - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) -  File not found
    F3 - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) - File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8:64bit: - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8:64bit: - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8:64bit: - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8:64bit: - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8:64bit: - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O8 - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta ()
    O8 - Extra context menu item: Alles mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlall.htm ()
    O8 - Extra context menu item: Auswahl mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlselected.htm ()
    O8 - Extra context menu item: Datei mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dllink.htm ()
    O8 - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
    O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
    O8 - Extra context menu item: Videos mit FDM herunterladen - D:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
    O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Domains: amazon.de ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
    O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87F7A994-F44E-4345-B88E-03ECE07BAB9D}: DhcpNameServer = 192.168.178.1
    O18:64bit: - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\haufereader - No CLSID value found
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O27:64bit: - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27:64bit: - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realconverter.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realplay.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\realtrimmer.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O27 - HKLM IFEO\rnxproc.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe (TuneUp Software)
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
     
    ========== Files/Folders - Created Within 30 Days ==========
     
    [2011.12.03 17:13:07 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\Temp
    [2011.12.03 17:11:18 | 000,000,000 | ---D | C] -- C:\.Trash-999
    [2011.12.03 14:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
    [2011.12.03 14:20:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
    [2011.12.03 14:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2011.12.03 13:47:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 12:59:25 | 000,090,232 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2011.12.03 12:59:22 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\NPE
    [2011.12.03 12:59:01 | 006,161,912 | ---- | C] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 01:09:34 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Avira
    [2011.12.03 01:09:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
    [2011.12.03 01:09:11 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
    [2011.12.03 01:09:11 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
    [2011.12.03 01:09:11 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
    [2011.12.03 01:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
    [2011.11.23 14:54:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2011.11.23 14:54:25 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2011.11.23 14:52:48 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2011.11.21 15:35:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DataDesign
    [2011.11.21 15:33:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sybase
    [2011.11.20 21:20:12 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\TIPP10
    [2011.11.20 21:20:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIPP10
    [2011.11.17 17:21:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011.11.13 13:55:16 | 000,000,000 | ---D | C] -- C:\Users\Peter\Desktop\Games
    [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
     
    ========== Files - Modified Within 30 Days ==========
     
    [2011.12.04 13:52:17 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    [2011.12.04 13:51:33 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011.12.04 13:51:33 | 000,019,904 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011.12.04 13:48:22 | 001,766,796 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2011.12.04 13:48:22 | 000,759,454 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
    [2011.12.04 13:48:22 | 000,703,364 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2011.12.04 13:48:22 | 000,169,072 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
    [2011.12.04 13:48:22 | 000,137,512 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2011.12.04 13:44:04 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011.12.04 13:44:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011.12.04 13:41:22 | 000,080,709 | ---- | M] () -- C:\Users\Peter\Desktop\warn.jpg
    [2011.12.03 17:20:14 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011.12.03 13:47:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
    [2011.12.03 13:46:48 | 000,000,000 | ---- | M] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 12:59:31 | 000,000,761 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:59:25 | 000,090,232 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR162.SYS
    [2011.12.03 12:59:08 | 006,161,912 | ---- | M] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.03 12:58:02 | 000,883,840 | ---- | M] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:09:26 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 01:02:28 | 084,419,032 | ---- | M] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.12.03 00:58:18 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.11.23 14:54:54 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:53:19 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2011.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | M] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | M] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | M] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | M] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.13 13:55:12 | 000,000,628 | ---- | M] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.09 17:08:21 | 000,350,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
     
