| 
 Hallo, 
hier das OTL-File:   Code: 
 OTL logfile created on: 28.10.2013 15:28:16 - Run 2OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Detlev\Desktop
 Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
 Internet Explorer (Version = 9.0.8112.16421)
 Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
 2,99 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 60,81% Memory free
 6,21 Gb Paging File | 4,80 Gb Available in Paging File | 77,35% Paging File free
 Paging file location(s): ?:\pagefile.sys
 
 %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
 Drive C: | 277,95 Gb Total Space | 168,52 Gb Free Space | 60,63% Space Free | Partition Type: NTFS
 Drive E: | 20,13 Gb Total Space | 5,19 Gb Free Space | 25,81% Space Free | Partition Type: FAT32
 
 Computer Name: MARLENA-PC | User Name: Detlev | Logged in as Administrator.
 Boot Mode: Normal | Scan Mode: Current user
 Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
 ========== Processes (SafeList) ==========
 
 PRC - C:\Users\Detlev\Desktop\OTL.exe (OldTimer Tools)
 PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.)
 PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
 PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 PRC - C:\Users\Detlev\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
 PRC - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
 PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
 PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
 PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
 PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
 PRC - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
 PRC - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
 PRC - C:\Windows\System32\lxeacoms.exe ( )
 PRC - C:\Windows\explorer.exe (Microsoft Corporation)
 PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
 PRC - C:\Program Files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe ()
 PRC - C:\Program Files\HomeCinema\PowerDVD8\PDVD8Serv.exe (Cyberlink Corp.)
 PRC - C:\Program Files\Corel\Corel MediaOne\CorelIOMonitor.exe ()
 PRC - C:\Windows\System32\PSIService.exe ()
 
 
 ========== Modules (No Company Name) ==========
 
 MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
 MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
 MOD - C:\Users\Detlev\AppData\Roaming\Dropbox\bin\libcef.dll ()
 MOD - C:\Users\Detlev\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\lxeadrs.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\lxeascw.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\epoemdll.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\epstring.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\epwizres.dll ()
 MOD - C:\Windows\System32\spool\drivers\w32x86\3\lxeadatr.dll ()
 MOD - C:\Windows\System32\LXEAsmr.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\iptk.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\epwizard.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\customui.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\epfunct.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\eputil.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\imagutil.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\lxeacaps.dll ()
 MOD - C:\Program Files\Lexmark S300-S400 Series\lxeaptp.dll ()
 MOD - C:\Windows\System32\LXEAsm.dll ()
 MOD - C:\Program Files\Corel\Corel MediaOne\CorelIOMonitor.exe ()
 
 
 ========== Services (SafeList) ==========
 
 SRV - (SBSDWSCService) -- C:\Program Files\Spybot File not found
 SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
 SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
 SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
 SRV - (TeamViewer8) -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
 SRV - (vsmon) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
 SRV - (IswSvc) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
 SRV - (lxea_device) -- C:\Windows\System32\lxeacoms.exe ( )
 SRV - (lxeaCATSCustConnectService) -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
 SRV - (resetWinService) -- C:\Program Files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe ()
 SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
 SRV - (de_serv) -- C:\Program Files\Common Files\AVM\De_serv.exe (AVM Berlin)
 SRV - (ProtexisLicensing) -- C:\Windows\System32\PSIService.exe ()
 
 
 ========== Driver Services (SafeList) ==========
 
 DRV - (vsdatant7) -- System32\drivers\vsdatant.win7.sys File not found
 DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
 DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
 DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
 DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
 DRV - (huawei_ext_ctrl) -- system32\DRIVERS\ew_juextctrl.sys File not found
 DRV - (huawei_enumerator) -- system32\DRIVERS\ew_jubusenum.sys File not found
 DRV - (huawei_cdcecm) -- system32\DRIVERS\ew_jucdcecm.sys File not found
 DRV - (huawei_cdcacm) -- system32\DRIVERS\ew_jucdcacm.sys File not found
 DRV - (ew_usbenumfilter) -- system32\DRIVERS\ew_usbenumfilter.sys File not found
 DRV - (ew_hwusbdev) -- system32\DRIVERS\ew_hwusbdev.sys File not found
 DRV - (agfucapi) -- system32\DRIVERS\AGFUCAPI.SYS File not found
 DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
 DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
 DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
 DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
 DRV - (ISWKL) -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
 DRV - (Vsdatant) -- C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
 DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek                                            )
 DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
 DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
 DRV - (RSUSBSTOR) -- C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
 DRV - (NETFRITZ) -- C:\Windows\System32\drivers\Netfritz.sys (AVM Berlin)
 DRV - (USB28xxBGA) -- C:\Windows\System32\drivers\emBDA.sys (eMPIA Technology, Inc.)
 DRV - (USB28xxOEM) -- C:\Windows\System32\drivers\emOEM.sys (eMPIA Technology, Inc.)
 DRV - (emAudio) -- C:\Windows\System32\drivers\emAudio.sys (eMPIA Technology, Inc.)
 DRV - (WINIO) -- C:\Windows\System32\WinIo.sys (hxxp://www.internals.com)
 
