| kruemmel |  31.03.2013 15:29 |        Hallo Heiko!  
Bin deiner Anweisung Schritt für Schritt gefolgt (Herzliches :dankeschoen: für die tolle Anleitung! )und zu folgenden Ergebnissen gekommen: 
Schritt 1: 
Zip- Datei befindet sich im Anhang.  
Schritt 2: unter Systemsteuerung  -> Programme deinstallieren finde ich „bittorrent toolbar“ nicht.  
Habe den Laptop gebraucht übernommen und hatte keine Ahnung davon  
Schritt 3:  
AdwCleaner Logfile:   Code:  
 # AdwCleaner v2.115 - Datei am 31/03/2013 um 16:05:57 erstellt 
# Aktualisiert am 17/03/2013 von Xplode 
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) 
# Benutzer : Hannelore - KARIN-PC 
# Bootmodus : Normal 
# Ausgeführt unter : C:\Users\Hannelore\Desktop\adwcleaner.exe 
# Option [Löschen]     
**** [Dienste] ****     
***** [Dateien / Ordner] *****   
Datei Gelöscht : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml 
Datei Gelöscht : C:\Users\HANNEL~1\AppData\Local\Temp\searchqutoolbar-manifest.xml 
Datei Gelöscht : C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\74v2hsto.default\searchplugins\Askcom.xml 
Datei Gelöscht : C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\74v2hsto.default\searchplugins\Search_Results.xml 
Ordner Gelöscht : C:\ProgramData\Ask 
Ordner Gelöscht : C:\ProgramData\boost_interprocess 
Ordner Gelöscht : C:\ProgramData\Trymedia 
Ordner Gelöscht : C:\Users\Hannelore\AppData\LocalLow\Conduit 
Ordner Gelöscht : C:\Users\Hannelore\AppData\LocalLow\ConduitEngine 
Ordner Gelöscht : C:\Users\Hannelore\AppData\LocalLow\PriceGong 
Ordner Gelöscht : C:\Users\Hannelore\AppData\LocalLow\searchquband 
Ordner Gelöscht : C:\Users\Karin\AppData\Local\PackageAware 
Ordner Gelöscht : C:\Users\Karin\AppData\LocalLow\boost_interprocess 
Ordner Gelöscht : C:\Users\Karin\AppData\LocalLow\Conduit 
Ordner Gelöscht : C:\Users\Karin\AppData\LocalLow\PriceGong 
Ordner Gelöscht : C:\Users\Karin\AppData\LocalLow\searchquband 
Ordner Gelöscht : C:\Users\Karin\AppData\LocalLow\Searchqutoolbar 
Ordner Gelöscht : C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\74v2hsto.default\Conduit 
Ordner Gelöscht : C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\74v2hsto.default\ConduitCommon   
***** [Registrierungsdatenbank] *****   
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit 
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\conduitEngine 
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong 
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\searchqutoolbar 
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar 
Schlüssel Gelöscht : HKCU\Software\DataMngr 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0} 
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2849855 
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} 
Schlüssel Gelöscht : HKLM\Software\Conduit 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS 
Schlüssel Gelöscht : HKLM\Software\PIP 
Schlüssel Gelöscht : HKLM\SOFTWARE\Software 
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] 
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]   
***** [Internet Browser] *****   
-\\ Internet Explorer v8.0.7601.17514   
[OK] Die Registrierungsdatenbank ist sauber.   
-\\ Mozilla Firefox v19.0.2 (en-US)   
Datei : C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\74v2hsto.default\prefs.js   
Gelöscht : user_pref("CT2849855..clientLogIsEnabled", true); 
Gelöscht : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] 
Gelöscht : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] 
Gelöscht : user_pref("CT2849855.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); 
Gelöscht : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); 
Gelöscht : user_pref("CT2849855.AppTrackingLastCheckTime", "Fri Nov 11 2011 21:59:44 GMT+0100"); 
Gelöscht : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true); 
Gelöscht : user_pref("CT2849855.CTID", "CT2849855"); 
Gelöscht : user_pref("CT2849855.CurrentServerDate", "12-11-2011"); 
Gelöscht : user_pref("CT2849855.DialogsAlignMode", "LTR"); 
Gelöscht : user_pref("CT2849855.DialogsGetterLastCheckTime", "Fri Nov 11 2011 21:23:25 GMT+0100"); 
Gelöscht : user_pref("CT2849855.DownloadReferralCookieData", ""); 
Gelöscht : user_pref("CT2849855.EMailNotifierPollDate", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedLastCount129349796701375473", 161); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313974171006416", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313975698350231", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313976370850190", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313976648818968", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313977444757117", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313980389131455", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313980655381977", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313980886163259", "Sat Dec 11 2010 08:59:31 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313981234756535", "Sat Dec 11 2010 08:59:31 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313983226631720", "Sat Dec 11 2010 08:59:31 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedPollDate129313983607725691", "Sat Dec 11 2010 08:59:31 GMT+0100"); 
Gelöscht : user_pref("CT2849855.FeedTTL129313974171006416", 10); 
Gelöscht : user_pref("CT2849855.FeedTTL129313977444757117", 15); 
Gelöscht : user_pref("CT2849855.FeedTTL129313980655381977", 5); 
Gelöscht : user_pref("CT2849855.FeedTTL129313981234756535", 5); 
Gelöscht : user_pref("CT2849855.FirstServerDate", "11-12-2010"); 
Gelöscht : user_pref("CT2849855.FirstTime", true); 
Gelöscht : user_pref("CT2849855.FirstTimeFF3", true); 
Gelöscht : user_pref("CT2849855.FixPageNotFoundErrors", false); 
Gelöscht : user_pref("CT2849855.GroupingServerCheckInterval", 1440); 
Gelöscht : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); 
Gelöscht : user_pref("CT2849855.HasUserGlobalKeys", true); 
Gelöscht : user_pref("CT2849855.HomePageProtectorEnabled", false); 
Gelöscht : user_pref("CT2849855.Initialize", true); 
Gelöscht : user_pref("CT2849855.InitializeCommonPrefs", true); 
Gelöscht : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3); 
Gelöscht : user_pref("CT2849855.InstallationType", "UnknownIntegration"); 
Gelöscht : user_pref("CT2849855.InstalledDate", "Sat Dec 11 2010 08:59:30 GMT+0100"); 
Gelöscht : user_pref("CT2849855.IsAlertDBUpdated", true); 
Gelöscht : user_pref("CT2849855.IsGrouping", false); 
Gelöscht : user_pref("CT2849855.IsMulticommunity", false); 
Gelöscht : user_pref("CT2849855.IsOpenThankYouPage", true); 
Gelöscht : user_pref("CT2849855.IsOpenUninstallPage", false); 
Gelöscht : user_pref("CT2849855.LanguagePackLastCheckTime", "Fri Nov 11 2011 21:23:24 GMT+0100"); 
Gelöscht : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440); 
Gelöscht : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] 
Gelöscht : user_pref("CT2849855.LastLogin_3.2.5.2", "Sat Apr 16 2011 10:31:08 GMT+0200"); 
Gelöscht : user_pref("CT2849855.LastLogin_3.3.3.2", "Fri Jun 24 2011 16:25:36 GMT+0200"); 
Gelöscht : user_pref("CT2849855.LastLogin_3.5.0.12", "Mon Aug 15 2011 17:55:11 GMT+0200"); 
Gelöscht : user_pref("CT2849855.LastLogin_3.6.0.10", "Thu Sep 22 2011 17:11:00 GMT+0200"); 
Gelöscht : user_pref("CT2849855.LastLogin_3.7.0.6", "Tue Nov 08 2011 16:51:42 GMT+0100"); 
Gelöscht : user_pref("CT2849855.LastLogin_3.8.0.8", "Sat Nov 12 2011 17:33:20 GMT+0100"); 
Gelöscht : user_pref("CT2849855.LatestVersion", "3.8.0.8"); 
Gelöscht : user_pref("CT2849855.Locale", "de"); 
Gelöscht : user_pref("CT2849855.MCDetectTooltipHeight", "83"); 
Gelöscht : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); 
Gelöscht : user_pref("CT2849855.MCDetectTooltipWidth", "295"); 
Gelöscht : user_pref("CT2849855.MyStuffEnabledAtInstallation", true); 
Gelöscht : user_pref("CT2849855.SearchEngineBeforeUnload", "Google"); 
Gelöscht : user_pref("CT2849855.SearchFromAddressBarIsInit", true); 
Gelöscht : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...] 
Gelöscht : user_pref("CT2849855.SearchInNewTabEnabled", true); 
Gelöscht : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440); 
Gelöscht : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Fri Nov 11 2011 21:23:23 GMT+0100"); 
Gelöscht : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] 
Gelöscht : user_pref("CT2849855.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...] 
Gelöscht : user_pref("CT2849855.SearchProtectorEnabled", false); 
Gelöscht : user_pref("CT2849855.SearchProtectorToolbarDisabled", false); 
Gelöscht : user_pref("CT2849855.ServiceMapLastCheckTime", "Fri Nov 11 2011 21:23:24 GMT+0100"); 
Gelöscht : user_pref("CT2849855.SettingsLastCheckTime", "Sat Nov 12 2011 20:33:03 GMT+0100"); 
Gelöscht : user_pref("CT2849855.SettingsLastUpdate", "1319756020"); 
Gelöscht : user_pref("CT2849855.ThirdPartyComponentsInterval", 504); 
Gelöscht : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Mon Oct 24 2011 18:43:28 GMT+0200"); 
Gelöscht : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1255348257"); 
Gelöscht : user_pref("CT2849855.ToolbarShrinkedFromSetup", false); 
Gelöscht : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855"); 