    ========== Files Created - No Company Name ==========
     
    [2011.12.04 13:41:22 | 000,080,709 | ---- | C] () -- C:\Users\Peter\Desktop\warn.jpg
    [2011.12.03 13:46:48 | 000,000,000 | ---- | C] () -- C:\Users\Peter\defogger_reenable
    [2011.12.03 12:59:31 | 000,000,761 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\SMRBackup162.dat
    [2011.12.03 12:58:09 | 000,883,840 | ---- | C] () -- C:\Users\Peter\Desktop\Avira-DE-Cleaner.exe
    [2011.12.03 01:09:26 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
    [2011.12.03 00:58:18 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2011.12.03 00:57:41 | 084,419,032 | ---- | C] () -- C:\Users\Peter\Desktop\avira_free_antivirus_de.exe
    [2011.11.23 14:54:54 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2011.11.21 15:48:16 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2010.lnk
    [2011.11.21 15:34:49 | 000,000,153 | ---- | C] () -- C:\Windows\ODBC.INI
    [2011.11.21 15:19:38 | 000,002,319 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN Bibliothek 2012.lnk
    [2011.11.21 15:18:43 | 000,002,669 | ---- | C] () -- C:\Users\Public\Desktop\TAXMAN 2012.lnk
    [2011.11.21 09:38:34 | 000,096,102 | ---- | C] () -- C:\Users\Peter\Desktop\TV Ticket Service_ Eintrittskarten für Fernseh-Sendungen.pdf
    [2011.11.20 21:20:11 | 000,000,692 | ---- | C] () -- C:\Users\Peter\Desktop\TIPP10.lnk
    [2011.11.17 17:21:42 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011.11.13 13:55:12 | 000,000,628 | ---- | C] () -- C:\Windows\SysNative\mapisvc.inf
    [2011.11.08 10:56:09 | 005,133,509 | ---- | C] () -- C:\Users\Peter\Desktop\IMG_8450.JPG
    [2011.09.27 11:17:26 | 000,198,144 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll
    [2011.09.27 11:16:20 | 000,304,128 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll
    [2011.09.27 11:14:14 | 000,133,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll
    [2011.09.27 11:13:58 | 000,069,120 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll
    [2011.06.10 11:53:49 | 001,456,640 | ---- | C] () -- C:\Program Files (x86)\Common Files\Falk Navi-Manager.msi
    [2011.04.30 15:18:32 | 000,000,000 | ---- | C] () -- C:\Users\Peter\AppData\Local\{D431F69B-9F80-4998-8606-16B2FF4763C2}
    [2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
    [2011.02.13 15:06:41 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
    [2010.11.03 22:34:25 | 000,000,038 | ---- | C] () -- C:\Windows\osAviSplitter.INI
    [2010.10.21 14:18:46 | 000,303,104 | ---- | C] () -- C:\Windows\SysWow64\dnt27VC8.dll
    [2010.10.21 14:16:58 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\dntvmc27VC8.dll
    [2010.10.21 14:16:34 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dntvm27VC8.dll
    [2010.10.17 19:03:42 | 001,653,284 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2010.09.24 12:27:18 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
    [2010.08.27 16:22:42 | 000,000,123 | -HS- | C] () -- C:\ProgramData\.zreglib
    [2010.08.19 16:11:13 | 000,003,314 | ---- | C] () -- C:\Windows\cdplayer.ini
    [2010.08.14 18:02:08 | 008,676,883 | ---- | C] () -- C:\Windows\SysWow64\NCMedia2.dll
    [2010.08.14 13:07:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2010.08.14 12:46:47 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
    [2010.08.11 19:14:48 | 000,015,873 | ---- | C] () -- C:\Windows\SysWow64\Inetde.dll
    [2010.08.01 15:26:08 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2010.07.25 18:27:31 | 000,027,648 | ---- | C] () -- C:\Users\Peter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010.07.25 13:49:01 | 000,000,130 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\default.rss
    [2010.07.24 20:05:40 | 000,111,932 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
    [2010.07.24 20:05:40 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
    [2010.07.24 20:05:40 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
    [2010.07.24 20:05:40 | 000,026,154 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
    [2010.07.24 20:05:40 | 000,024,903 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
    [2010.07.24 20:05:40 | 000,021,390 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
    [2010.07.24 20:05:40 | 000,020,148 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
    [2010.07.24 20:05:40 | 000,011,811 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
    [2010.07.24 20:05:40 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
    [2010.07.24 20:05:40 | 000,001,146 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_DU.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
    [2010.07.24 20:05:40 | 000,001,139 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
    [2010.07.24 20:05:40 | 000,001,136 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
    [2010.07.24 20:05:40 | 000,001,129 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
    [2010.07.24 20:05:40 | 000,001,120 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_IT.dat
    [2010.07.24 20:05:40 | 000,001,107 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_GE.dat
    [2010.07.24 20:05:40 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
    [2010.07.24 20:05:40 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
    [2010.06.21 12:08:08 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2010.06.21 12:03:04 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
    [2010.06.21 12:03:04 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
    [2010.06.21 12:03:01 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
    [2010.06.21 12:03:01 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
    [2010.06.21 11:29:41 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010.06.21 11:29:41 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
    [2010.06.21 11:29:40 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
    [2010.06.21 11:29:40 | 000,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
    [2010.04.29 16:37:26 | 000,002,137 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2009.11.25 13:40:50 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
    [2009.09.30 11:05:48 | 000,290,816 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v60.dll
    [2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2008.10.30 17:00:22 | 000,048,640 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v60.dll
    [2008.10.30 16:59:24 | 000,025,088 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v60.dll
    [2006.04.21 09:08:22 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\HtmlHelp.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v50.dll
    [2004.12.14 16:55:22 | 000,000,019 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v50.dll
     
    ========== LOP Check ==========
     
    [2011.08.27 09:53:16 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Abelssoft
    [2010.08.23 18:44:52 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Acronis
    [2010.11.04 20:14:37 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\ASCOMP Software
    [2011.10.28 21:04:07 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Aura4You
    [2010.10.20 16:37:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Bioshock2
    [2010.08.12 23:07:50 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\BOM
    [2011.12.04 13:44:46 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Dropbox
    [2011.10.28 20:44:03 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DVDVideoSoft
    [2011.02.24 21:00:08 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers
    [2011.10.28 20:40:05 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\E-Zsoft
    [2011.10.04 17:49:02 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\elsterformular
    [2010.07.24 20:16:41 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\EPSON
    [2011.07.17 20:04:06 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Foxit Software
    [2011.10.29 15:58:57 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Free Download Manager
    [2011.10.25 20:26:07 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Free iPad Video Converter
    [2010.10.31 19:56:53 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GetFoldersize
    [2010.11.19 11:07:17 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GetRightToGo
    [2011.02.25 17:02:48 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\HandBrake
    [2010.11.20 19:32:46 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Haufe Mediengruppe
    [2011.09.25 13:32:09 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\HTC
    [2011.02.21 21:43:44 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
    [2010.07.25 16:54:20 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\IrfanView
    [2011.01.31 19:43:31 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Lexware
    [2011.02.24 21:21:48 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Mp3tag
    [2011.10.28 20:34:52 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\MPEG Streamclip
    [2011.02.21 21:58:18 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\MyPhoneExplorer
    [2010.11.04 23:24:35 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\OfficeRecovery
    [2010.07.22 15:51:03 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\OpenOffice.org
    [2010.08.08 16:42:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\PC Suite
    [2010.11.19 19:48:37 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Privacy Guardian
    [2010.07.25 13:17:54 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Qualcomm
    [2010.08.08 16:42:31 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Samsung
    [2011.11.20 21:22:39 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TIPP10
    [2010.11.24 19:26:40 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TuneUp Software
    [2011.11.25 13:24:39 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TV-Browser
    [2010.08.09 19:35:55 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\UBitMenu
    [2011.08.26 15:15:38 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Utherverse
    [2011.09.10 17:43:06 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\XMedia Recode
    [2011.11.30 20:53:41 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\XnView
    [2011.11.21 09:04:43 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
     