 
 ========== Standard Registry (SafeList) ==========
 
 
 ========== Internet Explorer ==========
 
 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.medion.com/
 IE - HKLM\..\SearchScopes,DefaultScope =
 IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MEDC
 IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Lager
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.medion.com/
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
 IE - HKCU\..\URLSearchHook: {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No CLSID value found
 IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
 IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MEDC
 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 ========== FireFox ==========
 
 FF - prefs.js..browser.search.suggest.enabled: false
 FF - prefs.js..browser.search.useDBForOrder: true
 FF - prefs.js..browser.startup.homepage: "hxxp://web.de/"
 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
 FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.12.2.17486
 FF - prefs.js..extensions.enabledItems: ff-bmboc@bytemobile.com:4.2.2
 FF - prefs.js..network.proxy.type: 4
 FF - user.js - File not found
 
 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
 FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
 FF - HKLM\Software\MozillaPlugins\@cambridgesoft.com/Chem3D,version=12.0: C:\Program Files\CambridgeSoft\ChemOffice2010\Chem3D\npChem3DPlugin.dll (CambridgeSoft Corp.)
 FF - HKLM\Software\MozillaPlugins\@cambridgesoft.com/ChemDraw,version=12.0: C:\Program Files\CambridgeSoft\ChemOffice2010\ChemDraw\npcdn32.dll (CambridgeSoft Corp.)
 FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
 FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012.08.12 13:33:19 | 000,000,000 | ---D | M]
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.09.19 17:46:48 | 000,000,000 | ---D | M]
 FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.09.19 17:46:49 | 000,000,000 | ---D | M]
 FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.09.19 17:46:48 | 000,000,000 | ---D | M]
 FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.09.19 17:46:49 | 000,000,000 | ---D | M]
 
 [2009.07.05 12:12:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Detlev\AppData\Roaming\mozilla\Extensions
 [2013.10.25 17:33:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Detlev\AppData\Roaming\mozilla\Firefox\Profiles\tfr0ijpc.default\extensions
 [2010.05.21 19:55:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Detlev\AppData\Roaming\mozilla\Firefox\Profiles\tfr0ijpc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
 [2013.10.21 15:17:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 [2013.09.19 17:46:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
 [2013.09.19 17:46:55 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 [2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
 
 ========== Chrome  ==========
 
 
 O1 HOSTS File: ([2011.09.01 16:30:11 | 000,437,206 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
 O1 - Hosts: 127.0.0.1       localhost
 O1 - Hosts: ::1             localhost
 O1 - Hosts: 127.0.0.1        www.007guard.com
 O1 - Hosts: 127.0.0.1        007guard.com
 O1 - Hosts: 127.0.0.1        008i.com
 O1 - Hosts: 127.0.0.1        www.008k.com
 O1 - Hosts: 127.0.0.1        008k.com
 O1 - Hosts: 127.0.0.1        www.00hq.com
 O1 - Hosts: 127.0.0.1        00hq.com
 O1 - Hosts: 127.0.0.1        010402.com
 O1 - Hosts: 127.0.0.1        www.032439.com
 O1 - Hosts: 127.0.0.1        032439.com
 O1 - Hosts: 127.0.0.1        www.0scan.com
 O1 - Hosts: 127.0.0.1        0scan.com
 O1 - Hosts: 127.0.0.1        1000gratisproben.com
 O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
 O1 - Hosts: 127.0.0.1        1001namen.com
 O1 - Hosts: 127.0.0.1        www.1001namen.com
 O1 - Hosts: 127.0.0.1        100888290cs.com
 O1 - Hosts: 127.0.0.1        www.100888290cs.com
 O1 - Hosts: 127.0.0.1        www.100sexlinks.com
 O1 - Hosts: 127.0.0.1        100sexlinks.com
 O1 - Hosts: 127.0.0.1        10sek.com
 O1 - Hosts: 127.0.0.1        www.10sek.com
 O1 - Hosts: 127.0.0.1        www.1-2005-search.com
 O1 - Hosts: 15040 more lines...
 O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
 O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
 O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
 O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
 O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
 O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
 O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
 O4 - HKLM..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel MediaOne\CorelIOMonitor.exe ()
 O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
 O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
 O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
 O4 - HKLM..\Run: [MDS_Menu] C:\Program Files\HomeCinema\MediaShow4\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
 O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\HomeCinema\PowerDVD8\Language\Language.exe ()
 O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\HomeCinema\PowerDVD8\PDVD8Serv.exe (Cyberlink Corp.)
 O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
 O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\HomeCinema\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
 O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files\HomeCinema\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
 O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
 O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
 O4 - Startup: C:\Users\Detlev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Detlev\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
 O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000 File not found
 O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
 O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
 O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
 O13 - gopher Prefix: missing
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D6BBEC4B-84E3-4D74-9886-804784EDE6CF}: DhcpNameServer = 192.168.2.1
 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
 O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
 O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) -  File not found
 O24 - Desktop WallPaper: C:\Users\Detlev\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
 O24 - Desktop BackupWallPaper: C:\Users\Detlev\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
 O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
 O32 - HKLM CDRom: AutoRun - 1
 O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
 O32 - AutoRun File - [2008.08.21 11:50:32 | 000,000,672 | RH-- | M] () - E:\AUTOEXEC.BAT -- [ FAT32 ]
 O33 - MountPoints2\{201ab6ab-abc4-11e0-b05b-001f161344f1}\Shell - "" = AutoRun
 O33 - MountPoints2\{201ab6ab-abc4-11e0-b05b-001f161344f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 O33 - MountPoints2\{201ab6c2-abc4-11e0-b05b-001f161344f1}\Shell - "" = AutoRun
 O33 - MountPoints2\{201ab6c2-abc4-11e0-b05b-001f161344f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 O33 - MountPoints2\{8b4b6b59-b2ae-11e0-a96e-001f161344f1}\Shell - "" = AutoRun
 O33 - MountPoints2\{8b4b6b59-b2ae-11e0-a96e-001f161344f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 O33 - MountPoints2\{8b4b6b67-b2ae-11e0-a96e-001f161344f1}\Shell - "" = AutoRun
 O33 - MountPoints2\{8b4b6b67-b2ae-11e0-a96e-001f161344f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 O33 - MountPoints2\{8b4b6b72-b2ae-11e0-a96e-001f161344f1}\Shell - "" = AutoRun
 O33 - MountPoints2\{8b4b6b72-b2ae-11e0-a96e-001f161344f1}\Shell\AutoRun\command - "" = G:\AutoRun.exe
 O33 - MountPoints2\{f19fd50f-ba6f-11e2-9bb0-001f161344f1}\Shell - "" = AutoRun
 O33 - MountPoints2\{f19fd50f-ba6f-11e2-9bb0-001f161344f1}\Shell\AutoRun\command - "" = F:\laucher.exe
 O34 - HKLM BootExecute: (autocheck autochk *)
 O35 - HKLM\..comfile [open] -- "%1" %*
 O35 - HKLM\..exefile [open] -- "%1" %*
 O37 - HKLM\...com [@ = comfile] -- "%1" %*
 O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
 O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
 ========== Files/Folders - Created Within 30 Days ==========
 