Gelöscht : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] 
Gelöscht : user_pref("CT2849855.UserID", "UN43765846068240566"); 
Gelöscht : user_pref("CT2849855.ValidationData_Search", 0); 
Gelöscht : user_pref("CT2849855.ValidationData_Toolbar", 2); 
Gelöscht : user_pref("CT2849855.WeatherNetwork", ""); 
Gelöscht : user_pref("CT2849855.WeatherPollDate", "Sat Dec 11 2010 08:59:31 GMT+0100"); 
Gelöscht : user_pref("CT2849855.WeatherUnit", "C"); 
Gelöscht : user_pref("CT2849855.alertChannelId", "1241896"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e.:2z527", "2423"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6F71736B73717371"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737577797179777977242F4B4947[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b-0?3g>d", "6C3C6841707341707A78727476204B757B4D254F7D51252A52[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", ""); 
Gelöscht : user_pref("CT2849855.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477A213F3E484F4E4D464[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "6F6B6D3E424275407A777072457979774A7C7A4F21"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6F71736B73717271737A73"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b90e@8ff=eg", "393F352F3E"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443"); 
Gelöscht : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...] 
Gelöscht : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D"); 
Gelöscht : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B"); 
Gelöscht : user_pref("CT2849855.backendstorage.cb_firstuse0100", "31"); 
Gelöscht : user_pref("CT2849855.backendstorage.cbfirsttime", "5765642053657020323820323031312030393A32303A35372[...] 
Gelöscht : user_pref("CT2849855.backendstorage.enableinj", ""); 
Gelöscht : user_pref("CT2849855.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...] 
Gelöscht : user_pref("CT2849855.backendstorage.url_history", "687474703A2F2F7777772E676F6F676C652E636F6D2F73656[...] 
Gelöscht : user_pref("CT2849855.backendstorage.url_history_time", "31333139353338363238343736"); 
Gelöscht : user_pref("CT2849855.components.1000034", false); 
Gelöscht : user_pref("CT2849855.components.1000234", false); 
Gelöscht : user_pref("CT2849855.components.129349796699812960", false); 
Gelöscht : user_pref("CT2849855.components.129349796701375473", false); 
Gelöscht : user_pref("CT2849855.components.129349796701375474", false); 
Gelöscht : user_pref("CT2849855.components.129349796701531725", false); 
Gelöscht : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] 
Gelöscht : user_pref("CT2849855.globalFirstTimeInfoLastCheckTime", "Sat Nov 12 2011 17:33:20 GMT+0100"); 
Gelöscht : user_pref("CT2849855.homepageProtectorEnableByLogin", true); 
Gelöscht : user_pref("CT2849855.initDone", true); 
Gelöscht : user_pref("CT2849855.isAppTrackingManagerOn", true); 
Gelöscht : user_pref("CT2849855.myStuffEnabled", true); 
Gelöscht : user_pref("CT2849855.myStuffPublihserMinWidth", 400); 
Gelöscht : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] 
Gelöscht : user_pref("CT2849855.myStuffServiceIntervalMM", 1440); 
Gelöscht : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] 
Gelöscht : user_pref("CT2849855.oldAppsList", "129349796699187955,129349796699500456,1000234,129349796699656708[...] 
Gelöscht : user_pref("CT2849855.revertSettingsEnabled", true); 
Gelöscht : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10); 
Gelöscht : user_pref("CT2849855.searchProtectorEnableByLogin", true); 
Gelöscht : user_pref("CT2849855.testingCtid", ""); 
Gelöscht : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Fri Nov 11 2011 21:23:24 GMT+0100"); 
Gelöscht : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Tue Nov 01 2011 17:36:28 GMT+0100"); 
Gelöscht : user_pref("CT2849855.usagesFlag", 2); 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1241896/1237569/AT", "\"0\"[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/AT", "\"0\"")[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63438026930213[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/20[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=11/8/20[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/21/2[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/27/2[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/30/2[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/17/20[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/20[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2849855&octid=[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...] 
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"07b[...] 
Gelöscht : user_pref("CommunityToolbar.EngineOwner", ""); 
Gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}"); 
Gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bittorrentbar_de"); 
Gelöscht : user_pref("CommunityToolbar.IsEngineShown", true); 
Gelöscht : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); 
Gelöscht : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Karin\\AppData\\Roaming\\Mozilla\\F[...] 
Gelöscht : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.8.0.8"); 
Gelöscht : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...] 
Gelöscht : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/menu_dlg/pg_dlg.html#pg_e[...] 
Gelöscht : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2849855"); 
Gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}"); 
Gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bittorrentbar_de"); 
Gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...] 
Gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2849855"); 
Gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2849855"); 
Gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Apr 17 2011 18:45:35 GMT+02[...] 
Gelöscht : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440); 
Gelöscht : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Jun 22 2011 23:29:02 GMT+0200"); 
Gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); 
Gelöscht : user_pref("CommunityToolbar.alert.locale", "en"); 
Gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); 
Gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu Jun 23 2011 22:13:44 GMT+0200"); 
Gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); 
Gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); 
Gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); 
Gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false); 
Gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); 
Gelöscht : user_pref("CommunityToolbar.alert.userId", "7d93ba28-6f63-4a8d-8374-4acad3e85a93"); 
Gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Fri Nov 11 2011 21:23:24 GMT+0100"); 
Gelöscht : user_pref("CommunityToolbar.globalUserId", "d421b1e9-e237-4fc3-967c-ee8fd1085fa1"); 
Gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); 
Gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); 
Gelöscht : user_pref("CommunityToolbar.killedEngine", true); 
Gelöscht : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Nov 08 2011 20:52:2[...] 
Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); 
Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Nov 11 2011 21:23:34 GMT+010[...] 
Gelöscht : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); 
Gelöscht : user_pref("CommunityToolbar.notifications.locale", "en"); 
Gelöscht : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); 
Gelöscht : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Nov 11 2011 21:23:24 GMT+0100"); 
Gelöscht : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); 
Gelöscht : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); 
Gelöscht : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); 
Gelöscht : user_pref("CommunityToolbar.notifications.showTrayIcon", false); 
Gelöscht : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); 
Gelöscht : user_pref("CommunityToolbar.notifications.userId", "6a5363cf-2740-4dd9-a039-7d8ee15fca61"); 
Gelöscht : user_pref("CommunityToolbar.undefined", ""); 
Gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); 
Gelöscht : user_pref("browser.search.defaultenginename", "Search Results"); 
Gelöscht : user_pref("browser.search.order.1", "Search Results"); 
Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); 
Gelöscht : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=410&sr=0&q=");   
Datei : C:\Users\Hannelore\AppData\Roaming\Mozilla\Firefox\Profiles\d41qh64p.default\prefs.js   
Gelöscht : user_pref("browser.search.order.1", "Ask.com"); 
Gelöscht : user_pref("browser.search.selectedEngine", "Ask.com"); 
Gelöscht : user_pref("browser.startup.homepage", "hxxp://www.ask.com/?l=dis&o=14672");   
*************************   
AdwCleaner[S1].txt - [27809 octets] - [31/03/2013 16:05:57]   
########## EOF - C:\AdwCleaner[S1].txt - [27870 octets] ##########   [/CODE] 
--- --- ---  
Schritt 4: OTL Logfile:   Code:  
 OTL logfile created on: 31.03.2013 16:13:13 - Run 4 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Hannelore\Desktop 
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7601.17514) 
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 
  