    ========== Purity Check ==========
     
     
     
    ========== Alternate Data Streams ==========
     
    @Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:96D0C06F
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:42D9E231
    
    < End of report >
    Code:
    OTL Extras logfile created on: 04.12.2011 13:49:04 - Run 3
    OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Peter\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
     
    4,00 Gb Total Physical Memory | 2,38 Gb Available Physical Memory | 59,58% Memory free
    8,00 Gb Paging File | 6,07 Gb Available in Paging File | 75,92% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 100,01 Gb Total Space | 44,07 Gb Free Space | 44,07% Space Free | Partition Type: NTFS
    Drive D: | 831,50 Gb Total Space | 682,19 Gb Free Space | 82,04% Space Free | Partition Type: NTFS
     
    Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Extra Registry (SafeList) ==========
     
     
    ========== File Associations ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
     
    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
     
    ========== Shell Spawning ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
     
    ========== Security Center Settings ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
     
    ========== Firewall Settings ==========
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
     
    ========== Authorized Applications List ==========
     
     
    ========== HKEY_LOCAL_MACHINE Uninstall List ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
    "{2016B2AD-0051-05C7-9CCB-CE9F05659CB7}" = ccc-utility64
    "{25D04DBB-FE9D-E3BA-C2F3-F1BE9B8C0709}" = ATI Catalyst Install Manager
    "{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java(TM) 6 Update 21 (64-bit)
    "{4B55F339-396E-29A9-B6D0-24B6D251C90A}" = AMD Drag and Drop Transcoding
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile-Gerätecenter
    "{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
    "{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
    "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
    "{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
    "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{D285FC5F-3021-32E9-9C59-24CA325BDC5C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
    "{EC8A40B2-096A-4EA4-B11A-167F87F293A7}" = iCloud
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
    "BC15EA930074932BB2C4B4493C9FD4EA95087D1A" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
    "CCleaner" = CCleaner
    "EPSON Printer and Utilities" = EPSON-Drucker-Software
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
    "NVIDIA Drivers" = NVIDIA Drivers
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{0197D136-598D-4968-BEEA-91C1B764F05D}" = Lexware buchhalter 2012
    "{02627EE5-EACA-4742-A9CC-E687631773E4}" = Nero ShowTime
    "{086A7D8C-0A38-4C7F-819A-620275550D5C}" = Nero Burning ROM Help
    "{0CA1005F-B640-0354-EC82-F8F7447A8E8A}" = CCC Help Hungarian
    "{0F32914F-A633-4516-B531-7084C8F19F93}" = Haufe iDesk-Browser
    "{0FC472C3-6A2A-969F-10E7-E8F61B18117C}" = Catalyst Control Center Localization All
    "{1923679F-C14B-4790-BC54-EFA3FCDE147B}" = Lexware Elster
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{1C00C7C5-E615-4139-B817-7F4003DE68C0}" = Nero PhotoSnap Help
    "{1D081AB0-B1CC-11E0-80C0-005056B12123}" = Haufe iDesk-Service
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1FCBD504-AB7D-4757-9A14-850348384B08}" = StarMoney
    "{20372FAA-3AF4-4B3D-9B1D-564CDEA5957C}" = PMDG744X_GE_LH
    "{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
    "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
    "{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
    "{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
    "{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 22
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
    "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
    "{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
    "{31405CA2-F009-D91B-FEFF-35924343CB14}" = Catalyst Control Center InstallProxy
    "{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
    "{31B75145-DF24-C759-E735-9C129956961E}" = CCC Help Spanish
    "{3222B0CE-59C5-4CA0-B545-2B88F200756B}" = Falk Navi-Manager
    "{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
    "{3526C5B8-60EE-4199-BEFD-6BCC86F051B9}" = TAXMAN 2011
    "{3563500D-85F7-48AE-A91D-811E92BA49BB}" = TAXMAN Bibliothek 2011
    "{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
    "{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
    "{37BC8FCE-15B1-456E-A62C-EEB175B71340}" = Lexware reisekosten plus 2011
    "{37C8899D-FD70-481F-94AA-1F1B08765E22}" = Acronis*True*Image*Home
    "{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}" = Epson Easy Photo Print 2
    "{406A89D6-09E6-4550-B370-8D376DDB56BE}" = Adobe Flash Player 10 ActiveX
    "{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
    "{50DFE454-6234-4BEB-BADF-0571CB9D2F13}" = AudialsOne
    "{54194F60-988C-4D03-B922-C2B00EFDA39A}" = NVIDIA PhysX
    "{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
    "{5454085C-840F-4070-8FAA-441000038301}" = BioShock 2
    "{5454085C-840F-4070-8FAA-441000038302}" = BioShock 2
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
    "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
    "{5C5B0836-9648-4057-8044-2DF181E073E2}" = TAXMAN 2010
    "{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE)
    "{5D9BE3C1-8BA4-4E7E-82FD-9F74FA6815D1}" = Nero Vision Help
    "{5E08ECD1-C98E-4711-BF65-8FD736B3F969}" = Nero RescueAgent Help
    "{5E453519-60F6-4A4D-A0BF-16663F9B3536}" = Safari
    "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
    "{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2
    "{60C731FB-C951-41CE-AD41-8E54C8594609}" = Nero Disc Copy Gadget Help
    "{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
    "{62B7C52C-CAB6-48B1-8245-52356C141C92}" = RENESIS® Player Browser Plugins
    "{63B9224A-89C9-44E6-8252-5F2F73A71C54}" = StarMoney
    "{641C1B16-FD4C-0F97-47AE-76637FC64225}" = CCC Help English
    "{65415AC9-0D2B-4A0F-9786-28748640F781}" = Falk Navi-Manager
    "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    "{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{77E33D87-255E-413E-9C8D-EED2A7F9BEBF}" = Nero Live Help
    "{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79C2D7F9-3BF8-52C1-6A7A-84C9296171F8}" = CCC Help German
    "{7B29E627-71A5-6824-3F85-DBEF19624BD0}" = ccc-core-static
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
    "{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
    "{85243696-5E58-4357-9CF8-3498C609941D}" = NeroLiveGadget Help
    "{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
    "{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
    "{879C52A2-FF9A-4CB5-BB74-B0DA994ABB2A}" = StarMoney
    "{88B2BB7B-A684-E8E3-65C6-DDC5DC152C2A}" = CCC Help French
    "{89196F9A-2E0B-4197-A3DF-6EF78731EB35}" = Lexware online banking
    "{89E0B0D4-DFC3-49B9-8E88-F1B801325C8A}" = Emergency 3
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial 
    "{8CB77076-DB66-5D92-7886-807226C9CE4B}" = CCC Help Italian
    "{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine
    "{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
    "{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
    "{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
    "{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
    "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
    "{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
    "{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
    "{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
    "{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{90850407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
    "{90C67C7D-E918-402C-9856-7B13999E1786}" = StarMoney
