Alt 11.03.2013, 18:00   #1
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

Hey Leute,

ich habe noch keinen Thread zu meinem Thema gefunden Wäre nett, wenn mir jemand helfen mag. Also: Wenn ich Youtube-Videos abspiele, dann stockt mein Laptop manchmal, ein lautes Störgeräusch ertönt und nichts geht mehr. Nach über einer Minute kann ich den Computer wieder benutzen.

Außerdem: Manchmal stockt der PC zwar ohne Störgeräusch, dann kann ich den Mauszeiger aber auch nicht mehr bewegen. Danach kann ich das Keyboard nicht benutzen, nur €-Zeichen und andere Sonderzeichen. Geht erst wieder nach dem Neustart.

Letztens ist er auch mal abgestürzt und ein blauer Bildschirm erschien (es kam der Begriff "dump memory" vor). Ich habe einen ASUS X5DIJ, Betriebssystem Windows 7 Home Premium Service Pack 1. Der Laptop ist 3 Jahre alt. Avira hat nix gefunden.

Mein PC ist zudem sehr langsam, aber ich weiß nicht, wie ich ihn schneller machen könnte. Super wäre es, wenn du mir dabei auch helfen könntest

Kurz: Mag jemand vielleicht ein edler Cyber-Ritter eine holde Dame aus ihrer Verzweiflung retten? Ihm gebürt mein ewiger Dank


Alt 13.03.2013, 12:47   #2
/// Winkelfunktion
/// TB-Süch-Tiger™
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

Hallo und

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Die Logs der aufgegebenen Tools wie zB Malwarebytes sind immer zu posten - egal ob ein Fund dabei war oder nicht!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.

Erstmal eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in CODE-Tags in den Thread.


Alt 13.03.2013, 15:11   #3
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

Vielen Dank!