3,43 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 73,06% Memory free 
6,85 Gb Paging File | 5,90 Gb Available in Paging File | 86,10% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 424,66 Gb Total Space | 121,03 Gb Free Space | 28,50% Space Free | Partition Type: NTFS 
Drive D: | 40,00 Gb Total Space | 30,00 Gb Free Space | 75,01% Space Free | Partition Type: NTFS 
  
Computer Name: KARIN-PC | User Name: Hannelore | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - [2013.03.30 21:41:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Hannelore\Desktop\OTL.exe 
PRC - [2012.12.23 21:33:30 | 000,144,520 | R--- | M] (Symantec Corporation) -- C:\Programme\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe 
PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe 
PRC - [2012.11.23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe 
PRC - [2012.11.12 18:56:01 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Programme\SUPERAntiSpyware\SASCORE.EXE 
PRC - [2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe 
PRC - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe 
PRC - [2010.07.27 12:01:09 | 000,484,816 | ---- | M] () -- C:\Programme\3DataManager\3DataManager_Launcher.exe 
PRC - [2010.07.08 14:18:29 | 000,333,264 | ---- | M] () -- C:\Programme\3DataManager\WTGService.exe 
PRC - [2009.12.10 09:48:26 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 
PRC - [2009.12.10 09:48:24 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 
PRC - [2009.11.07 04:46:52 | 000,020,480 | ---- | M] (X10) -- C:\Programme\Common Files\X10\Common\X10nets.exe 
PRC - [2009.10.02 14:26:12 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 
PRC - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 
PRC - [2009.08.18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 
PRC - [2009.02.03 15:53:00 | 001,155,072 | ---- | M] (MAGIX AG) -- C:\Programme\Common Files\MAGIX Services\Database\bin\FABS.exe 
PRC - [2009.01.12 14:15:52 | 000,071,096 | ---- | M] () -- C:\Programme\Blaze Media Pro\NMSAccess32.exe 
PRC - [2008.03.19 12:30:46 | 002,558,464 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\Windows\System32\hasplms.exe 
PRC - [2007.07.24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe 
  