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{92633C0F-C9BE-41E3-B439-0B508F859DB5}" = StarMoney
    "{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite
    "{96E1C9EE-5109-41FA-B412-E3358626051D}" = PMDG744X_PW_NW3
    "{98A67610-A3B5-4098-A423-3708040026D3}" = "Nero SoundTrax Help
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9A4C534E-431F-4A17-97D4-D1682B19A054}" = Emergency4
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9C6F56DA-7051-6677-4E5A-9DC6C573F2B5}" = CCC Help Portuguese
    "{9C979BC5-0B86-47A1-B6C1-6057297DB61C}" = PMDG744X_RR_BA
    "{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
    "{9E9FDDE6-2C26-492A-85A0-05646B3F2795}" = NeroLiveGadget
    "{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}" = PixiePack Codec Pack
    "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{ABD462F9-7436-4086-A65B-AC6360ED45FC}" = PMDG744XF_RR_CXF
    "{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
    "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch
    "{AD6BC5CC-2EF0-49C4-B33D-CDC8B2C4DC80}" = Nero Recode Help
    "{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
    "{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
    "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
    "{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
    "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
    "{C3FA3CCE-2A88-0976-B875-4B3E9D41204D}" = Catalyst Control Center Graphics Previews Common
    "{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
    "{CBCFD97D-FE82-43F4-A978-996CACF71E6B}_is1" = UBitMenuDE
    "{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
    "{CE96F5A5-584D-4F8F-AA3E-9BAED413DB72}" = Nero CoverDesigner Help
    "{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
    "{D34A78EB-78F2-48ab-8CAE-5D4DC255A491}" = Lexware reisekosten plus 2011
    "{D4CF23EE-B0B6-4E5F-A335-8E63F8AFAC98}" = PMDG744X_GE_KL
    "{D54A0D86-35B0-BFC8-174B-D991EDF903B8}" = Catalyst Control Center Graphics Previews Vista
    "{D5610369-AF78-386F-4985-9822654973A3}" = CCC Help Polish
    "{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync
    "{d881334f-9d80-46b0-8374-d8f1145baeba}" = Nero 9
    "{D92F1880-822A-41CA-0090-451FBB89BF4C}" = FIFA Fussball-Weltmeisterschaft 2006 (TM)
    "{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
    "{DAF15921-FA90-4427-82A2-1852A9BAC99A}" = Lexware Datenbank plus 2011
    "{DF344785-0900-471E-B9F5-6F28C89AF638}" = TAXMAN Bibliothek 2012
    "{DF6A95F5-ADC1-406A-BDC6-2AA7CC0182AA}" = Nero Live
    "{E2062054-90AC-44F1-800E-DC4930F4DC9E}" = StarMoney 8.0 
    "{E2F2B987-F2BC-4969-95F2-92099486B811}" = StarMoney
    "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
    "{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
    "{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
    "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
    "{EDCEE320-0FB3-4197-9F86-8C1CCF2278FB}" = PMDG 747-400/400F for FSX
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
    "{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
    "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
    "{F3C2ECAA-1B4D-4B75-9105-106B0D03EF02}" = Lexware Info Service
    "{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
    "{F4443656-4EE4-42F8-81C4-709313BB3688}" = Eudora
    "{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
    "{F6BDD7C5-89ED-4569-9318-469AA9732572}" = Nero BurnRights Help
    "{F722209B-739E-40E4-ADB1-062BD032A0DB}" = Personal ID
    "{F77ABA68-8AC4-497E-9FFA-9CA4506B78FC}" = PMDG744XF_PW_FXF
    "{F77D44EB-2A6E-E2EE-7C30-40A5409B2650}" = CCC Help Greek
    "{FA3FDB06-3368-4579-B2F2-5AE8AD6E7871}" = TAXMAN 2012
    "{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
    "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
    "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "7-Zip" = 7-Zip 4.65
    "AC3Filter_is1" = AC3Filter 1.63b
    "Adobe AIR" = Adobe AIR
    "AirlineTycoon2-Demo_is1" = Airline Tycoon 2 Demo v1.01
    "AnyDVD" = AnyDVD
    "Audiograbber" = Audiograbber 1.83 SE 
    "Aura DVD Ripper Professional_is1" = Aura DVD Ripper Professional 1.3.8
    "Aura Software Manager_is1" = Aura Software Manager 1.0.3
    "Avira AntiVir Desktop" = Avira Free Antivirus
    "AVMFBox" = AVM FRITZ!Box Dokumentation
    "Biet-O-Matic v2.14.6" = Biet-O-Matic v2.14.6
    "CameraWindowDC" = Canon Utilities CameraWindow DC
    "CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    "CameraWindowLauncher" = Canon Utilities CameraWindow
    "Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
    "CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
    "Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
    "Canon MOV Decoder" = Canon MOV Decoder
    "Canon MOV Encoder" = Canon MOV Encoder
    "CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
    "ClearProg" = ClearProg 1.6.0 Final
    "CloneCD" = CloneCD
    "CloneDVD2" = CloneDVD2
    "DCoder Image Source" = DCoder Image Source (remove only)
    "DivX Setup.divx.com" = DivX-Setup
    "DScaler 5 Mpeg Decoders_is1" = DScaler 5 Mpeg Decoders
    "ElsterFormular 11.5.0.4546" = ElsterFormular
    "EOS Video Snapshot Task" = Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX
    "EPSON Scanner" = EPSON Scan
    "FFMPEG Core Files" = FFMPEG Core Files (remove only)
    "FlightSim_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Microsoft Flight Simulator X: Acceleration
    "FormatFactory" = FormatFactory 2.60
    "Foxit Reader" = Foxit Reader
    "Free Download Manager_is1" = Free Download Manager 3.0
    "Free Studio_is1" = Free Studio version 5.2.0
    "Free Video Dub_is1" = Free Video Dub version 1.8
    "Freez FLV to AVI/MPEG/WMV Converter v1.6_is1" = Freez FLV to AVI/MPEG/WMV Converter
    "GameCenter" = GameCenter
    "GetFoldersize_is1" = GetFoldersize 2.3.2
    "HijackThis" = HijackThis 2.0.2
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
    "InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
    "InstallShield_{F535B2CF-C9BB-4162-B03A-02D6971F32CC}" = Microsoft Flight Simulator X
    "IrfanView" = IrfanView (remove only)
    "KLiteCodecPack_is1" = K-Lite Codec Pack 5.7.0 (Full)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
    "MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
    "Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
    "Mp3tag" = Mp3tag v2.48
    "MPE" = MyPhoneExplorer
    "MyCamera" = Canon Utilities MyCamera
    "MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
    "MyCameraDC" = Canon Utilities MyCamera DC
    "OpenSource AVI Splitter" = OpenSource AVI Splitter (remove only)
    "OpenSource DTS/AC3/DD+ Source Filter" = OpenSource DTS/AC3/DD+ Source Filter (remove only)
    "Origin" = Origin
    "PhotoStitch" = Canon Utilities PhotoStitch
    "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
    "RealMedia" = RealMedia (remove only)
    "RealPlayer 12.0" = RealPlayer
    "RemoteCaptureDC" = Canon Utilities RemoteCapture DC
    "RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "RTMshadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X
    "Secure Eraser_is1" = Secure Eraser v4.0
    "SHOUTcast Source" = SHOUTcast Source (remove only)
    "Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.20
    "SP1_F535B2CF-C9BB-4162-B03A-02D6971F32CC" = Microsoft Flight Simulator X Service Pack 1
    "SP1shadow_{7D606567-5047-451A-B49E-29FCB6012B4E}" = Flight Simulator X Service Pack 1
    "SpeedFan" = SpeedFan (remove only)
    "TIPP10_is1" = TIPP10 Version 2.1.0
    "TuneUp Utilities 2011" = TuneUp Utilities 2011
    "tvbrowser" = TV-Browser 3.0-beta2
    "Uninstall_is1" = Uninstall 1.0.0.1
    "UpdateYeti_is1" = UpdateYeti
    "VLC media player" = VLC media player 1.0.5
    "WinRAR archiver" = WinRAR
    "XMedia Recode" = XMedia Recode 3.0.2.5
    "XnView_is1" = XnView 1.97
    "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
    "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
    "ZoomPlayer" = Zoom Player (remove only)
    "ZoomPlayerLang" = Zoom Player deutsche Sprachdateien (entfernen)
     