OTL logfile created on: 13.03.2013 14:42:05 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Asus\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,97 Gb Total Physical Memory | 1,38 Gb Available Physical Memory | 34,81% Memory free
7,93 Gb Paging File | 4,69 Gb Available in Paging File | 59,19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 74,52 Gb Total Space | 18,15 Gb Free Space | 24,36% Space Free | Partition Type: NTFS
Drive D: | 204,03 Gb Total Space | 18,61 Gb Free Space | 9,12% Space Free | Partition Type: NTFS
Drive G: | 1,83 Gb Total Space | 1,64 Gb Free Space | 89,54% Space Free | Partition Type: FAT
Computer Name: ASUS-PC | User Name: Asus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC -  File not found
PRC - C:\Users\Asus\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\scalc.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe ()
PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
PRC - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe ()
PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()
PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe ()
MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
MOD - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe ()
MOD - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()
MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll ()
MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (SolutoLauncherService) -- C:\Program Files\Soluto\SolutoLauncherService.exe (Soluto)
SRV:64bit: - (SolutoService) -- C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV:64bit: - (SolutoRemoteService) -- C:\Program Files\Soluto\SolutoRemoteService.exe (Soluto)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (ATKGFNEXSrv) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (OpenVPNService) -- C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe ()
SRV - (CVPND) -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe (ASUS)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ADSMService) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)
SRV - (MSCSPTISRV) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) -- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (Soluto) -- C:\Windows\SysNative\drivers\Soluto.sys (Soluto LTD.)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (tap0901) -- C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CVPNDRVA) -- C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (AsDsm) -- C:\Windows\SysNative\drivers\AsDsm.sys (ASUSTek Computer Inc)
DRV:64bit: - (CVirtA) -- C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (ewusbnet) -- C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwusbfake) -- C:\Windows\SysNative\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (lullaby) -- C:\Windows\SysNative\drivers\lullaby.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (DNE) -- C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks, Inc.)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV:64bit: - (ASMMAP64) -- C:\Program Files\ATKGFNEX\ASMMAP64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=111304&tt=290412_4_bst&babsrc=SP_ss&mntrId=7c02b03600000000000000fff2134b42
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\SearchScopes\{3C91F9AE-DF32-41A4-8F59-1391742B7D6C}: "URL" = hxxp://search.avg.com/?d=4e2ee956&i=23&tp=chrome&q={searchTerms}&lng={language}&nt=1
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ASUT_de
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7B36e61c98-5a87-4eee-bace-8fed1aef6d79%7D:0.9
FF - prefs.js..extensions.enabledAddons: socialfixer%40mattkruse.com:7.501
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.11
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.5
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1.1
FF - prefs.js..extensions.enabledItems: treestyletab@piro.sakura.ne.jp:0.11.2011021901
FF - prefs.js..extensions.enabledItems: {71328583-3CA7-4809-B4BA-570A85818FBB}:0.6.3
FF - prefs.js..extensions.enabledItems: cache@status.org:0.7.9
FF - prefs.js..extensions.enabledItems: {36e61c98-5a87-4eee-bace-8fed1aef6d79}:0.6
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.10 04:07:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.02.03 20:03:38 | 000,000,000 | ---D | M]
[2010.10.17 13:29:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\Extensions
[2013.02.15 20:24:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\fwl4d9pq.default\extensions
[2012.12.28 00:31:35 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\fwl4d9pq.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2011.02.09 23:32:27 | 000,000,000 | ---D | M] (CacheViewer) -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\fwl4d9pq.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}
[2012.07.24 11:52:11 | 000,000,000 | ---D | M] (Avira SearchFree Toolbar plus Web Protection) -- C:\Users\Asus\AppData\Roaming\mozilla\Firefox\Profiles\fwl4d9pq.default\extensions\toolbar@ask.com
[2011.05.03 02:25:24 | 000,021,992 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\cache@status.org.xpi
[2012.12.12 22:39:57 | 000,009,505 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\clipconverter@clipconverter.cc.xpi
[2012.07.06 15:00:56 | 000,123,385 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\elemhidehelper@adblockplus.org.xpi
[2013.02.11 00:02:00 | 000,155,983 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\socialfixer@mattkruse.com.xpi
[2011.05.28 22:24:49 | 000,205,682 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\{36e61c98-5a87-4eee-bace-8fed1aef6d79}.xpi
[2012.12.17 21:38:36 | 000,222,578 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi
[2012.11.24 16:45:38 | 000,269,905 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2013.02.15 20:24:06 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.01.16 12:01:32 | 000,000,873 | ---- | M] () -- C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\fwl4d9pq.default\searchplugins\conduit.xml
[2012.05.16 22:03:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.03.10 04:07:07 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013.02.05 23:14:45 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.05.09 23:23:24 | 000,002,355 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2013.02.05 23:14:45 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013.02.05 23:14:45 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2013.02.05 23:14:45 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.02.05 23:14:45 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.02.05 23:14:45 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (TBSB02188 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\Babylon Toolbar\tbcore3.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} - C:\Program Files (x86)\Babylon Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1966995642-2264083377-1929930323-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Asus\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{52ADBC23-9B62-4D04-9107-E91F1E967E9E}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C5FECA72-5375-4139-B22C-CB039CC9779B}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F2A672B3-E521-4EF2-9266-D2C92AEA1C81}: DhcpNameServer =
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (c:\program files\soluto\soluto.exe /userinit) - c:\program files\soluto\soluto.exe (Soluto)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{69503c3b-f759-11df-aa39-20cf3018582c}\Shell - "" = AutoRun
O33 - MountPoints2\{69503c3b-f759-11df-aa39-20cf3018582c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{695046d4-f759-11df-aa39-20cf3018582c}\Shell - "" = AutoRun
O33 - MountPoints2\{695046d4-f759-11df-aa39-20cf3018582c}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{69504749-f759-11df-aa39-20cf3018582c}\Shell - "" = AutoRun