   ========== Modules (No Company Name) ========== 
  
MOD - [2012.05.30 08:51:08 | 000,699,280 | R--- | M] () -- C:\Programme\Norton Internet Security\Engine\20.3.0.36\wincfi39.dll 
MOD - [2010.07.27 12:01:09 | 000,484,816 | ---- | M] () -- C:\Programme\3DataManager\3DataManager_Launcher.exe 
  
   ========== Services (SafeList) ========== 
  
SRV - [2013.03.31 09:21:11 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) 
SRV - [2013.03.08 11:28:35 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) 
SRV - [2012.12.23 21:33:30 | 000,144,520 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe -- (NIS) 
SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) 
SRV - [2012.11.12 18:56:01 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Programme\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE) 
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv) 
SRV - [2010.11.20 14:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) 
SRV - [2010.09.27 10:55:53 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) 
SRV - [2010.07.08 14:18:29 | 000,333,264 | ---- | M] () [Auto | Running] -- C:\Programme\3DataManager\WTGService.exe -- (WTGService) 
SRV - [2009.12.10 09:48:26 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) 
SRV - [2009.12.10 09:48:24 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) 
SRV - [2009.11.07 04:46:52 | 000,020,480 | ---- | M] (X10) [Auto | Running] -- C:\Programme\Common Files\X10\Common\X10nets.exe -- (x10nets) 
SRV - [2009.10.22 18:05:40 | 000,118,560 | ---- | M] (Wistron Corp.) [On_Demand | Stopped] -- C:\Programme\Launch Manager\WisLMSvc.exe -- (WisLMSvc) 
SRV - [2009.10.02 14:26:12 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) 
SRV - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) 
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) 
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend) 
SRV - [2009.02.03 15:53:00 | 001,155,072 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs) 
SRV - [2009.01.12 14:15:52 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\Blaze Media Pro\NMSAccess32.exe -- (NMSAccess) 
SRV - [2008.08.07 11:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Programme\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) 
SRV - [2008.03.19 12:30:46 | 002,558,464 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Auto | Running] -- C:\Windows\System32\hasplms.exe -- (hasplms) 
SRV - [2007.07.24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Programme\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) 
SRV - [2006.10.26 15:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RtsUCcid.sys -- (USBCCID) 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (RtsUIR) 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard) 
DRV - [2013.03.22 03:52:23 | 000,997,464 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\BASHDefs\20130322.001\BHDrvx86.sys -- (BHDrvx86) 
DRV - [2013.03.17 11:06:41 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent) 
DRV - [2013.03.16 02:00:00 | 001,603,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20130330.009\NAVEX15.SYS -- (NAVEX15) 
DRV - [2013.03.16 02:00:00 | 000,093,296 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20130330.009\NAVENG.SYS -- (NAVENG) 
DRV - [2013.03.13 16:57:20 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\IPSDefs\20130329.001\IDSvix86.sys -- (IDSVix86) 
DRV - [2013.01.30 21:18:18 | 000,338,592 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\symnets.sys -- (SymNetS) 
DRV - [2013.01.30 21:18:06 | 000,934,488 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\SymEFA.sys -- (SymEFA) 
DRV - [2013.01.28 19:45:18 | 000,602,712 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\srtsp.sys -- (SRTSP) 
DRV - [2013.01.28 19:45:18 | 000,032,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\srtspx.sys -- (SRTSPX) 
DRV - [2013.01.21 20:15:32 | 000,367,704 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\SymDS.sys -- (SymDS) 
DRV - [2012.11.15 20:45:16 | 000,036,512 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SymIMV.sys -- (SymIM) 
DRV - [2012.11.15 20:22:02 | 000,175,264 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\Ironx86.sys -- (SymIRON) 
DRV - [2012.11.15 20:18:04 | 000,134,304 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\ccSetx86.sys -- (ccSet_NIS) 
DRV - [2012.09.25 18:06:54 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Programme\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) 
DRV - [2012.09.08 12:47:04 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) 
DRV - [2012.09.08 12:47:04 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) 
DRV - [2012.09.08 12:47:04 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) 
DRV - [2012.09.08 12:47:04 | 000,010,240 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter) 
DRV - [2012.08.09 09:10:01 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Programme\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) 
DRV - [2011.07.22 18:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV) 
DRV - [2011.07.12 23:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL) 
DRV - [2010.11.20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) 
DRV - [2010.11.20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) 
DRV - [2010.04.01 10:13:38 | 001,009,184 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192se.sys -- (rtl8192se) 
DRV - [2010.02.10 16:01:10 | 000,132,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd) 
DRV - [2010.01.08 04:50:08 | 000,232,448 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) 
DRV - [2009.12.22 19:18:58 | 000,065,576 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) 
DRV - [2009.12.02 16:54:20 | 000,020,008 | ---- | M] (Psychology Software Tools) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\prtdrv.sys -- (PRTDRV) 
DRV - [2009.09.18 05:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI) 
DRV - [2009.08.13 17:39:40 | 000,786,400 | ---- | M] (DiBcom SA) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mod7700.sys -- (mod7700) 
DRV - [2009.07.31 03:45:22 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR) 
DRV - [2009.07.14 01:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp) 
DRV - [2009.05.13 13:47:30 | 000,027,160 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\x10ufx2.sys -- (XUIF) 
DRV - [2009.05.13 13:26:26 | 000,013,720 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\x10hid.sys -- (X10Hid) 
DRV - [2008.03.18 15:09:16 | 000,350,720 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aksfridge.sys -- (aksfridge) 
DRV - [2008.02.11 15:55:04 | 000,586,240 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (Hardlock) 
DRV - [2007.07.23 14:12:44 | 000,046,336 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\akshhl.sys -- (akshhl) 
DRV - [2007.07.05 14:16:56 | 000,238,976 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\akshasp.sys -- (akshasp) 
DRV - [2007.07.05 14:16:56 | 000,014,976 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\aksusb.sys -- (aksusb) 
DRV - [2006.04.12 16:19:54 | 000,011,776 | ---- | M] (Psychology Software Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SRBoxDRv.sys -- (SRBoxDRv) 
DRV - [2002.10.25 14:49:48 | 000,007,168 | ---- | M] (Psychology Software Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PortDRv.sys -- (PortDRv) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\..\SearchScopes,DefaultScope =  
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
  