 [2013.10.27 13:16:09 | 001,089,001 | ---- | C] (Farbar) -- C:\Users\Detlev\Desktop\FRST.exe
 [2013.10.27 00:29:11 | 002,347,384 | ---- | C] (ESET) -- C:\Users\Detlev\Desktop\esetsmartinstaller_enu.exe
 [2013.10.26 18:16:03 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
 [2013.10.26 17:20:12 | 000,181,064 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
 [2013.10.26 17:14:17 | 000,000,000 | ---D | C] -- C:\RegBackup
 [2013.10.26 16:44:33 | 000,000,000 | ---D | C] -- C:\Users\Detlev\Desktop\Tweaking.com - Windows Repair
 [2013.10.25 17:38:18 | 000,359,085 | ---- | C] (Farbar) -- C:\Users\Detlev\Desktop\FSS.exe
 [2013.10.25 17:29:51 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
 [2013.10.25 17:27:17 | 001,033,335 | ---- | C] (Thisisu) -- C:\Users\Detlev\Desktop\JRT.exe
 [2013.10.25 11:06:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Detlev\Desktop\OTL.exe
 [2013.10.23 18:43:06 | 000,000,000 | ---D | C] -- C:\FRST
 [2013.10.21 15:48:49 | 000,000,000 | ---D | C] -- C:\AdwCleaner
 [2013.10.19 23:23:02 | 000,000,000 | ---D | C] -- C:\Program Files\Uninstaller
 [2013.10.10 11:11:47 | 000,000,000 | ---D | C] -- C:\Users\Detlev\Desktop\Buffet
 [2013.10.09 16:05:50 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
 [2013.10.09 16:05:49 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
 [2013.10.09 16:05:49 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
 [2013.10.09 16:05:49 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
 [2013.10.09 16:05:49 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
 [2013.10.09 16:05:48 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
 [2013.10.09 16:05:47 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
 [2013.10.09 16:05:46 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
 [2013.10.09 15:57:43 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
 [2013.10.09 15:57:32 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
 [2013.10.09 15:57:32 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
 [2013.10.09 15:57:30 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
 [2013.10.09 15:57:29 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
 [2013.10.09 15:57:29 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
 [2013.10.09 15:57:29 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
 [2013.10.09 15:57:29 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
 [2013.10.09 15:57:29 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
 [2013.10.09 15:57:29 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
 [2013.10.09 15:57:29 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
 [2013.10.09 15:57:29 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
 [2013.10.09 15:57:28 | 002,050,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
 [2013.10.09 15:57:22 | 000,293,376 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
 [2013.10.09 15:57:22 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
 [2013.10.09 15:55:16 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiafbdrv.dll
 [2013.10.09 15:55:16 | 000,025,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidparse.sys
 [2013.10.05 15:59:10 | 000,000,000 | ---D | C] -- C:\Program Files\Audacity
 [13 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
 ========== Files - Modified Within 30 Days ==========
 