O33 - MountPoints2\{69504749-f759-11df-aa39-20cf3018582c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{69504756-f759-11df-aa39-20cf3018582c}\Shell - "" = AutoRun
O33 - MountPoints2\{69504756-f759-11df-aa39-20cf3018582c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{6a410d26-ea6a-11df-8852-20cf3018582c}\Shell - "" = AutoRun
O33 - MountPoints2\{6a410d26-ea6a-11df-8852-20cf3018582c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.13 14:40:12 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL.exe
[2013.03.13 04:53:49 | 000,000,000 | ---D | C] -- C:\Users\Asus\.tuxguitar-1.2
[2013.03.13 04:52:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013.03.13 04:52:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.03.13 04:51:44 | 000,782,240 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013.03.13 04:51:43 | 000,861,088 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.03.13 04:51:43 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.03.13 04:51:12 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.03.13 04:51:12 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.03.13 04:51:12 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.03.13 04:50:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.03.13 04:49:04 | 000,896,928 | ---- | C] (Oracle Corporation) -- C:\Users\Asus\Desktop\jxpiinstall.exe
[2013.03.13 04:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuxGuitar
[2013.03.13 04:47:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TuxGuitar
[2013.03.13 04:41:24 | 007,715,210 | ---- | C] (Herac) -- C:\Users\Asus\Desktop\tuxguitar-1.2-windows-x86-installer.exe
[2013.03.12 00:01:19 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Roaming\pdfforge
[2013.03.12 00:01:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2013.03.12 00:01:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFCreator
[2013.03.12 00:00:43 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Local\Programs
[2013.03.11 23:55:49 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
[2013.03.08 16:25:26 | 000,000,000 | ---D | C] -- C:\Users\Asus\AppData\Local\{F240AD28-B592-42FB-9E10-1D9565BA212E}
[2013.03.01 01:08:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.03.01 01:08:41 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2013.03.01 01:08:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013.03.01 00:25:17 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Kunst Fotos
[2013.02.27 01:16:11 | 002,776,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2013.02.27 01:16:11 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll
[2013.02.27 01:16:11 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll
[2013.02.27 01:16:10 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll
[2013.02.27 01:16:01 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2013.02.27 01:16:01 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2013.02.27 01:15:55 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013.02.27 01:15:55 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013.02.27 01:15:55 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013.02.27 01:15:55 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013.02.27 01:15:55 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013.02.27 01:15:55 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013.02.27 01:15:55 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013.02.27 01:15:55 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013.02.27 01:15:54 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2013.02.27 01:15:54 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2013.02.27 01:15:54 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2013.02.27 01:15:53 | 001,887,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2013.02.27 01:15:53 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2013.02.27 01:15:53 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2013.02.27 01:15:53 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2013.02.27 01:15:53 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2013.02.27 01:15:53 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2013.02.27 01:15:53 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll
[2013.02.27 01:15:53 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013.02.27 01:15:53 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013.02.27 01:15:53 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013.02.27 01:15:53 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013.02.27 01:15:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013.02.27 01:15:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013.02.27 01:15:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013.02.27 01:15:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013.02.27 01:15:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013.02.27 01:15:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013.02.27 01:15:52 | 001,682,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2013.02.27 01:15:52 | 001,238,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll
[2013.02.27 01:15:52 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2013.02.27 01:15:51 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2013.02.27 01:15:51 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll
[2013.02.27 01:15:50 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2013.02.27 01:15:50 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2013.02.19 21:55:31 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\papa fotos handy
[2013.02.19 21:51:38 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Brenna 13
[2013.02.18 22:47:11 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Les Amours Imaginaires 2010 [DVDRip.XviD-miguel]
[2013.02.18 22:46:17 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\La Double Vie de Veronique
[2013.02.18 22:42:14 | 000,000,000 | ---D | C] -- C:\Users\Asus\Desktop\Breakfast on Pluto
[2013.02.16 15:14:14 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.02.16 15:14:14 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.02.16 15:14:11 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.02.16 15:14:11 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.02.16 15:14:11 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.02.16 15:14:11 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.02.16 15:14:10 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.02.16 15:14:10 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.02.16 15:14:09 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.02.16 15:14:08 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.02.16 15:14:08 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.02.16 15:14:07 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.02.16 15:14:05 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.02.16 15:14:05 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.02.16 15:14:05 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.02.13 20:50:34 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013.02.13 20:50:33 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013.02.13 20:50:33 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013.02.13 20:49:53 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013.02.13 20:49:52 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013.02.13 20:49:52 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013.02.13 20:49:52 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013.02.13 20:49:52 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013.02.13 20:49:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013.02.13 20:49:45 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2008.08.12 05:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll
[46 C:\Users\Asus\Desktop\*.tmp files -> C:\Users\Asus\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.13 14:40:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Asus\Desktop\OTL.exe
[2013.03.13 14:32:25 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.13 14:32:21 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.03.13 14:32:21 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.03.13 14:31:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.13 07:48:24 | 000,867,700 | ---- | M] () -- C:\Users\Asus\Desktop\102_4634.JPG
[2013.03.13 04:50:57 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.03.13 04:50:54 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.03.13 04:50:54 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013.03.13 04:50:54 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.03.13 04:50:54 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.03.13 04:50:54 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.03.13 04:49:08 | 000,896,928 | ---- | M] (Oracle Corporation) -- C:\Users\Asus\Desktop\jxpiinstall.exe
[2013.03.13 04:47:50 | 000,000,951 | ---- | M] () -- C:\Users\Public\Desktop\TuxGuitar.lnk
[2013.03.13 04:41:26 | 007,715,210 | ---- | M] (Herac) -- C:\Users\Asus\Desktop\tuxguitar-1.2-windows-x86-installer.exe
[2013.03.13 03:18:46 | 000,867,471 | ---- | M] () -- C:\Users\Asus\Desktop\BA Agata Waleczek.pdf
[2013.03.13 02:01:49 | 000,056,802 | ---- | M] () -- C:\Users\Asus\Desktop\250923_10151274187189778_1682797431_n.jpg
[2013.03.13 02:00:37 | 000,075,417 | ---- | M] () -- C:\Users\Asus\Desktop\26855_1434398577929_6550657_n.jpg
[2013.03.13 01:58:56 | 000,067,014 | ---- | M] () -- C:\Users\Asus\Desktop\564051_4212282232560_292395225_n.jpg
[2013.03.13 01:56:29 | 000,061,391 | ---- | M] () -- C:\Users\Asus\Desktop\526974_10151055670253225_2145800475_n.jpg
[2013.03.13 01:27:29 | 000,076,963 | ---- | M] () -- C:\Users\Asus\Desktop\j für aga.jpg
[2013.03.12 22:38:41 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.12 22:38:41 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.12 21:53:32 | 001,500,294 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.03.12 21:53:32 | 000,654,852 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.03.12 21:53:32 | 000,616,694 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.03.12 21:53:32 | 000,130,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.03.12 21:53:32 | 000,106,816 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.03.12 00:01:20 | 000,001,037 | ---- | M] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2013.03.11 23:55:52 | 000,001,744 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2013.03.11 20:44:34 | 000,015,246 | ---- | M] () -- C:\Users\Asus\Desktop\packliste strasbourg.ods
[2013.03.11 20:44:33 | 000,000,108 | -H-- | M] () -- C:\Users\Asus\Desktop\.~lock.packliste strasbourg.ods#
[2013.03.11 17:43:05 | 000,131,072 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2013.03.11 17:42:31 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.11 04:00:03 | 000,663,526 | ---- | M] () -- C:\Users\Asus\Desktop\8126535925_0723dc9435_kk.jpg
[2013.03.11 03:58:04 | 001,060,702 | ---- | M] () -- C:\Users\Asus\Desktop\8126535925_0723dc9435_k.jpg
[2013.03.09 15:07:58 | 001,133,293 | ---- | M] () -- C:\Users\Asus\Desktop\cspCjbJG.jpg
[2013.03.09 01:58:22 | 000,051,095 | ---- | M] () -- C:\Users\Asus\Desktop\19144_251463506013_4613375_n.jpg
[2013.03.07 02:12:44 | 000,153,591 | ---- | M] () -- C:\Users\Asus\Desktop\kampf.png
[2013.03.07 01:47:14 | 000,373,502 | ---- | M] () -- C:\Users\Asus\Desktop\Auszug - Das Sexuelle in Riefenstahls Triumph des Willens.pdf
[2013.03.07 01:39:41 | 000,141,044 | ---- | M] () -- C:\Users\Asus\Desktop\holz.png
[2013.03.07 00:31:42 | 000,176,539 | ---- | M] () -- C:\Users\Asus\Desktop\kamerad.png
[2013.03.07 00:11:08 | 000,178,283 | ---- | M] () -- C:\Users\Asus\Desktop\VOYUER.png
[2013.03.01 01:55:37 | 001,894,439 | ---- | M] () -- C:\Users\Asus\Desktop\Jonas Hofrichter Portfolio.pdf
[2013.02.25 23:06:12 | 000,868,247 | ---- | M] () -- C:\Users\Asus\Desktop\Kolla-Ried (3 von 4).jpg
[2013.02.16 15:51:46 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2013.02.16 15:49:10 | 000,292,104 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.02.15 14:52:32 | 000,099,756 | ---- | M] () -- C:\Users\Asus\Desktop\Kunst Redaktionsprotokoll 13.2..pdf
[46 C:\Users\Asus\Desktop\*.tmp files -> C:\Users\Asus\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.13 04:47:50 | 000,000,951 | ---- | C] () -- C:\Users\Public\Desktop\TuxGuitar.lnk
[2013.03.13 03:18:43 | 000,867,471 | ---- | C] () -- C:\Users\Asus\Desktop\BA Agata Waleczek.pdf
[2013.03.13 02:01:49 | 000,056,802 | ---- | C] () -- C:\Users\Asus\Desktop\250923_10151274187189778_1682797431_n.jpg
[2013.03.13 02:00:36 | 000,075,417 | ---- | C] () -- C:\Users\Asus\Desktop\26855_1434398577929_6550657_n.jpg
[2013.03.13 01:58:55 | 000,067,014 | ---- | C] () -- C:\Users\Asus\Desktop\564051_4212282232560_292395225_n.jpg
[2013.03.13 01:56:28 | 000,061,391 | ---- | C] () -- C:\Users\Asus\Desktop\526974_10151055670253225_2145800475_n.jpg
[2013.03.13 01:27:13 | 000,076,963 | ---- | C] () -- C:\Users\Asus\Desktop\j für aga.jpg
[2013.03.12 21:51:02 | 000,867,700 | ---- | C] () -- C:\Users\Asus\Desktop\102_4634.JPG
[2013.03.12 00:01:20 | 000,001,037 | ---- | C] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2013.03.11 23:55:52 | 000,001,744 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2013.03.11 23:55:52 | 000,001,694 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2013.03.11 20:44:33 | 000,000,108 | -H-- | C] () -- C:\Users\Asus\Desktop\.~lock.packliste strasbourg.ods#
[2013.03.11 20:44:32 | 000,015,246 | ---- | C] () -- C:\Users\Asus\Desktop\packliste strasbourg.ods
[2013.03.11 04:00:03 | 000,663,526 | ---- | C] () -- C:\Users\Asus\Desktop\8126535925_0723dc9435_kk.jpg
[2013.03.11 03:58:00 | 001,060,702 | ---- | C] () -- C:\Users\Asus\Desktop\8126535925_0723dc9435_k.jpg
[2013.03.09 15:07:56 | 001,133,293 | ---- | C] () -- C:\Users\Asus\Desktop\cspCjbJG.jpg
[2013.03.09 01:57:58 | 000,051,095 | ---- | C] () -- C:\Users\Asus\Desktop\19144_251463506013_4613375_n.jpg
[2013.03.07 02:12:44 | 000,153,591 | ---- | C] () -- C:\Users\Asus\Desktop\kampf.png
[2013.03.07 01:47:11 | 000,373,502 | ---- | C] () -- C:\Users\Asus\Desktop\Auszug - Das Sexuelle in Riefenstahls Triumph des Willens.pdf
[2013.03.07 01:25:36 | 000,141,044 | ---- | C] () -- C:\Users\Asus\Desktop\holz.png
[2013.03.07 00:31:41 | 000,176,539 | ---- | C] () -- C:\Users\Asus\Desktop\kamerad.png
[2013.03.07 00:11:08 | 000,178,283 | ---- | C] () -- C:\Users\Asus\Desktop\VOYUER.png
[2013.03.01 01:55:29 | 001,894,439 | ---- | C] () -- C:\Users\Asus\Desktop\Jonas Hofrichter Portfolio.pdf
[2013.02.26 21:11:49 | 000,868,247 | ---- | C] () -- C:\Users\Asus\Desktop\Kolla-Ried (3 von 4).jpg
[2013.02.18 22:49:45 | 732,684,288 | ---- | C] () -- C:\Users\Asus\Desktop\XXY.[Spanish].DVDRip.XviD.MP3.[DTL].avi
[2013.02.18 22:48:32 | 729,270,272 | ---- | C] () -- C:\Users\Asus\Desktop\Pl.Galerianki.avi
[2013.02.15 14:52:31 | 000,099,756 | ---- | C] () -- C:\Users\Asus\Desktop\Kunst Redaktionsprotokoll 13.2..pdf
[2012.04.06 16:37:46 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2012.04.02 21:59:14 | 000,007,603 | ---- | C] () -- C:\Users\Asus\AppData\Local\Resmon.ResmonCfg
[2011.01.31 15:37:45 | 000,003,584 | ---- | C] () -- C:\Users\Asus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.10.17 16:06:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.06.29 22:43:49 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2009.04.08 18:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll
[2008.05.22 16:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:2F370DA6
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:4CF61E54
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:A724744F
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:AB689DEA