  
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =  
  
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =  
  
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com [binary data] 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://medion.msn.com [binary data] 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aldi.com 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\SearchScopes\{4CD44656-8609-47F5-BB74-4FDFA8AA39BF}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
IE - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaultengine: "Google" 
FF - prefs.js..browser.search.defaultenginename: "Google" 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.5 
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0 
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:5.5 
FF - user.js - File not found 
  
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll () 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) 
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) 
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) 
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found 
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@millisecond.com/npInquisit,version=3.0: C:\Program Files\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3050.dll (Millisecond Software) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF - HKCU\Software\MozillaPlugins\@millisecond.com/npInquisit,version=3.0: C:\Program Files\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3050.dll (Millisecond Software) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.10.18 18:03:38 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn\ [2013.03.31 16:08:24 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.09.16 19:36:35 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFFPlgn\ [2013.03.17 14:39:05 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.08 11:28:35 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.31 09:24:52 | 000,000,000 | ---D | M] 
  
[2011.01.12 20:51:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannelore\AppData\Roaming\mozilla\Extensions 
[2013.03.30 21:14:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannelore\AppData\Roaming\mozilla\Firefox\Profiles\d41qh64p.default\extensions 
[2013.03.30 21:13:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions 
[2013.03.08 11:28:35 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll 
[2012.11.20 08:17:14 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml 
[2013.02.20 21:58:47 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml 
  
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts 
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC) 
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programme\Norton Internet Security\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation) 
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton Internet Security\Engine\20.3.0.36\IPS\IPSBHO.dll (Symantec Corporation) 
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) 
O2 - BHO: (Windows Live ID-Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) 
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) 
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Norton Internet Security\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation) 
O3 - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. 
O3 - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\Toolbar\WebBrowser: (no name) - {64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} - No CLSID value found. 
O3 - HKU\S-1-5-21-2565143384-857478621-2599862508-1003\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Norton Internet Security\Engine\20.3.0.36\CoIEPlg.dll (Symantec Corporation) 
O4 - Startup: C:\Users\Karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk =  File not found 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) 
O9 - Extra Button: eBay.at - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/5221-29898-17534-1/4 File not found 
O9 - Extra 'Tools' menuitem : eBay.at - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/5221-29898-17534-1/4 File not found 
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) 
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) 
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) 
O13 - gopher Prefix: missing 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Value error.) 
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 1.7.0_17) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 10.17.2) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{142F2D10-AFAC-4319-8B97-F2F9242E1639}: DhcpNameServer = 143.205.176.16 143.205.176.17 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{550500B5-3829-4243-93C4-E08B690AD997}: DhcpNameServer = 61.177.7.1 218.104.32.106 168.95.1.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8A34EE5B-9CDB-4BBC-A369-A031E82A7022}: DhcpNameServer = 192.168.1.1 
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) 
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) 
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) 
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) 
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) 
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) 
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2013.03.31 09:42:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java 
[2013.03.31 09:42:50 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe 
[2013.03.31 09:42:07 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe 
[2013.03.31 09:42:07 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe 
[2013.03.31 09:42:07 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll 
[2013.03.31 09:24:40 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe 
[2013.03.31 09:24:16 | 000,000,000 | -HSD | C] -- C:\Config.Msi 
[2013.03.30 21:41:53 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Hannelore\Desktop\OTL.exe 
[2013.03.30 21:01:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} 
[2013.03.30 21:01:21 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files 
[2013.03.30 20:44:16 | 000,000,000 | ---D | C] -- C:\Users\Hannelore\AppData\Roaming\SUPERAntiSpyware.com 
[2013.03.30 20:42:25 | 000,000,000 | ---D | C] -- C:\Users\Hannelore\AppData\Local\Apps 
[2013.03.30 20:39:59 | 000,000,000 | ---D | C] -- C:\Users\Hannelore\AppData\Local\CrashDumps 
[2013.03.21 07:07:29 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys 
[2013.03.17 14:37:56 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security 
[2013.03.13 17:06:15 | 000,627,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll 
[2013.03.13 17:06:13 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll 
[2013.03.13 17:06:13 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll 
[2013.03.13 17:06:13 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll 
[2013.03.13 17:06:12 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb 
[2013.03.08 11:28:31 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox 
   ========== Files - Modified Within 30 Days ========== 
  
[2013.03.31 16:15:04 | 000,010,096 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2013.03.31 16:15:04 | 000,010,096 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2013.03.31 16:08:22 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2013.03.31 16:07:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2013.03.31 16:07:26 | 2760,847,360 | -HS- | M] () -- C:\hiberfil.sys 
[2013.03.31 16:04:53 | 000,609,993 | ---- | M] () -- C:\Users\Hannelore\Desktop\adwcleaner.exe 
[2013.03.31 15:55:03 | 000,076,088 | ---- | M] () -- C:\Users\Hannelore\Desktop\Gmer.zip 
[2013.03.31 15:53:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job 
[2013.03.31 15:37:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2013.03.31 15:20:33 | 000,659,238 | ---- | M] () -- C:\Windows\System32\perfh007.dat 
[2013.03.31 15:20:33 | 000,620,384 | ---- | M] () -- C:\Windows\System32\perfh009.dat 
[2013.03.31 15:20:33 | 000,132,776 | ---- | M] () -- C:\Windows\System32\perfc007.dat 
[2013.03.31 15:20:33 | 000,108,566 | ---- | M] () -- C:\Windows\System32\perfc009.dat 
[2013.03.31 09:41:56 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll 
[2013.03.31 09:41:56 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll 
[2013.03.31 09:41:56 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe 
[2013.03.31 09:41:56 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe 
[2013.03.31 09:41:56 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe 
[2013.03.31 09:41:56 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll 
[2013.03.31 09:24:52 | 000,001,993 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk 
[2013.03.31 09:21:11 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe 
[2013.03.31 09:21:11 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl 
[2013.03.30 21:41:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Hannelore\Desktop\OTL.exe 
[2013.03.30 21:41:18 | 000,000,000 | ---- | M] () -- C:\Users\Hannelore\defogger_reenable 
[2013.03.30 21:15:37 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk 
[2013.03.20 07:03:24 | 001,900,054 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1403000.024\Cat.DB 
[2013.03.17 14:37:57 | 000,002,427 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk 
[2013.03.17 14:36:30 | 000,014,818 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1403000.024\VT20130115.021 
[2013.03.17 11:06:41 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS 
[2013.03.17 11:06:41 | 000,007,446 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT 
[2013.03.17 11:06:41 | 000,000,806 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF 
   ========== Files Created - No Company Name ========== 
  