 [2013.10.28 15:20:56 | 000,615,096 | ---- | M] () -- C:\Windows\System32\perfh007.dat
 [2013.10.28 15:20:56 | 000,592,452 | ---- | M] () -- C:\Windows\System32\perfh009.dat
 [2013.10.28 15:20:56 | 000,122,534 | ---- | M] () -- C:\Windows\System32\perfc007.dat
 [2013.10.28 15:20:56 | 000,100,526 | ---- | M] () -- C:\Windows\System32\perfc009.dat
 [2013.10.28 15:16:39 | 000,034,997 | ---- | M] () -- C:\ProgramData\nvModes.dat
 [2013.10.28 15:16:38 | 000,034,997 | ---- | M] () -- C:\ProgramData\nvModes.001
 [2013.10.28 15:15:58 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
 [2013.10.28 15:15:58 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
 [2013.10.28 15:15:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
 [2013.10.27 13:16:09 | 001,089,001 | ---- | M] (Farbar) -- C:\Users\Detlev\Desktop\FRST.exe
 [2013.10.27 13:10:07 | 000,891,167 | ---- | M] () -- C:\Users\Detlev\Desktop\SecurityCheck.exe
 [2013.10.27 00:29:05 | 002,347,384 | ---- | M] (ESET) -- C:\Users\Detlev\Desktop\esetsmartinstaller_enu.exe
 [2013.10.26 18:15:05 | 000,351,800 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
 [2013.10.26 18:13:08 | 000,181,064 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE
 [2013.10.26 17:15:46 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-MARLENA-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-bit).dat
 [2013.10.26 16:44:06 | 002,804,464 | ---- | M] () -- C:\Users\Detlev\Desktop\tweaking.com_windows_repair_aio.zip
 [2013.10.25 17:38:14 | 000,359,085 | ---- | M] (Farbar) -- C:\Users\Detlev\Desktop\FSS.exe
 [2013.10.25 17:27:14 | 001,033,335 | ---- | M] (Thisisu) -- C:\Users\Detlev\Desktop\JRT.exe
 [2013.10.25 17:17:19 | 001,060,070 | ---- | M] () -- C:\Users\Detlev\Desktop\adwcleaner.exe
 [2013.10.25 11:06:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Detlev\Desktop\OTL.exe
 [2013.10.23 18:45:28 | 000,377,856 | ---- | M] () -- C:\Users\Detlev\Desktop\98of1w57.exe
 [2013.10.23 18:39:17 | 000,000,000 | ---- | M] () -- C:\Users\Detlev\defogger_reenable
 [2013.10.23 18:37:21 | 000,050,477 | ---- | M] () -- C:\Users\Detlev\Desktop\Defogger.exe
 [2013.10.22 14:36:27 | 000,170,496 | ---- | M] () -- C:\Users\Detlev\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 [2013.10.15 09:58:37 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
 [2013.10.15 09:58:37 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
 [2013.10.09 20:38:09 | 000,022,699 | ---- | M] () -- C:\Users\Detlev\kürbis.odt
 [2013.10.05 16:34:34 | 004,844,206 | ---- | M] () -- C:\Users\Detlev\Desktop\test.wav
 [2013.10.05 15:59:11 | 000,000,718 | ---- | M] () -- C:\Users\Detlev\Desktop\Audacity.lnk
 [2013.10.05 13:50:48 | 000,000,770 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
 [2013.10.01 12:46:03 | 000,137,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
 [2013.10.01 12:46:03 | 000,089,376 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
 [2013.10.01 12:46:03 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
 [13 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
 