    ========== HKEY_CURRENT_USER Uninstall List ==========
     
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "A380v2 (FSX)" = A380v2 (FSX)
    "ActiveTrader 5.0.0_b15" = ActiveTrader 5.0.0_b15
    "Airbus Series Vol.2 (FS X)" = Airbus Series Vol.2 (FS X) ActiveTrader 5.0.0_b15
    
    "Dropbox" = Dropbox
     
    ========== Last 10 Event Log Errors ==========
     
    [ Application Events ]
    Error - 30.03.2011 14:53:01 | Computer Name = Peter-PC | Source = Application Error | ID = 1000
    Description = Name der fehlerhaften Anwendung: Metro2033.exe, Version: 1.0.0.1, 
    Zeitstempel: 0x4c7775b7  Name des fehlerhaften Moduls: Metro2033.exe, Version: 1.0.0.1,
     Zeitstempel: 0x4c7775b7  Ausnahmecode: 0xc0000005  Fehleroffset: 0x003e7ccb  ID des fehlerhaften
     Prozesses: 0xff8  Startzeit der fehlerhaften Anwendung: 0x01cbef0bab09bd20  Pfad der
     fehlerhaften Anwendung: D:\program files (x86)\steam\steamapps\common\metro 2033\Metro2033.exe
    Pfad
     des fehlerhaften Moduls: D:\program files (x86)\steam\steamapps\common\metro 2033\Metro2033.exe
    Berichtskennung:
     ef87a480-5afe-11e0-8e21-485b39af178a
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    Error - 31.03.2011 16:24:46 | Computer Name = Peter-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
    Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen
     Aktualisierungs-CAB-Datei bei <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
     Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum
     gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei.
    .
     