[2013.03.31 16:04:52 | 000,609,993 | ---- | C] () -- C:\Users\Hannelore\Desktop\adwcleaner.exe 
[2013.03.31 15:55:03 | 000,076,088 | ---- | C] () -- C:\Users\Hannelore\Desktop\Gmer.zip 
[2013.03.31 09:24:52 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 
[2013.03.31 09:24:52 | 000,001,993 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk 
[2013.03.30 21:41:18 | 000,000,000 | ---- | C] () -- C:\Users\Hannelore\defogger_reenable 
[2011.11.23 22:38:05 | 000,005,632 | ---- | C] () -- C:\Users\Hannelore\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
   ========== ZeroAccess Check ========== 
  
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] 
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] 
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Both   
< End of report >   --- --- --- 
[code] 
Extra.txt: OTL Logfile:   Code:  
 OTL Extras logfile created on: 31.03.2013 16:13:13 - Run 4 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Hannelore\Desktop 
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7601.17514) 
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy 
  
3,43 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 73,06% Memory free 
6,85 Gb Paging File | 5,90 Gb Available in Paging File | 86,10% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 424,66 Gb Total Space | 121,03 Gb Free Space | 28,50% Space Free | Partition Type: NTFS 
Drive D: | 40,00 Gb Total Space | 30,00 Gb Free Space | 75,01% Space Free | Partition Type: NTFS 
  
Computer Name: KARIN-PC | User Name: Hannelore | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) 
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) 
  
[HKEY_USERS\S-1-5-21-2565143384-857478621-2599862508-1003\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) 
htafile [open] -- "%1" %* 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) 
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = Reg Error: Unknown registry data type -- File not found 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
   ========== Firewall Settings ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
   ========== Authorized Applications List ========== 
  