 ========== Files Created - No Company Name ==========
 
 [2013.10.27 13:10:09 | 000,891,167 | ---- | C] () -- C:\Users\Detlev\Desktop\SecurityCheck.exe
 [2013.10.26 17:15:46 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-MARLENA-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-bit).dat
 [2013.10.26 16:44:04 | 002,804,464 | ---- | C] () -- C:\Users\Detlev\Desktop\tweaking.com_windows_repair_aio.zip
 [2013.10.25 17:17:21 | 001,060,070 | ---- | C] () -- C:\Users\Detlev\Desktop\adwcleaner.exe
 [2013.10.23 18:45:34 | 000,377,856 | ---- | C] () -- C:\Users\Detlev\Desktop\98of1w57.exe
 [2013.10.23 18:39:17 | 000,000,000 | ---- | C] () -- C:\Users\Detlev\defogger_reenable
 [2013.10.23 18:37:36 | 000,050,477 | ---- | C] () -- C:\Users\Detlev\Desktop\Defogger.exe
 [2013.10.09 20:29:26 | 000,022,699 | ---- | C] () -- C:\Users\Detlev\kürbis.odt
 [2013.10.05 16:34:33 | 004,844,206 | ---- | C] () -- C:\Users\Detlev\Desktop\test.wav
 [2013.10.05 15:59:11 | 000,000,730 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
 [2013.10.05 15:59:11 | 000,000,718 | ---- | C] () -- C:\Users\Detlev\Desktop\Audacity.lnk
 [2013.02.28 20:32:14 | 001,010,782 | ---- | C] () -- C:\Users\Detlev\Speisekarte_La_Piazzetta.pdf
 [2011.09.08 20:57:45 | 000,002,316 | ---- | C] () -- C:\Users\Detlev\AppData\Roaming\1030.C82
 [2011.08.21 14:16:50 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
 [2011.07.07 13:58:01 | 000,014,991 | ---- | C] () -- C:\Users\Detlev\Lebenslauf.odt
 [2010.08.28 13:07:12 | 000,017,238 | ---- | C] () -- C:\Users\Detlev\Selbstdarstellung.odt
 [2010.05.21 20:06:46 | 000,000,552 | ---- | C] () -- C:\Users\Detlev\AppData\Local\d3d8caps.dat
 [2010.05.21 20:04:19 | 000,001,356 | ---- | C] () -- C:\Users\Detlev\AppData\Local\d3d9caps.dat
 [2010.02.19 18:11:23 | 002,016,285 | ---- | C] () -- C:\Users\Detlev\Facharbeit2.odt
 [2009.09.04 14:49:57 | 000,001,453 | ---- | C] () -- C:\Users\Detlev\Fehlende Songtexte.rtf
 [2009.07.19 13:25:17 | 000,021,430 | ---- | C] () -- C:\Users\Detlev\AppData\Roaming\UserTile.png
 [2009.06.28 20:31:38 | 000,000,052 | ---- | C] () -- C:\Users\Detlev\AppData\Roaming\wklnhst.dat
 [2009.06.27 11:47:53 | 000,170,496 | ---- | C] () -- C:\Users\Detlev\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 [2009.04.21 07:54:03 | 000,034,997 | ---- | C] () -- C:\ProgramData\nvModes.001
 [2009.04.21 07:54:02 | 000,034,997 | ---- | C] () -- C:\ProgramData\nvModes.dat
 
 ========== ZeroAccess Check ==========
 
 [2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
 [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
 [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
 [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 "" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
 "ThreadingModel" = Apartment
 
 [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
 "" = c:\windows\system32\wbem\fastprox.dll -- [2009.04.10 22:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
 "ThreadingModel" = Free
 
 [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 "" = c:\windows\system32\wbem\wbemess.dll -- [2009.04.10 22:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation)
 "ThreadingModel" = Both
 
 ========== Files - Unicode (All) ==========
 [2013.09.13 12:04:14 | 097,446,370 | ---- | M] ()(C:\Windows\System32\???¨) -- C:\Windows\System32\뉏빽ᰴ¨
 [2013.09.13 12:04:14 | 097,446,370 | ---- | C] ()(C:\Windows\System32\???¨) -- C:\Windows\System32\뉏빽ᰴ¨
 
 < End of report >
 und das Extra-File:   Code: 
 OTL Extras logfile created on: 28.10.2013 15:28:16 - Run 2OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Detlev\Desktop
 Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
 Internet Explorer (Version = 9.0.8112.16421)
 Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
 2,99 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 60,81% Memory free
 6,21 Gb Paging File | 4,80 Gb Available in Paging File | 77,35% Paging File free
 Paging file location(s): ?:\pagefile.sys
 
 %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
 Drive C: | 277,95 Gb Total Space | 168,52 Gb Free Space | 60,63% Space Free | Partition Type: NTFS
 Drive E: | 20,13 Gb Total Space | 5,19 Gb Free Space | 25,81% Space Free | Partition Type: FAT32
 
 Computer Name: MARLENA-PC | User Name: Detlev | Logged in as Administrator.
 Boot Mode: Normal | Scan Mode: Current user
 Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
 ========== Extra Registry (SafeList) ==========
 
 
 ========== File Associations ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
 .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
 .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
 ========== Shell Spawning ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
 batfile [open] -- "%1" %*
 cmdfile [open] -- "%1" %*
 comfile [open] -- "%1" %*
 cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
 exefile [open] -- "%1" %*
 helpfile [open] -- Reg Error: Key error.
 hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
 htmlfile [edit] -- Reg Error: Key error.
 htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
 http [open] -- Reg Error: Value error.
 https [open] -- Reg Error: Value error.
 inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
 piffile [open] -- "%1" %*
 regfile [merge] -- Reg Error: Key error.
 scrfile [config] -- "%1"
 scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
 scrfile [open] -- "%1" /S
 txtfile [edit] -- Reg Error: Key error.
 Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
 Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
 Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
 Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
 ========== Security Center Settings ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 "cval" = 1
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 "AntiVirusOverride" = 1
 "AntiSpywareOverride" = 1
 "FirewallOverride" = 0
 "VistaSp1" = Reg Error: Unknown registry data type -- File not found
 "VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
 ========== System Restore Settings ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
 "DisableSR" = 0
 
 ========== Firewall Settings ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 "EnableFirewall" = 0
 "DisableNotifications" = 0
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
 "EnableFirewall" = 0
 "DisableNotifications" = 0
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
 "EnableFirewall" = 0
 "DisableNotifications" = 0
 