    [ System Events ]
    Error - 02.12.2011 20:08:42 | Computer Name = Peter-PC | Source = Service Control Manager | ID = 7001
    Description = Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der
     aufgrund folgenden Fehlers nicht gestartet wurde:   %%1068
     
    Error - 02.12.2011 20:08:49 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 02.12.2011 20:09:19 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 02.12.2011 20:11:43 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 02.12.2011 20:11:43 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 03.12.2011 08:15:35 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    Error - 03.12.2011 12:03:25 | Computer Name = Peter-PC | Source = DCOM | ID = 10010
    Description = 
     
    Error - 03.12.2011 12:14:42 | Computer Name = Peter-PC | Source = Service Control Manager | ID = 7009
    Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
     Windows Mobile-basierte Geräteverbindungen erreicht.
     
    Error - 03.12.2011 12:14:42 | Computer Name = Peter-PC | Source = Service Control Manager | ID = 7000
    Description = Der Dienst "Windows Mobile-basierte Geräteverbindungen" wurde aufgrund
     folgenden Fehlers nicht gestartet:   %%1053
     
    Error - 03.12.2011 12:14:42 | Computer Name = Peter-PC | Source = DCOM | ID = 10005
    Description = 
     
    [ TuneUp Events ]
    Error - 04.12.2010 06:43:07 | Computer Name = Peter-PC | Source = TuneUp.UtilitiesSvc | ID = 300
    Description = 
     
    Error - 04.12.2010 06:43:07 | Computer Name = Peter-PC | Source = TuneUp.UtilitiesSvc | ID = 300
    Description = 
     
    Error - 04.12.2010 06:43:07 | Computer Name = Peter-PC | Source = TuneUp.UtilitiesSvc | ID = 300
    Description = 
     
     
    < End of report >
    Malewarebyte: Kein Fund

  5. #5
    Moderator Team-Mitglied Avatar von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    28.352

    AW: Bundespolizei Trojaner seit gestern

    1.
    ALTE VERSION!!!:
    Code:
    Logfile of HijackThis 2.0.2 
    Die neue Version gibt es hier:
    also lösche/deinstalliere HijackThis "2.0.2." und lade Dir erneut von hier TrendMicro™ HijackThis™/Version 2.0.4 herunter, poste das neue Logfile
    - Keine offenen Fenster, solang bis HijackThis läuft!!

    2.
    Java aktualisieren- über Systemsteuerung-> Nach Update suchen...
    Deine Javaversion ist nicht aktuell.
    Downloade nun die Offline-Version von Java Version 6 Update 29 von Oracle und installiere sie. Achte darauf, eventuell angebotene Toolbars nicht mitzuinstallieren, also während der Installation den Haken bei der Toolbar entfernen.

    3.
    Achtung wichtig!:
    Falls Du selber im Logfile Änderungen vorgenommen hast, musst Du durch die Originalbezeichnung ersetzen und so in Script einfügen! sonst funktioniert nicht!
    (Benutzerordner, dein Name oder sonstige Änderungen durch X, Stern oder andere Namen ersetzt)
    Fixen mit OTL
    • Starte die OTL.exe.
    • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
    • Kopiere folgendes Skript (unverändert inkl. :OTL):
    Code:
    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2206084
    IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - No CLSID value found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    [2011.10.08 17:38:48 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2011.10.08 17:38:48 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    F3:64bit: - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) -  File not found
    F3 - HKCU WinNT: Load - (C:\Users\Peter\AppData\Local\Temp\AF82B87C9F73BFD328A8.exe) - File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\haufereader - No CLSID value found
    [2011.12.03 14:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2011.12.03 12:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2011.12.03 12:59:01 | 006,161,912 | ---- | C] (Symantec Corporation) -- C:\Users\Peter\Desktop\de_cleaner.exe
    [2011.12.04 13:44:04 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011.12.03 17:20:14 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    @Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:96D0C06F
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:42D9E231
    
    :Commands
    [purity]
    [emptytemp]
    • und füge es hier ein:
    • Schließe alle Programme.
    • Klicke auf den Fix Button.
    • Klick auf .
    • OTL verlangt einen Neustart. Bitte zulassen.
    • Nach dem Neustart findest Du ein Textdokument.
      Kopiere den Inhalt hier in Code-Tags in Deinen Thread.