< End of report >
OTL Extras logfile created on: 13.03.2013 14:42:05 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Asus\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,97 Gb Total Physical Memory | 1,38 Gb Available Physical Memory | 34,81% Memory free
7,93 Gb Paging File | 4,69 Gb Available in Paging File | 59,19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 74,52 Gb Total Space | 18,15 Gb Free Space | 24,36% Space Free | Partition Type: NTFS
Drive D: | 204,03 Gb Total Space | 18,61 Gb Free Space | 9,12% Space Free | Partition Type: NTFS
Drive G: | 1,83 Gb Total Space | 1,64 Gb Free Space | 89,54% Space Free | Partition Type: FAT
Computer Name: ASUS-PC | User Name: Asus | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
"{002C6A39-C685-4354-B440-CE3E27198671}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{05420C81-D799-4780-AA46-45BC9801FE6F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{08D60825-F2E1-422F-9B58-27A729426333}" = rport=2869 | protocol=6 | dir=out | app=system | 
"{096F6B4D-1C22-4DC5-B1D7-385041440B0A}" = rport=139 | protocol=6 | dir=out | app=system | 
"{097281AC-735E-49C9-B358-BE52E12D6782}" = lport=139 | protocol=6 | dir=in | app=system | 
"{104FE3CB-54C9-4232-9E1F-F183FDC978CA}" = rport=445 | protocol=6 | dir=out | app=system | 
"{165838F7-A97F-456F-B2BB-EBF9FCC66B2C}" = rport=138 | protocol=17 | dir=out | app=system | 
"{18444415-FB41-472B-9FC7-9593BCA29DC8}" = lport=137 | protocol=17 | dir=in | app=system | 
"{24E4E1ED-DEC5-47BA-8206-21F6430604A1}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{35BAB70C-E8DF-4D57-BD92-D7374CF29787}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{3C7A385E-F33F-4485-9180-B0FA444CBBA4}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{3F0B85E2-CEA5-4513-812D-427A9D547DBE}" = lport=8182 | protocol=6 | dir=in | name=java(tm) platform se binary | 
"{4119252C-8605-4C46-80AA-0C7BD4FA21A4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{564DF96F-5071-49D8-AEE6-1387FE188FE5}" = lport=138 | protocol=17 | dir=in | app=system | 
"{61A6FA6C-0996-4B4B-9CFF-796719CF6BC5}" = rport=137 | protocol=17 | dir=out | app=system | 
"{6C48D93B-A542-4749-BE8B-FBFBBBDDCFC8}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{6DB2EF68-1E5A-4EB8-8EB7-A19A42DF5634}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{7A27C943-4C12-447A-B696-FCB11773A764}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{804FAA28-DB56-4748-8FF8-FB20B5EEBE42}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{948B357D-DB54-42AC-B47B-1CBC8212941E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{98C2B33E-11A7-4CA3-970A-4FFD8873DB64}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{B00300C4-8D32-4DD3-A879-DBC88C4F9FA4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{B4E7B6C3-59C2-4C7F-AFBD-37B514152EDE}" = lport=5353 | protocol=17 | dir=in | name=java(tm) platform se binary | 
"{B61B9680-C282-4FCB-8F84-6D9E8137CCAE}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{B66CDC5F-34F0-4451-866B-07E740F7A73C}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B974F9A5-D192-4009-8855-287D60F09344}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{B9B20323-92F8-487D-9A92-B955493142DA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BA602C2B-CB0D-47C9-8BC9-830677224ED7}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{BD6E0415-FDA7-4A3B-A81F-DBAC87365BF6}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{C1062702-D30B-4874-A57C-5A8986363B7B}" = lport=445 | protocol=6 | dir=in | app=system | 
"{C415CE05-0324-4CDE-A52B-5CA569148EA0}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{C781F91F-297A-4170-BA97-BF4A8116CB17}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{D18D2FA8-17B2-48AC-AD5E-8D891F4CE7BE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{EC144EAC-A96B-4F3C-B2AC-7CCACDB0A5F1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{EF59C5DD-1300-4092-9228-BB94A347A985}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
========== Vista Active Application Exception List ==========
"{02AF860D-D739-49AE-AFEC-A45389C03FAB}" = protocol=6 | dir=out | app=system | 
"{02D469EA-F93C-418B-9140-8095FED5B7C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{09C81D06-CE08-4349-BDF4-83F8182256EB}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoconsole.exe | 
"{1492B87C-565C-4A45-87E9-E395A8F88070}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{1A32605A-1175-439F-A8B9-01BC4A6854E2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{1F898BFE-5159-4003-97DA-CED471A77FC6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{20120093-CE5B-4558-B2C2-7002BB948509}" = protocol=6 | dir=in | app=c:\users\asus\desktop\solutoinstaller-n7m2cot1g4.exe | 
"{22A55436-C7AD-4EA7-A1C1-C28EA76683E2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{26044ABE-DEFB-458D-A1FC-E35A43EF04D3}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoservice.exe | 
"{283B5127-EE14-442D-B16F-B73D71C1992A}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoupdateservice.exe | 
"{2BC095E8-F527-46A2-A70F-AED7BFA7AB59}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoconsole.exe | 
"{30D3D32A-0838-4FA4-AA95-4085F06391CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{30E2D84F-87EC-413A-900B-8E0CD545C79F}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoconsole.exe | 
"{314770DA-C8A9-4E3C-8ECB-4027D8179CDC}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{39A96F45-B833-43E0-A54E-11161CAAFBAF}" = protocol=17 | dir=in | app=c:\program files\soluto\solutocleanup.exe | 
"{3BA104A5-9986-4225-96EF-A7A3CA8CE4E8}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoupdateservice.exe | 
"{3BB53BD7-43BE-4586-BAED-E88D413AD58C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{43331561-4378-468B-92F0-A1F2632C9E33}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoservice.exe | 
"{4C1D2BB9-F8A4-49D3-B032-290113DFDC68}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{6342130E-156B-4F38-9EF3-A30133998942}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | 
"{63EE9F27-B9B9-4D65-822D-2A0667EDCF94}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{6528873A-35FA-4FD6-B913-AA323DE42506}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoupdateservice.exe | 
"{69C42AD4-3A2E-4C26-A86B-A43B67AFF694}" = protocol=17 | dir=in | app=c:\users\asus\desktop\solutoinstaller-n7m2cot1g4.exe | 
"{6EA4512A-6240-48E7-A5D2-89591C802291}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{70E3486A-9A2E-455A-87A8-66C598D8AC8C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{717DF5E0-FD6F-407F-A540-B8402A059DE0}" = protocol=17 | dir=in | app=c:\program files\soluto\soluto.exe | 
"{73A72A5A-C4F2-4603-B41E-2B93A715F950}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{7B90F7C3-19F9-47D9-AE0B-24E07CD056B6}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | 
"{7EEE623F-EC75-4204-921E-6D5DB6C64162}" = protocol=6 | dir=in | app=c:\program files\soluto\solutocleanup.exe | 
"{830CBB8B-6E60-42FC-9518-25C46F2A87E4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{8A103ACC-18A9-4B40-A10A-E6A0FA2A7DC1}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | 
"{8A2B13A7-7D2B-40A8-8EE2-2A440C15C67A}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{8A42DACF-37E7-4D7E-995A-6385D0DA6910}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{8AEB8409-F424-4C0C-A246-4C16F7EBA4D1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{8BFABD15-A813-4E2A-B5C6-090D6ECE6CCD}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoupdateservice.exe | 
"{8CDEEC3C-175C-4BFB-B301-C43B57E5322F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{93B1DDE8-E12E-4A68-B1F0-1C5C492515FC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{9A67DADB-D44F-4EB9-B92A-27200129BBA8}" = protocol=17 | dir=in | app=e:\alicesetup.exe | 