   ========== Vista Active Open Ports Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{00FDA8F4-4A16-4B43-B6AB-BD2E080ADFCB}" = lport=445 | protocol=6 | dir=in | app=system |  
"{20863C92-899D-4BC2-B6D4-B07DF5E9910B}" = lport=2869 | protocol=6 | dir=in | app=system |  
"{381C4A9D-2E99-4761-9825-0D1113FF71A2}" = lport=138 | protocol=17 | dir=in | app=system |  
"{43442C62-0364-4929-AC44-17507AD93ABB}" = rport=138 | protocol=17 | dir=out | app=system |  
"{482E3ABE-9FFA-4FBC-B3EF-C9D025416028}" = rport=445 | protocol=6 | dir=out | app=system |  
"{4D5812FC-ACF7-430A-AACF-412918ED71A4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{4FC73A00-9446-447A-9095-321E0ECC7A37}" = lport=139 | protocol=6 | dir=in | app=system |  
"{5411440E-6291-466D-8D29-57CA4EEE41EE}" = rport=10243 | protocol=6 | dir=out | app=system |  
"{553D4C16-E982-4EA5-875D-2EAC9ED0E58D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{5985F74B-B438-4833-9D3C-6C3AA4940352}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{5A321B6F-0909-4FF8-A4C8-6A6B9F88CBC9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |  
"{AD89F20D-D960-407B-A6BD-B111A722E5FE}" = lport=137 | protocol=17 | dir=in | app=system |  
"{B07538A6-D577-4139-8C8D-4862CCD9E3C5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{C2B05194-C8BB-46CE-B7D3-A992D877D3D6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{C9C70879-DFD8-4D1B-976E-B3EDB4532655}" = rport=137 | protocol=17 | dir=out | app=system |  
"{CB08A578-9B8D-46E1-B4ED-FC6D4B0D9F4F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{CE754FB7-3DA3-4871-B64E-0EE957CBEA8F}" = lport=10243 | protocol=6 | dir=in | app=system |  
"{CFA10990-C342-4506-85CA-FF48F3546D8E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{D813176E-4AEC-434D-BCD3-BCADB33C4AD6}" = rport=139 | protocol=6 | dir=out | app=system |  
"{D94D469B-DE3C-49D0-A47C-CBA1191CEC65}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{DAFC1185-BEE3-47A6-AF06-1DB01472981A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |  
"{DC069F1B-29F5-46D6-9D51-FE809155FC3D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |  
"{DD858F7D-B1F0-46D2-BA87-7521BEDB4921}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{EA979150-7EF3-4085-AC29-87905B360D02}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |  
"{F9C402AB-DF38-40F0-951C-F722DD8540CB}" = lport=2869 | protocol=6 | dir=in | app=system |  
   ========== Vista Active Application Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{0279E00E-CD83-4A3E-BAEC-D7E255689D09}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |  
"{0C0CA445-2B31-421C-859F-3B1EBDAA8F5E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{10D1D10C-B65D-45FD-AA03-B2BE23F1DD87}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |  
"{186AF690-0F8B-43CA-B27B-04BDDF8C3343}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |  
"{195AED33-F8E7-4840-BA1C-8665F62FA499}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |  
"{1A8F5B54-E828-4ED1-847B-56CD34F65281}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |  
"{1FEFE585-214C-4A12-9BE8-3A1543327DCF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe |  
"{1FF68C9D-CD01-4229-9201-A965F5342820}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{20745CD8-D99C-4CBC-AAA4-F7C903104CB0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |  
"{23DE5619-1920-413B-95E8-D00B8AB0EBF8}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |  
"{251E4CC2-EDF1-4D21-8F61-472192DA4909}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |  
"{25BA9A93-FF81-42E7-99AE-83997969CCD9}" = protocol=17 | dir=in | app=c:\users\karin\appdata\roaming\dropbox\bin\dropbox.exe |  
"{39E88B47-4736-4608-A7AB-ED28B10F2B1C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{3C3E8896-3C94-4A28-B0F5-2177F7195E09}" = dir=in | app=c:\program files\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe |  
"{3CC2FE6A-39EC-4A56-9E14-E82AB4E1E2EA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{42EF726C-4A13-46CB-9089-E3020209E7FE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{4598A47E-23EF-4B6B-9FE4-C5EEE846AD47}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |  
"{45DDD9B6-988A-4157-A9CC-C586F66B752C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |  
"{477F38FA-E7C6-4546-8EE3-B5526751C424}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |  
"{502AC307-9BAE-42E7-91D8-901046D68C2C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |  
"{50571E51-FFF8-47E3-AA86-C19F8EE9D85C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{514C5B2B-DB63-4D0F-95ED-82F1CDB32BA9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{52F682DC-719F-45B8-B215-77C7D509968E}" = protocol=6 | dir=in | app=c:\users\karin\appdata\roaming\dropbox\bin\dropbox.exe |  
"{641847EF-CC40-43E5-9786-20B5B1643A9C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |  
"{664828CB-13DE-4B06-80D8-C5C8B60158D1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |  
"{74BA836C-1032-4C58-8798-E45C6B428A0D}" = protocol=6 | dir=out | app=system |  
"{757DF72B-956C-4591-AD0F-613C1BE9DA0D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe |  
"{76510D9C-1109-4F0D-A0A5-16C7EB70012D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |  
"{76EB9ADD-7F30-4F37-9632-20CEF4E40542}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |  
"{80AC2432-9B88-465B-8090-B747700EF784}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |  
"{9244160B-A70B-4A63-97E7-94D78E8CB047}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |  
"{96FC19BE-7626-4547-A61E-CEBEBBBAC346}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{A1A1C5EB-DBB3-499C-9434-4F1F5C64BB9F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |  
"{A67A5D45-2F07-4C54-A947-4B91FA1FD198}" = dir=in | app=c:\program files\cyberlink\powerdvd9\powerdvd9.exe |  
"{B6F5E725-233E-4A05-879B-6CBB20E9F59A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |  
"{B868D76C-AB75-44BF-96B5-5A5556935F01}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |  
"{BFFE2A2B-C833-46D1-8269-0F32AF157569}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{C548726E-488F-4613-8256-5B8B1CC336CB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |  
"{D036BDCB-6933-4C0C-88E7-25B9519DBD40}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |  
"{D59E2178-FC54-4B61-85AA-162728E0F1C7}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |  
"{D9AA8A7F-3D68-4F4F-9F21-692EA800A815}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |  
"{E047519A-8C29-43B6-95F4-B3D3B31B9069}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{E6B29F2A-6C4E-4784-BAD8-97557977817B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |  
"{F6C6A89E-EEC9-4A65-89F9-910C66C69FA7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 
"_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension 
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 
"{07B62101-7EBD-434A-94B1-B38063BE5516}" = CorelDRAW Essentials 4 - PHOTO-PAINT 
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID-Anmelde-Assistent 
"{0ED4216F-3540-4D6B-8199-1C8DDEA3924B}" = CorelDRAW Essentials 4 - Lang DE 
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan 
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch 
"{19AC095C-3520-4999-AA15-93B6D0248A50}" = CorelDRAW Essentials 4 - Content 
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema 
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool 
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery 
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT 
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17 
"{28379381-B56A-43e1-B505-3098D82B1C30}" = 4500G510gm_Software_Min 
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie 
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm 
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update 
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver 
"{34A9406E-1994-4C20-AC72-04CFA2B24545}" = CorelDRAW Essentials 4 - Lang EN 
"{3576C335-958D-4D60-A812-F68F9A2796AF}" = CorelDRAW Essentials 4 - Lang IT 
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works 
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform 
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile 
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology 
"{3E6F0CAD-EE38-42A5-9EEA-AE17A55BF2D4}" = Firebird SQL Server - MAGIX Edition 
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker 
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go 
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger 
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg 
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax 
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis 
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater 
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter 
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module 
"{5500BB35-1C21-4328-9F16-F894B860FADE}" = CorelDRAW Essentials 4 - Lang NL 
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call 
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module 
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components 
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting 
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin 
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply 
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox 
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable 
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync 
"{76E852ED-1B06-4BC8-9D6A-625DB95FB7E5}" = CorelDRAW Essentials 4 - IPM - No VBA 
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update 
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime 
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow 
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert 
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) 
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) 
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) 
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) 
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) 
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) 
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) 
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) 
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System 
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3) 
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3) 
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In 
"{9043B9A0-9505-405B-8202-E7167A38A89C}" = CorelDRAW Essentials 4 
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) 
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr 
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) 
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc 
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 
"{9D3D8C60-A55F-4fed-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver 
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer 
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support 
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{ABD8B955-1C69-4AF3-949B-13CD587C175F}" = CorelDRAW Essentials 4 - Lang BR 
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) 
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status 
"{B2455727-ED8F-4643-8A6E-F4AB8DE3633D}" = Network 
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer 
"{B860298B-CE03-4DE2-B92E-422F2C20A2D8}_is1" = PDF-XChange Lite 4 
"{B9FA9F15-A1F3-4DB1-AD49-0B9351843FAA}" = CorelDRAW Essentials 4 - Draw 
"{BA9319FE-BCEF-4C99-8039-F464648D046E}" = CorelDRAW Essentials 4 - Lang FR 
"{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}" = Microsoft SQL Server 2005 Compact Edition [DEU] 
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) 
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations 
"{BE0D4271-69C9-4f28-AD9B-BB33D126A30E}" = 4500G510gm 
"{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}" = CorelDRAW Essentials 4 - ICA 
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant 
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail 
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint 
"{C682F3F0-00A6-4379-B083-4F3273624D7B}" = CorelDRAW Essentials 4 - Lang ES 
"{C8C8387B-A98B-44E8-807A-1A9B7F51FFDA}" = Blaze Media Pro 
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector 
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware 
"{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}" = CorelDRAW Essentials 4 - Windows Shell Extension 
"{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.5.0.8 
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow 
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp 
"{DF0B357C-5874-47D0-81E7-79AA890B0CE0}" = 4500_G510gm_Help 
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer 
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update 
"{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy 
"{E5083D57-D93F-404C-A91F-1C50D67C2BEB}" = HP Officejet 4500 G510g-m 
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant 
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module 
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] 
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard 
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver 
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver 
"{F16841F6-5F0F-4DBE-B318-63CEB916F21D}" = CorelDRAW Essentials 4 - Filters 
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack 
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials 
"3DataManager" = 3DataManager 
"7-Zip" = 7-Zip 9.20 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9 
"AVS Screen Capture_is1" = AVS Screen Capture version 1.1.2 
"AVS Update Manager_is1" = AVS Update Manager 1.0 
"AVS Video Editor_is1" = AVS Video Editor 5 
"AVS Video Recorder_is1" = AVS Video Recorder 2.4 
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4 
"Blaze Media Pro" = Blaze Media Pro 
"CCleaner" = CCleaner 
"DivX Setup" = DivX-Setup 
"ESET Online Scanner" = ESET Online Scanner v3 
"FMCODEC" = FM Screen Capture Codec (Remove Only) 
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2 
"Hofer Foto Manager Free D" = Hofer Foto Manager Free 
"Hofer Foto Service D" = Hofer Foto Service 
"Hofer Fotodruck Service" = Hofer Fotodruck Service 4.5 
"Hofer Online Druck Service D" = Hofer Online Druck Service 
"HOMESTUDENTR" = Microsoft Office Home and Student 2007 
"HP Document Manager" = HP Document Manager 2.0 
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0 
"HP Smart Web Printing" = HP Smart Web Printing 4.5 
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 
"HPExtendedCapabilities" = HP Customer Participation Program 13.0 
"HPOCR" = OCR Software by I.R.I.S. 13.0 
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam 
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema 
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go 
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow 
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer 
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint 
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector 
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow 
"InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy 
"IrfanView" = IrfanView (remove only) 
"MEDION Fotos auf CD & DVD SE Hofer D" = MEDION Fotos auf CD & DVD SE Hofer 
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile 
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack 
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US) 
"MozillaMaintenanceService" = Mozilla Maintenance Service 
"Nano" = Nano 1.1.2 
"NIS" = Norton Internet Security 
"R for Windows 2.13.0_is1" = R for Windows 2.13.0 
"RarZilla Free Unrar" = RarZilla Free Unrar 
"Shop for HP Supplies" = Shop for HP Supplies 
"SynTPDeinstKey" = Synaptics Pointing Device Driver 
"TVWiz" = Intel(R) TV Wizard 
"VLC media player" = VLC media player 1.1.4 
"WinLiveSuite_Wave3" = Windows Live Essentials 
"X10Hardware" = X10 Hardware(TM) 
   ========== Last 20 Event Log Errors ========== 
  