    4.
    Öffne CCleaner - Anleitung CCleaner
    • "Cleaner"->"Analysieren"->Klick auf den Button "Start CCleaner"
    • "Registry""Fehler suchen"-> "Fehler beheben"->"Alle beheben"
    • Starte dein System neu auf


    5.
    Systemreinigung und Prüfung:
    Anleitung:-> Grundreinigung mit SUPERAntiSpyware

    6.
    ♦ Schon seit langem gehört "Worm.Win32.Autorun" zu den beliebtesten Verbreitungswegen von Viren, sollte man daher, die auf dem Speichermedium gesicherten Daten (wie USB-Stick/Festplatte und andere) zeitweise prüfen lassen
    ♦ Also schließe jetzt alle externe Datenträgeran Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.►Anleitung

    7.
    ESET Online Scanner
    Achtung!:
    Keinen andere Virenscanner auf Deinem PC installieren, sondern dein PC NUR online scannen!!!
    ♦ Prüfe Deinen Rechner jetzt, auf Viren, Trojaner, Würmer und anderen Schadcode, mit dem kostenlosen Online Virenscanner von:
    Eset/Nod32 bitte auswählen!!!-> Link und Anleitung zum ESET/NOD32 online Scanner-> Kostenlose Online Scanner
    ♦ Poste bitte das Protokoll

    ► Wie ist den aktuellen Zustand des Rechners? Auffälligkeiten, Probleme?
    Warnung!:
    Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
    Anhang nicht öffnen, in unserem Forum erst nachfragen!

    Bitte diese Warnung weitergeben, wo Du nur kannst!
    Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
    Bitte diese Warnung weitergeben, wo Du nur kannst!

  6. #6
    Forenbenutzer
    Registriert seit
    22.08.2009
    Beiträge
    58

    AW: Bundespolizei Trojaner seit gestern

    Hallo
    anbei die Logs :

    Code:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 20:03:14, on 04.12.2011
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16421)
    Boot mode: Normal
    
    Running processes:
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2206084
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Program Files (x86)\Free Download Manager\iefdm2.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
    O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - Startup: Dropbox.lnk = Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
    O8 - Extra context menu item: add to &BOM - C:\\PROGRA~2\\BIET-O~1\\\\AddToBOM.hta
    O8 - Extra context menu item: Alles mit FDM herunterladen - file://D:\Program Files (x86)\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Auswahl mit FDM herunterladen - file://D:\Program Files (x86)\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Datei mit FDM herunterladen - file://D:\Program Files (x86)\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Free YouTube Download - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
    O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Videos mit FDM herunterladen - file://D:\Program Files (x86)\Free Download Manager\dlfvideo.htm
    O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O18 - Protocol: haufereader - (no CLSID) - (no file)
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira Echtzeit Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Lexware Datenbank Plus (Lexware_Datenbank_Plus) - iAnywhere Solutions, Inc. - C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: StarMoney 8.0 OnlineUpdate - Star Finanz - Software Entwicklung und Vertriebs GmbH - C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
    O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    
    --
    End of file - 9649 bytes
    Code:
    SUPERAntiSpyware Scann-Protokoll
    http://www.superantispyware.com
    
    Generiert 12/04/2011 bei 09:21 PM
    
    Version der Applikation : 5.0.1136
    
    Version der Kern-Datenbank : 8012
    Version der Spur-Datenbank : 5824
    
    Scan Art       : kompletter Scann
    Totale Scann-Zeit : 01:05:54
    
    Operating System Information
    Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
    UAC On - Limited User
    
    Gescannte Speicherelemente  : 681
    Erfasste Speicher-Bedrohungen  : 0
    Gescannte Register-Elemente  : 74441
    Erfasste Register-Bedrohungen  : 0
    Gescannte Datei-Elemente     : 75841
    Erfasste Datei-Elemente   : 0
    Beim Fixen mit OTL verschand das Programm vom Desktop und es erschien keine Text Datei

    Code:
    ESETSmartInstaller@High as downloader log:
    all ok
    # version=7
    # OnlineScannerApp.exe=1.0.0.1
    # OnlineScanner.ocx=1.0.0.6583
    # api_version=3.0.2
    # EOSSerial=9c3192bfcdecaf44acf0d3dc016ee716
    # end=finished
    # remove_checked=true
    # archives_checked=true
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=true
    # utc_time=2011-12-04 11:54:19
    # local_time=2011-12-05 12:54:19 (+0100, Mitteleuropäische Zeit)
    # country="Germany"
    # lang=1033
    # osver=6.1.7601 NT Service Pack 1
    # compatibility_mode=512 16777215 100 0 35874217 35874217 0 0
    # compatibility_mode=1024 16777215 100 0 45919066 45919066 0 0
    # compatibility_mode=1792 16777215 100 0 164529 164529 0 0
    # compatibility_mode=5893 16776574 100 94 13596346 74661729 0 0
    # compatibility_mode=8192 67108863 100 0 3857 3857 0 0
    # scanned=364451
    # found=0
    # cleaned=0
    # scan_time=10980

    Sonst läust alles grad normal

    Meisnt Du das Teil ist sicher gelöscht ?

  7. #7
    Moderator Team-Mitglied Avatar von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    28.352

    AW: Bundespolizei Trojaner seit gestern

    1.
    Kannst du die Programme die wir verwendet haben und nicht brauchst entfernen, bis auf
    Code:
    CCleaner - Zeitweise laufen lassen:-> Anleitung
    Tool-Bereinigung mit OTL

    Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
    • Bitte lade Dir (falls noch nicht vorhanden) OTL von OldTimer herunter.
    • Speichere es auf Deinem Desktop.
    • Doppelklick auf OTL.exe um das Programm auszuführen.
    • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
    • Klicke auf den Button "Bereinigung"
    • OTL fragt eventuell nach einem Neustart.
      Sollte es dies tun, so lasse dies bitte zu.
    Anmerkung: Nach dem Neustart werden OTL und andere Helferprogramme, die Du im Laufe der Bereinigung heruntergeladen hast, nicht mehr vorhanden sein. Sie wurden entfernt. Es ist daher Ok, wenn diese Programme nicht mehr vorhanden sind. Sollten noch welche übrig geblieben sein, lösche sie manuell.