"{A83D087F-4D22-490B-AC8B-83DE9284B0BA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{AAADAB94-A72D-4FDB-ACA2-BA56B69DA715}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{ACE21CE5-F53A-415A-BEAB-AE1A547A0F77}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | 
"{AE74736B-2E90-4F3C-905D-4162D5F9B91C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{AFAE8B75-D3E1-4C40-8D22-B68641F82F99}" = protocol=6 | dir=in | app=c:\program files\soluto\soluto.exe | 
"{B03E060B-0A66-4397-8CAB-EFD986924767}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
"{B3B83BFD-8797-407A-ABEF-CFABEE0F6363}" = protocol=6 | dir=in | app=c:\program files\soluto\soluto.exe | 
"{B811F705-694A-44E4-8074-8E43B333998F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BB8391C7-3C07-4F0E-B256-A55F5F4F8353}" = protocol=6 | dir=in | app=e:\alicesetup.exe | 
"{BCE65711-08F8-4CBE-A966-6EDFCE560D8B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{BFB1C2F4-BAD8-4F04-A8E4-6FCECADD6AB1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{C0D15393-CC6D-47CB-AF68-915277C5295A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C811A3B7-E51A-4565-A9A8-9A83776D5462}" = protocol=6 | dir=in | app=c:\users\asus\appdata\local\google\google talk plugin\googletalkplugin.exe | 
"{C96CCB5A-1D79-4838-AC71-901E0D6F7265}" = protocol=17 | dir=in | app=c:\users\asus\appdata\local\google\google talk plugin\googletalkplugin.exe | 
"{D2938DCD-DDEE-4FA8-B543-B2EF5FA6E00E}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D4CF678B-7EA4-48CF-A073-BB800A90F836}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{D95333B8-C10B-4776-82B8-1D0818F0C19A}" = protocol=17 | dir=in | app=c:\program files\soluto\soluto.exe | 
"{DC1316BB-5AFB-49D9-A1E2-2D07F6DD6F2C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{F4012F18-B5A2-439B-B565-F81BD725B6D6}" = protocol=17 | dir=in | app=c:\program files\soluto\solutoservice.exe | 
"{F6CA5517-3295-4348-8C69-114D2838D6FE}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoconsole.exe | 
"{FFC6429C-211E-4085-B0AC-22A1152C8185}" = protocol=6 | dir=in | app=c:\program files\soluto\solutoservice.exe | 
"TCP Query User{4EAF09EA-97B2-4CA7-A370-DC801D0CB90B}F:\starcraft 1.15 - no install needed\starcraft.exe" = protocol=6 | dir=in | app=f:\starcraft 1.15 - no install needed\starcraft.exe | 
"TCP Query User{C3A35916-F222-4A77-BA8C-163DABB35DE9}C:\users\asus\desktop\starcraft 1.15 - no install needed\starcraft.exe" = protocol=6 | dir=in | app=c:\users\asus\desktop\starcraft 1.15 - no install needed\starcraft.exe | 
"TCP Query User{DE326F3E-5639-43A9-86B6-DB3C78EB67E5}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | 
"UDP Query User{20893048-35B4-4FEC-872A-8D450B18913B}C:\users\asus\desktop\starcraft 1.15 - no install needed\starcraft.exe" = protocol=17 | dir=in | app=c:\users\asus\desktop\starcraft 1.15 - no install needed\starcraft.exe | 
"UDP Query User{6C7045D1-4FBA-4109-885F-922A8D441DB7}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | 
"UDP Query User{B2CA2C84-D491-4FCA-BC1F-69B89309105A}F:\starcraft 1.15 - no install needed\starcraft.exe" = protocol=17 | dir=in | app=f:\starcraft 1.15 - no install needed\starcraft.exe | 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{2128559D-BBCD-4744-87F0-7C0CD5CFB464}" = Windows Live Family Safety
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6CFC80-684E-4E1D-B4D9-DA801C05440C}" = Soluto
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}" = Cisco Systems VPN Client
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}" = ASUS Power4Gear Hybrid
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}" = SRS Premium Sound Control Panel
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Elantech" = ETDWare PS/2-x64
"EPSON P50 Series" = Druckerdeinstallation für EPSON P50 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Redirection Port Monitor" = RedMon - Redirection Port Monitor
"USB 2.0 1.3M UVC WebCam" = USB 2.0 1.3M UVC WebCam
"WinRAR archiver" = WinRAR 4.11 (64-bit)
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{03534DA5-2F88-4B8E-A978-849B979E1B8F}" = TuxGuitar
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2B81872B-A054-48DA-BE3B-FA5C164C303A}" = ASUS FancyStart
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{5508128A-2C7B-46B5-81F9-58E8E8115F0B}" = AdblockIE
"{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}" = ASUS CopyProtect
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 5.2.0
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8C1E2925-14F8-45AA-B999-1E2A74BF5607}" = Windows Live Sync
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.01) - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B653A2EC-D816-4498-A4FD-651047AB9DC9}" = Boingo Wi-Fi
"{BBED4F90-7AE5-40BF-AFB7-1B495692F4AB}" = syncables desktop SE
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F4BF5F6B-F695-4762-AEB2-D095A4C34D89}" = Alcor Micro USB Card Reader
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FA2092C5-7979-412D-A962-6485274AE1EE}" = ASUS Data Security Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ASUS WebStorage" = ASUS WebStorage
"ASUS_Screensaver" = ASUS_Screensaver
"Audacity_is1" = Audacity 2.0
"Avira AntiVir Desktop" = Avira Free Antivirus
"Babylon Toolbar" = Babylon Toolbar
"Digital Camera Enhancer_is1" = Digital Camera Enhancer
"ElsterFormular für Privatanwender" = ElsterFormular für Privatanwender
"Free Video Dub_is1" = Free Video Dub version
"GPL Ghostscript 9.00" = GPL Ghostscript 9.00
"HMA! Pro VPN" = HMA! Pro VPN 2.6.9
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"InstallShield_{F4BF5F6B-F695-4762-AEB2-D095A4C34D89}" = Alcor Micro USB Card Reader
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"OpenMG HotFix4.7-07-13-22-01" = OpenMG Limited Patch 4.7-07-14-05-01
"SecureW2 EAP Suite" = SecureW2 EAP Suite 1.1.1 for Windows
"VLC media player" = VLC media player 1.1.7
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-Bit)
========== HKEY_USERS Uninstall List ==========
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Avira SearchFree Toolbar plus Web Protection Updater
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 07.03.2013 13:38:42 | Computer Name = Asus-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Überspringen: Eap method DLL path Fehler bei der Überprüfung. Fehler:
 Type-ID=21, Autor-ID=29114, Lieferant-ID=0, Lieferant-Typ=0
Error - 07.03.2013 13:38:47 | Computer Name = Asus-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385,
 Zeitstempel: 0x4a5bc6b7  Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514,
 Zeitstempel: 0x4ce7b96f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0003bc24  ID des fehlerhaften
 Prozesses: 0x377c  Startzeit der fehlerhaften Anwendung: 0x01ce17b95c87b9a4  Pfad der
 fehlerhaften Anwendung: C:\Windows\SysWOW64\DllHost.exe  Pfad des fehlerhaften Moduls:
 C:\Windows\syswow64\ole32.dll  Berichtskennung: dce26e68-874d-11e2-9304-20cf3018582c
Error - 07.03.2013 14:19:26 | Computer Name = Asus-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385,
 Zeitstempel: 0x4a5bc6b7  Name des fehlerhaften Moduls: rasdlg.dll_unloaded, Version:, Zeitstempel: 0x4a5bdadd  Ausnahmecode: 0xc0000005  Fehleroffset: 0x6a06bcd2
 des fehlerhaften Prozesses: 0x377c  Startzeit der fehlerhaften Anwendung: 0x01ce17b95c87b9a4
 der fehlerhaften Anwendung: C:\Windows\SysWOW64\DllHost.exe  Pfad des fehlerhaften
 Moduls: rasdlg.dll  Berichtskennung: 8a9fea83-8753-11e2-9304-20cf3018582c
Error - 08.03.2013 20:17:34 | Computer Name = Asus-PC | Source = Application Hang | ID = 1002
Description = Programm MovieMaker.exe, Version 15.4.3555.308 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf 
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: 43b0    Startzeit: 01ce1c5b664da6ae    Endzeit: 25    Anwendungspfad:
 C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe    Berichts-ID: b29d1621-884e-11e2-9304-20cf3018582c