 ========== Authorized Applications List ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
 ========== Vista Active Open Ports Exception List ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 "{0456E877-E40A-45C8-ABA3-B29F6A9BF5A2}" = lport=2869 | protocol=6 | dir=in | app=system |
 "{048EC4B1-7B9B-437D-ACD9-6F0C3128D682}" = rport=138 | protocol=17 | dir=out | app=system |
 "{08E021D5-C8A6-4B57-AAB0-034831922A23}" = lport=2869 | protocol=6 | dir=in | app=system |
 "{14FFF122-BFEA-4FF1-B32B-26E949BD9680}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
 "{1A53B74A-BE7D-4CC0-ADC7-4D1CE7909A1D}" = rport=445 | protocol=6 | dir=out | app=system |
 "{230086CB-9191-4E65-B97A-C4B4BCB555FE}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
 "{2A402D9B-2184-4BD0-BFA6-8D19F85AE26B}" = lport=10243 | protocol=6 | dir=in | app=system |
 "{2B213D14-A65C-46B6-B066-6C1B7843C635}" = lport=138 | protocol=17 | dir=in | app=system |
 "{2E02E9DA-D954-4502-8331-E95B17684843}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
 "{2FE5157A-E016-4644-82D5-CE12CCB7AB20}" = lport=445 | protocol=6 | dir=in | app=system |
 "{328352A2-50CF-4210-8CA6-FA0F40813745}" = lport=139 | protocol=6 | dir=in | app=system |
 "{483A42F1-94AA-43EA-871C-A6724BF2C85B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 "{496CF423-FB8D-46B0-A63C-7B49312EC362}" = lport=137 | protocol=17 | dir=in | app=system |
 "{69FA9359-4FD6-4D79-94A4-4114EDA3DB7D}" = lport=139 | protocol=6 | dir=in | app=system |
 "{6B32E17C-2CE7-4C5B-9C90-11DC8F6D2EF4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{7030EF51-C8DA-4533-AD6B-81BD005E9341}" = lport=137 | protocol=17 | dir=in | app=system |
 "{70CF4561-E1B3-4FBA-B14C-90523A30E461}" = rport=445 | protocol=6 | dir=out | app=system |
 "{739903A5-9EAC-4DB4-9865-E1CA209F6A2A}" = rport=10243 | protocol=6 | dir=out | app=system |
 "{7A1A36AC-0069-4F19-87F0-D8DB7758B6D4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
 "{7FB80689-4561-4343-8D39-F5BF32446CB3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 "{868889C4-0015-4CAC-8A09-9A1A6ADC23BE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{AE1EBFCD-3117-4EB4-BDCE-313F967BFDDE}" = rport=137 | protocol=17 | dir=out | app=system |
 "{B0DD49FD-428E-4838-9BBB-17846049FFD6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 "{B46CBF94-8F95-4268-88C4-2B024D572899}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
 "{BDF430FD-B21A-4D1C-885C-5555463D2AED}" = lport=445 | protocol=6 | dir=in | app=system |
 "{CB577F57-F67E-4B3E-8161-8567FA08B5B4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
 "{CF5C490C-E405-49DD-BCFD-F14A52ACD169}" = lport=138 | protocol=17 | dir=in | app=system |
 "{D3E903D1-132C-4214-8D68-C6F417F34633}" = rport=138 | protocol=17 | dir=out | app=system |
 "{D58463CD-EEA4-4370-9D6C-47F389F5963A}" = rport=137 | protocol=17 | dir=out | app=system |
 "{DA546AB9-3098-4805-A138-E77E85AD1612}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
 "{EF865607-324A-4F83-A40E-B1FA6DB570CE}" = rport=139 | protocol=6 | dir=out | app=system |
 "{FE4E6EEF-E109-41B9-933D-8ED9F0F976E1}" = rport=139 | protocol=6 | dir=out | app=system |
 "{FE949A8B-FB90-4816-A4AA-3384037EBBC2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
 ========== Vista Active Application Exception List ==========
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 "{0ABF41E0-2225-4EDB-B252-CC42D67CBBD6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{0F3566BB-1BAE-4CF2-B75D-568D832D23CE}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
 "{0FEACBB4-42AF-4A2B-8D63-A3196266C15B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
 "{13352222-CB9A-4F74-B0B2-1ED6BD48139B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
 "{139DE8C9-C4B5-481B-9C81-9447ABE06EAD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{17F4B833-2939-4253-8859-6CA0015406A7}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
 "{199EEAA6-0CC4-4C28-A999-85AE1C53B88F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{19D7D01F-418B-491C-BC63-9D52978D274C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{1B2303D7-C2E4-47C3-AF79-6D52F072DA92}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
 "{1D7ADFBC-54B8-4593-9A6D-6E8B007DC70F}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe |
 "{2E5734B0-B519-4CFC-AACC-5EE4A153CF64}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
 "{2F40A347-0BD6-470A-BA5D-F4B80F0E0022}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{338AC39D-AD1C-4BEB-9ADF-8CD04FD3A1E5}" = dir=in | app=c:\program files\homecinema\powerdirector\pdr.exe |
 "{363FDB33-171E-4285-866A-33F6F7FE96B4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
 "{655CB76F-BCD5-4D1D-BA8B-E5FC204A7923}" = protocol=6 | dir=out | app=system |
 "{665E0FFD-D2B1-42D8-8C02-3B847BD846EA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
 "{6FFD73E5-A029-4EC2-AD3C-B7A38BF62F27}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
 "{7197B9F8-831F-4029-9CA4-833C8B718643}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
 "{84A6B385-7143-42FC-8CE0-893372F40F71}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
 "{91506166-3A26-4FC1-8106-ACEC2DA70C67}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
 "{93F2BCE3-9290-45D9-A846-BFE43295C22B}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
 "{969E0949-1549-4C48-B6AD-523BF3DBDDB2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{97A85B11-650D-4274-8381-46CD2369F5F2}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe |
 "{9991148B-AC85-4B3F-A905-3EBD52F698E4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
 "{A93F33F5-2298-40B5-A985-E87F2C7DB5E4}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
 "{A972B725-27D7-41E8-BFC3-A40E9D81B3AD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
 "{AAB78A6D-4358-43C7-AE1E-70BEB3787AB7}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
 "{AE55CEA3-ED03-4AFD-B03D-AC8D8B7769B4}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer.exe |
 "{B468E97F-EB16-475D-893C-034596C9B2F7}" = dir=in | app=c:\program files\homecinema\powerdvd8\powerdvd8.exe |
 "{C4512B3D-BB26-4B81-98AD-DA005B9BB951}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
 "{C70A0B90-EA2D-4A8C-A9E3-57A74AAD5248}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version8\teamviewer_service.exe |
 "{D5D2C593-7C37-4852-8635-C9460666493D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
 "{F25059BC-A752-4F10-A407-F9A507D88E9A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
 "{FE24EF2A-AA05-41A7-88E6-A6126130112A}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
 