    2.
    Wenn alles gut verlaufen und dein System läuft stabil,mache folgendes:
    Alle Systemwiederherstellungspunkte löschen, auch den Letzten
    am Ende soll die SWH unter alle Laufwerke aktiviert sein!

    3.
    Ich würde Dir vorsichtshalber raten, dein Passwort zu ändern
    z.B. Login-, Mail- oder Website-Passwörter
    Tipps:
    Die sichere Passwort-Wahl - (sollte man eigentlich regelmäßigen Abständen ca. alle 3-5 Monate ändern)
    auch noch hier unter: Sicheres Kennwort (Password)

    ► Wenn Du keine Probleme mehr hast, können wir damit dann Deinen Thread schließen?
    Warnung!:
    Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
    Anhang nicht öffnen, in unserem Forum erst nachfragen!

    Bitte diese Warnung weitergeben, wo Du nur kannst!
    Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
    Bitte diese Warnung weitergeben, wo Du nur kannst!

  8. #8
    Forenbenutzer
    Registriert seit
    22.08.2009
    Beiträge
    58

    AW: Bundespolizei Trojaner seit gestern

    Hallo

    Vielenm Dank
    Habe ich gemacht

    Nur wie lösche ich Wiederherstellungspunkte ?

    Ich habe noch eine FFrage: Ich habe gelesen daß man Win 7 nicht als Admin nutzten soll (tu ich aber glaub ich, oder wie find ich das raus ?)

    Wie kann man das ändern und was ändert sich dadurch ?

    Vielen Dank
    und
    Grüße
    Pastix

  9. #9
    Moderator Team-Mitglied Avatar von kira
    Registriert seit
    28.03.2006
    Ort
    Wien/Sprachen: Deutsch-Ungarisch
    Beiträge
    28.352

    AW: Bundespolizei Trojaner seit gestern

    Zitat Zitat von pastix Beitrag anzeigen

    Nur wie lösche ich Wiederherstellungspunkte ?
    habe dich Dir den Link zur Anleitung:-> Alle Systemwiederherstellungspunkte löschen, auch den Letzten

    Zitat Zitat von pastix Beitrag anzeigen
    Ich habe gelesen daß man Win 7 nicht als Admin nutzten soll (tu ich aber glaub ich, oder wie find ich das raus ?)

    Wie kann man das ändern und was ändert sich dadurch ?
    zwar ab Windows Vista die Einrichtung eines Standardkontos nicht die vollen Administratorrechte hat (Kontensteuerung bzw. UAC ), jedoch empfehlenswert ein eingeschränktes Konto zu eröffnen.
    Wenn ein Anwender mit einem Benutzerkonto mit eingeschränkten Rechten arbeitet, kann ein Virus sich nur auf Dateien verbreiten, für die der Benutzer die entsprechenden Rechte zur Veränderung besitzt. Dieses bedeutet normalerweise, dass Systemdateien vom Virus nicht infiziert werden können, solange der Administrator oder mit Administratorrechten versehene Systemdienste nicht Dateien des infizierten Benutzers aufrufen. Eventuell auf dem gleichen System arbeitende Benutzer können meist ebenfalls nicht infiziert werden, so lange sie nicht eine infizierte Datei des infizierten Benutzers ausführen oder die Rechte des infizierten Benutzers es erlauben, die Dateien von anderen Benutzern zu verändern.

    Da Windows-Systeme heute die weiteste Verbreitung auf PCs haben, sind sie derzeit das Hauptziel von Virenautoren. Die Tatsache, dass sehr viele Windows-Anwender mit Konten arbeiten, die Administratorrechte haben, sowie die Unkenntnis von Sicherheitspraktiken bei der relativ hohen Zahl unerfahrener Privatanwender macht Windows-Systeme noch lohnender als Ziel von Virenautoren.
    Geändert von kira (07.12.2011 um 05:03 Uhr)
    Warnung!:
    Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein!
    Anhang nicht öffnen, in unserem Forum erst nachfragen!

    Bitte diese Warnung weitergeben, wo Du nur kannst!
    Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten!
    Bitte diese Warnung weitergeben, wo Du nur kannst!

  10. #10
    Forenbenutzer
    Registriert seit
    22.08.2009
    Beiträge
    58

    AW: Bundespolizei Trojaner seit gestern

    Hallo
    Vielen Dank für die Hilfe

    Kann ich den eine anderes Konto als Admin einreichten damit ich mein aktuelles Profeil dann auch weiter nutzren kann wenn ich das nicht mehr als Admin definiert habe ?

Seite 1 von 2 12 LetzteLetzte

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

Ähnliche Themen

  1. Antworten: 0
    Letzter Beitrag: 10.08.2011, 11:30
  2. AntiVir findet seit gestern Trojaner
    Von SusanAlien im Forum Archiv
    Antworten: 21
    Letzter Beitrag: 29.12.2008, 11:44
  3. werde seit gestern blästigt
    Von nordlord im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 18.05.2008, 16:25
  4. Virenscanner zeigt seit Gestern Virenpfund an...
    Von Smith0606 im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 18.09.2007, 07:14
  5. computer lahmt seit gestern....
    Von m0ngO im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 16.02.2006, 20:09

Berechtigungen

  • Neue Themen erstellen: Nein
  • Themen beantworten: Nein
  • Anhänge hochladen: Nein
  • Beiträge bearbeiten: Nein
  •