Error - 09.03.2013 08:12:50 | Computer Name = Asus-PC | Source = VSS | ID = 8193
Description = 
Error - 09.03.2013 08:12:50 | Computer Name = Asus-PC | Source = VSS | ID = 8193
Description = 
Error - 09.03.2013 08:12:51 | Computer Name = Asus-PC | Source = VSS | ID = 8193
Description = 
Error - 09.03.2013 08:28:34 | Computer Name = Asus-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Skype.exe, Version:, Zeitstempel:
 0x50ec1757  Name des fehlerhaften Moduls: virtualCamera.ax, Version:, Zeitstempel:
 0x4ab990e2  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000094e1  ID des fehlerhaften Prozesses:
 0xb78  Startzeit der fehlerhaften Anwendung: 0x01ce1cbd3b02a70e  Pfad der fehlerhaften
 Anwendung: C:\Program Files (x86)\Skype\Phone\Skype.exe  Pfad des fehlerhaften Moduls:
 C:\Program Files (x86)\asus\VirtualCamera\virtualCamera.ax  Berichtskennung: db926340-88b4-11e2-9304-20cf3018582c
Error - 10.03.2013 19:03:33 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error - 12.03.2013 09:39:30 | Computer Name = Asus-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
 (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
 Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
 des "version"-Attributs im assemblyIdentity-Element ist ungültig.
[ Media Center Events ]
Error - 22.02.2013 17:00:01 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 22:00:01 - Fehler beim Herstellen der Internetverbindung.  22:00:01 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 17:00:07 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 22:00:06 - Fehler beim Herstellen der Internetverbindung.  22:00:06 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 18:00:12 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 23:00:12 - Fehler beim Herstellen der Internetverbindung.  23:00:12 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 18:00:18 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 23:00:17 - Fehler beim Herstellen der Internetverbindung.  23:00:17 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 19:00:36 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 00:00:36 - Fehler beim Herstellen der Internetverbindung.  00:00:36 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 19:00:50 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 00:00:41 - Fehler beim Herstellen der Internetverbindung.  00:00:41 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 20:01:14 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 01:01:14 - Fehler beim Herstellen der Internetverbindung.  01:01:14 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 20:01:39 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 01:01:20 - Fehler beim Herstellen der Internetverbindung.  01:01:20 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 21:01:55 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 02:01:55 - Fehler beim Herstellen der Internetverbindung.  02:01:55 
-     Serververbindung konnte nicht hergestellt werden..  
Error - 22.02.2013 21:02:07 | Computer Name = Asus-PC | Source = MCUpdate | ID = 0
Description = 02:02:00 - Fehler beim Herstellen der Internetverbindung.  02:02:00 
-     Serververbindung konnte nicht hergestellt werden..  
[ System Events ]
Error - 11.03.2013 15:25:52 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 11.03.2013 15:27:16 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 11.03.2013 15:27:18 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 11.03.2013 18:49:27 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 12.03.2013 02:49:45 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 12.03.2013 08:48:28 | Computer Name = Asus-PC | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst SolutoService erreicht.
Error - 12.03.2013 08:50:15 | Computer Name = Asus-PC | Source = DCOM | ID = 10016
Description = 
Error - 12.03.2013 18:15:49 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 12.03.2013 18:18:19 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
Error - 13.03.2013 00:27:13 | Computer Name = Asus-PC | Source = ipnathlp | ID = 31004
Description = 
< End of report >