 ========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 "_{ADDBE07D-95B8-4789-9C76-187FFF9624B4}" = CorelDRAW Essential Edition 3
 "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
 "{02602409-9189-4567-BC07-562605243B69}" = Windows Live Remote Client Resources
 "{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
 "{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
 "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
 "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
 "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
 "{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
 "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
 "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
 "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
 "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
 "{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
 "{334799B1-527F-475B-AF19-658124E2BE24}" = ZoneAlarm Security
 "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
 "{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
 "{3A65A74A-5B6E-451A-92D8-50F1182BBE9A}" = Windows Live Remote Service Resources
 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
 "{41E57D2A-F778-4183-B1F7-A4A5FDF0E896}" = Digitus Video Grabber
 "{47948554-90C6-4AAC-8CFA-D23CE11C1031}" = Nero 8 Essentials
 "{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}" = OpenOffice.org 3.4
 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
 "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
 "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
 "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
 "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
 "{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
 "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
 "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
 "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
 "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
 "{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN
 "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
 "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
 "{A062A15F-9CAC-4B88-98DF-87628A0BD721}" = Corel MediaOne
 "{A334F1BA-0A1D-4ED6-B4F9-4066157CA15D}" = DE
 "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
 "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
 "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
 "{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.5 - Deutsch
 "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
 "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
 "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
 "{AD799836-6B74-419B-A869-C326CA86ECCF}" = ZoneAlarm Firewall
 "{ADDBE07D-95B8-4789-9C76-187FFF9624B4}" = CorelDRAW Essential Edition 3
 "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
 "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
 "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
 "{B7766B0B-EE9B-43F3-A4E6-69077AFC115D}" = CambridgeSoft ChemDraw Std 12.0
 "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
 "{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}" = Microsoft SQL Server 2005 Compact Edition [DEU]
 "{BCC5DC79-2275-4171-8CEA-39F0DD9ADF58}" = USB Video/Audio Device Driver
 "{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
 "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
 "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
 "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
 "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
 "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
 "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
 "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
 "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
 "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
 "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
 "{E70C67ED-4592-11D6-85CC-00A0CC603DBA}" = Löwenzahn 6
 "{E773E0B9-6ABE-4F9E-816C-56B2DD8613B9}" = CambridgeSoft Activation Client
 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
 "{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
 "{F5A4F780-DF0C-444F-BA82-637CCF5C8052}" = Windows Live Family Safety
 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
 "{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
 "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
 "7-Zip" = 7-Zip 9.20
 "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
 "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
 "Age of Empires" = Microsoft Age of Empires
 "Age of Empires 2.0" = Microsoft Age of Empires II
 "Age of Empires Expansion 1.0" = Microsoft Age of Empires Expansion
 "Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
 "Audacity_is1" = Audacity 1.2.6
 "AVIConverter" = AVIConverter 5.1
 "Avira AntiVir Desktop" = Avira Free Antivirus
 "CCleaner" = CCleaner
 "Defraggler" = Defraggler
 "FormatFactory" = FormatFactory 3.1.1
 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
 "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
 "InstallShield_{41E57D2A-F778-4183-B1F7-A4A5FDF0E896}" = Digitus Video Grabber
 "InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
 "InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
 "InstallShield_{BCC5DC79-2275-4171-8CEA-39F0DD9ADF58}" = USB Video/Audio Device Driver
 "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
 "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
 "Lexmark S300-S400 Series" = Lexmark S300-S400 Series
 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
 "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
 "Mozilla Firefox 24.0 (x86 de)" = Mozilla Firefox 24.0 (x86 de)
 "MozillaMaintenanceService" = Mozilla Maintenance Service
 "NVIDIA Display Control Panel" = NVIDIA Display Control Panel
 "NVIDIA Drivers" = NVIDIA Drivers
 "Origin 6.0G" = Origin 6.0G
 "phase-6" = phase-6 2.1.1.3a
 "SynTPDeinstKey" = Synaptics Pointing Device Driver
 "SystemRequirementsLab" = System Requirements Lab
 "TeamViewer 8" = TeamViewer 8
 "Totalcmd" = Total Commander (Remove or Repair)
 "VLC media player" = VLC media player 2.0.3
 "WinLiveSuite" = Windows Live Essentials
 "YTdetect" = Yahoo! Detect
 "ZoneAlarm Free Firewall" = ZoneAlarm Free Firewall
 