[ Application Events ] 
Error - 25.03.2012 06:00:02 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 01.04.2012 09:41:42 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 08.04.2012 07:22:35 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 15.04.2012 07:43:51 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 16.04.2012 17:37:29 | Computer Name = Karin-PC | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: DivX Plus Player.exe, Version: 10.2.1.23, 
 Zeitstempel: 0x4e7b8e3c  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, 
 Zeitstempel: 0x4ec49b60  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00055fa8  ID des fehlerhaften 
 Prozesses: 0x14c4  Startzeit der fehlerhaften Anwendung: 0x01cd1c18940e4be8  Pfad der 
 fehlerhaften Anwendung: C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe 
Pfad 
 des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: 5d180494-880c-11e1-b91c-00262df7f59e 
  
Error - 22.04.2012 07:20:52 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 29.04.2012 06:22:21 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 29.04.2012 06:32:08 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 06.05.2012 06:00:01 | Computer Name = Karin-PC | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 11.05.2012 14:37:27 | Computer Name = Karin-PC | Source = IAStorDataMgrSvc | ID = 0 
Description = Der Dienst kann nicht gestartet werden. Der Dienstprozess konnte keine 
 Verbindung mit dem Dienstcontroller herstellen 
  
[ OSession Events ] 
Error - 07.05.2011 06:39:28 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3 
 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 17.12.2011 06:42:32 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1901 
 seconds with 180 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 02:50:07 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 189 seconds with 120 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 02:51:59 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 99 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 02:52:53 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 16 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 02:53:28 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 21 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 02:59:13 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 14 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 03:53:04 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 24 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 03:53:35 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 22 seconds with 0 seconds of active time.  This session ended with a crash. 
  
Error - 20.07.2012 06:36:58 | Computer Name = Karin-PC | Source = Microsoft Office 12 Sessions | ID = 7001 
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application  
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session  
lasted 21 seconds with 0 seconds of active time.  This session ended with a crash. 
  
[ System Events ] 
Error - 20.03.2013 01:04:04 | Computer Name = KARIN-PC | Source = BugCheck | ID = 1005 
Description =  
  
Error - 20.03.2013 01:04:04 | Computer Name = KARIN-PC | Source = BugCheck | ID = 1001 
Description =  
  
Error - 23.03.2013 04:28:18 | Computer Name = Karin-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 27.03.2013 10:28:07 | Computer Name = Karin-PC | Source = iaStor | ID = 262153 
Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht 
 geantwortet. 
  
Error - 27.03.2013 12:47:41 | Computer Name = Karin-PC | Source = EventLog | ID = 6008 
Description = Das System wurde zuvor am ?27.?03.?2013 um 17:44:08 unerwartet heruntergefahren. 
  
Error - 27.03.2013 12:48:42 | Computer Name = Karin-PC | Source = BugCheck | ID = 1005 
Description =  
  
Error - 27.03.2013 12:48:42 | Computer Name = Karin-PC | Source = BugCheck | ID = 1001 
Description =  
  
Error - 29.03.2013 13:32:04 | Computer Name = Karin-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 
Description = Installationsfehler: Die Installation des folgenden Updates ist mit 
 Fehler 0x80070643 fehlgeschlagen: Internet Explorer 10 für Windows 7 
  
Error - 30.03.2013 08:38:45 | Computer Name = Karin-PC | Source = DCOM | ID = 10010 
Description =  
  
Error - 30.03.2013 15:19:45 | Computer Name = Karin-PC | Source = DCOM | ID = 10010 
Description =  
  
  
< End of report >   --- --- ---  
habe gestern Abend noch CCleaner über den Laptop laufen lassen nachdem ich das erste OTL file gepostet habe, ich hoff das verfälscht die Ergebnisse nicht so sehr, so weit hab ich leider nicht mitgedacht....  
glg, 
kruemmel    |