Alt 13.03.2013, 16:10   #4
/// Winkelfunktion
/// TB-Süch-Tiger™
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

Rootkitscan mit GMER

Bitte lade dir GMER Rootkit Scanner GMER herunter: (Dateiname zufällig)
  • Schließe alle anderen Programme, deaktiviere deinen Virenscanner und trenne den Rechner vom Internet bevor du GMER startest.
  • Sollte sich nach dem Start ein Fenster mit folgender Warnung öffnen:
    WARNING !!!
    GMER has found system modification, which might have been caused by ROOTKIT activity.
    Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei: IAT/EAT und Show All
  • Setze den Haken bei Quickscan und entferne ihn bei allen anderen Laufwerken.
  • Starte den Scan mit "Scan".
  • Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!

Tauchen Probleme auf?
  • Probiere alternativ den abgesicherten Modus.
  • Erhältst du einen Bluescreen, dann entferne den Haken vor Devices.

Anschließend bitte MBAR ausführen:

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
Logfiles bitte immer in CODE-Tags posten

Alt 13.03.2013, 19:16   #5
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

und hier kommt auch schon der Gmer:
GMER 2.1.19155 - hxxp://www.gmer.net
Rootkit scan 2013-03-13 19:07:44
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB3O 298,09GB
Running: gmer_2.1.19155.exe; Driver: C:\Users\Asus\AppData\Local\Temp\pxldrpoc.sys

---- Threads - GMER 2.1 ----

Thread  C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [760:768]  000007fefc95cc10
Thread  C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [760:776]  000007fefc81b564
Thread  C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [760:836]  000007fefc81b564
Thread  C:\Windows\System32\svchost.exe [944:1200]                                         000007fef7fd818c
Thread  C:\Windows\System32\svchost.exe [944:1204]                                         000007fef77259a0
Thread  C:\Windows\System32\svchost.exe [944:2368]                                         000007fef68f88f8
Thread  C:\Windows\System32\svchost.exe [944:656]                                          000007feedf244e0
Thread  C:\Windows\System32\svchost.exe [944:1168]                                         000007feeb908a4c
Thread  C:\Windows\System32\svchost.exe [944:8076]                                         000007fef52814a0
Thread  C:\Windows\System32\svchost.exe [944:3768]                                         000007fef526a2b0
Thread  C:\Windows\system32\taskhost.exe [1940:2020]                                       000007fef8311010
Thread  C:\Windows\system32\taskhost.exe [1940:2036]                                       000007fef6511f38
Thread  C:\Windows\Explorer.EXE [1708:2972]                                                000007fef7fd818c
Thread  C:\Program Files\Windows Media Player\wmpnetwk.exe [4736:4964]                     000007fef8e22a7c
Thread  C:\Windows\System32\svchost.exe [3688:3088]                                        000007feea939688
Thread  C:\Windows\System32\spoolsv.exe [1712:6008]                                        000007fef5e710c8
Thread  C:\Windows\System32\spoolsv.exe [1712:6456]                                        000007fef4a26144
Thread  C:\Windows\System32\spoolsv.exe [1712:6128]                                        000007fef3555fd0
Thread  C:\Windows\System32\spoolsv.exe [1712:5676]                                        000007fef5e13438
Thread  C:\Windows\System32\spoolsv.exe [1712:6664]                                        000007fef35563ec
Thread  C:\Windows\System32\spoolsv.exe [1712:3512]                                        000007fef74d5e5c
Thread  C:\Windows\System32\spoolsv.exe [1712:7148]                                        000007fef2255074

---- EOF - GMER 2.1 ----
und hier das ergebnis von malwarebytes:
Malwarebytes Anti-Rootkit BETA

Database version: v2013.03.13.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [administrator]

13.03.2013 19:36:14
mbar-log-2013-03-13 (19-36-14).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled: 
Objects scanned: 29117
Time elapsed: 21 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)


Alt 14.03.2013, 10:45   #6
/// Winkelfunktion
/// TB-Süch-Tiger™
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal


Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
--> Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

Alt 14.03.2013, 17:43   #7
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

dein wunsch sei mir befehl!
Alt 14.03.2013, 21:55   #8
/// Winkelfunktion
/// TB-Süch-Tiger™
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

dein wunsch sei mir befehl!
ich erteile dir doch nur "Befehle", um deinen "Befehl" nach Hilfe gerecht zu werden

Die Logs sind bisher allesamt unauffällig.
Bevor wir noch größeren Aufwand betreiben: Hast du mit FF mal ein neues Profil getestet? => Firefox-Profile erstellen und löschen | Hilfe zu Firefox

Das alte Profil NICHT löschen. Starte den FF mit frischem Profil und probiere da mal YT aus und berichte
Logfiles bitte immer in CODE-Tags posten

Alt 14.03.2013, 22:35   #9
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

ich würde mich nie erdreisten, in den heiligen hallen des trojaner-board befehle zu erteilen - ich kann nur bitten und hoffen, dass mich jemand erhört

wie du mir empfohlen hast, habe ich ein neues profil bei ff erstellt und warte nun ab, was passiert. allerdings ist mir dabei etwas eingefallen: das störgeräusch ist außer bei yt auch schon bei anderen audio-anwendungen aufgetreten, z.b. bei itunes. hm... *grübel*

Alt 15.03.2013, 12:03   #10
/// Winkelfunktion
/// TB-Süch-Tiger™
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

ich kann nur bitten und hoffen, dass mich jemand erhört
Dein Erhörungswunsch sei mir Befehl

das störgeräusch ist außer bei yt auch schon bei anderen audio-anwendungen aufgetreten, z.b. bei itunes. hm... *grübel*
Weißt du noch in etwa seit wann du das hast bzw. was du geändert hast? Vllt ein Treiberupdate oder so?
Hast du schonmal im abgesicherten Modous getestet?
Logfiles bitte immer in CODE-Tags posten

Alt 15.03.2013, 14:28   #11
Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal - Standard

Bei Abspielen von Videos - lautes Störgeräusch, PC reagiert nicht, nach >1Min. wieder normal

hehe also den treiber habe ich eben gecheckt und er ist auf dem aktuellsten stand: VIA Hight Definition Audio, Treiberdatum 09.07.2009, Version

hm, seit wann ich es habe, weiß ich nicht. ich hatte mal die vermutung, es könnte an überhitzung liegen. kann das sein? das mit dem abgesicherten modus probier ich mal