 ========== HKEY_CURRENT_USER Uninstall List ==========
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 "Dropbox" = Dropbox
 
 ========== Last 20 Event Log Errors ==========
 
 [ Application Events ]
 Error - 27.10.2013 08:23:10 | Computer Name = Marlena-PC | Source = Application Error | ID = 1000
 Description = Fehlerhafte Anwendung FRST.exe, Version 3.3.8.1, Zeitstempel 0x4f25baec,
 fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18881, Zeitstempel 0x51da3e27, Ausnahmecode
 0xc0000005, Fehleroffset 0x0006657b,  Prozess-ID 0xa50, Anwendungsstartzeit 01ced30f3ad1a83c.
 
 Error - 27.10.2013 09:21:39 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\CYBERLINK POWERDVD 8.LNK> in der Hash-Zuordnung kann nicht aktualisiert
 werden.  Kontext:  Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes
 Gerät funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:39 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\CYBERLINK POWERDVD 8.LNK> in der Hash-Zuordnung kann nicht aktualisiert
 werden.  Kontext:  Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes
 Gerät funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:39 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\DESKTOP.INI> in der Hash-Zuordnung kann nicht aktualisiert werden.
 
 Kontext:
 Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes Gerät
 funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:40 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\POWERDVD 8-HILFE.LNK> in der Hash-Zuordnung kann nicht aktualisiert
 werden.  Kontext:  Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes
 Gerät funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:40 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\POWERDVD 8-HILFE.LNK> in der Hash-Zuordnung kann nicht aktualisiert
 werden.  Kontext:  Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes
 Gerät funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:40 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.
 
 Kontext:
 Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes Gerät
 funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:40 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden.
 
 Kontext:
 Anwendung, SystemIndex Katalog  Details:  Ein an das System angeschlossenes Gerät
 funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:40 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\POWERDVD 8 DEINSTALLIEREN.LNK> in der Hash-Zuordnung kann nicht
 aktualisiert werden.  Kontext:  Anwendung, SystemIndex Katalog  Details:  Ein an das
 System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
 
 Error - 27.10.2013 09:21:40 | Computer Name = Marlena-PC | Source = Windows Search Service | ID = 3013
 Description = Eintrag <C:\USERS\DETLEV\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME
 CINEMA\POWERDVD 8\POWERDVD 8 DEINSTALLIEREN.LNK> in der Hash-Zuordnung kann nicht
 aktualisiert werden.  Kontext:  Anwendung, SystemIndex Katalog  Details:  Ein an das
 System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
 
 [ System Events ]
 Error - 26.10.2013 19:24:16 | Computer Name = Marlena-PC | Source = bowser | ID = 8016
 Description = Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom
 Remotecomputer "EASYBOX" zum Namen "MARLENA-PC" auf Transport "NetBT_Tcpip_{D6BBEC4B-84E3-4D74-9886".
 Das Datagramm steht in den Daten.  Es werden keine weiteren Ereignisse erzeugt, solange
 die Rücksetzfrequenz nicht abgelaufen ist.
 
 Error - 26.10.2013 19:24:23 | Computer Name = Marlena-PC | Source = bowser | ID = 8016
 Description = Der Suchdiensttreiber erhielt zu viele nicht erlaubte Datagramme vom
 Remotecomputer "EASYBOX" zum Namen "MARLENA-PC" auf Transport "NetBT_Tcpip_{D6BBEC4B-84E3-4D74-9886".
 Das Datagramm steht in den Daten.  Es werden keine weiteren Ereignisse erzeugt, solange
 die Rücksetzfrequenz nicht abgelaufen ist.
 
 Error - 27.10.2013 07:50:54 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7000
 Description =
 
 Error - 27.10.2013 07:50:54 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7000
 Description =
 
 Error - 27.10.2013 07:50:54 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7009
 Description =
 
 Error - 27.10.2013 07:50:54 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7000
 Description =
 
 Error - 28.10.2013 10:16:23 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7000
 Description =
 
 Error - 28.10.2013 10:16:23 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7000
 Description =
 
 Error - 28.10.2013 10:16:23 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7009
 Description =
 
 Error - 28.10.2013 10:16:23 | Computer Name = Marlena-PC | Source = Service Control Manager | ID = 7000
 Description =
 
 
 < End of report >
 |