OTL logfile created on: 04.02.2012 02:43:13 - Run 3 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Wolfi\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,25 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 72,51% Memory free 7,08 Gb Paging File | 6,37 Gb Available in Paging File | 89,99% Paging File free Paging file location(s): c:\pagefile.sys 4000 4000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 465,76 Gb Total Space | 26,61 Gb Free Space | 5,71% Space Free | Partition Type: NTFS Computer Name: WOLFI-PC | User Name: Wolfi | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Users\Wolfi\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Programme\SpeedFan\speedfan.exe (Almico Software (www.almico.com)) PRC - C:\Programme\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) PRC - C:\Programme\Microsoft\Office Live\OfficeLiveSignIn.exe (Microsoft Corp.) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - C:\Users\Wolfi\AppData\Local\Temp\sfamcc00001.dll () MOD - C:\Users\Wolfi\AppData\Local\Temp\sfareca00001.dll () MOD - C:\Programme\Mozilla Firefox\mozjs.dll () MOD - C:\Programme\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll () MOD - C:\Programme\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL () MOD - C:\Programme\WinRAR\RarExt.dll () [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - (CPUCooLServer) -- File not found SRV - (Creative ALchemy AL1 Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe (Creative Labs) SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_e286960.dll () SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation) SRV - (Stereo Service) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (UMVPFSrv) -- C:\Programme\Common Files\Logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (WAS) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation) SRV - (W3SVC) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation) SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs) SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) SRV - (SandraAgentSrv) -- C:\Systemerkennung\SiSoftware Sandra Lite 2010.SP3\RpcAgentSrv.exe (SiSoftware) SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) SRV - (Cherry Device Interface) -- C:\Programme\Cherry\CDI\cdi.exe (ZF Electronics GmbH) SRV - (AppHostSvc) -- C:\Windows\System32\inetsrv\apphostsvc.dll (Microsoft Corporation) SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (CTAudSvcService) -- C:\Programme\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (cpuz135) -- C:\Windows\System32\drivers\cpuz135_x32.sys (CPUID) DRV - (LVUVC) Logitech HD Webcam C270(UVC) -- C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.) DRV - (LVRS) -- C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.) DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (speedfan) -- C:\Windows\system32\speedfan.sys (Almico Software) DRV - (ntiopnp) -- C:\Windows\System32\drivers\ntiopnp.sys () DRV - (ntiomin) -- C:\Windows\System32\drivers\ntiomin.sys () DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys () DRV - (LVPr2Mon) -- C:\Windows\System32\drivers\LVPr2Mon.sys () DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation) DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI) DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation) DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.) DRV - (SASENUM) -- C:\Programme\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com) DRV - (P17) -- C:\Windows\System32\drivers\P17.sys (Creative Technology Ltd.) DRV - (RivaTuner32) -- C:\Programme\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys () DRV - (SANDRA) -- C:\Systemerkennung\SiSoftware Sandra Lite 2010.SP3\WNt500x86\sandra.sys (SiSoftware) DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys () DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys () DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (cFosNT) -- C:\Windows\System32\Drivers\cFosNT.sys (cFos Software GmbH) DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH) DRV - (VX3000) -- C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation) DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.) DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.) DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation ) DRV - (ha20x2k) -- C:\Windows\System32\drivers\HA20X2K.SYS (Creative Technology Ltd) DRV - (emupia) -- C:\Windows\System32\drivers\EMUPIA2K.SYS (Creative Technology Ltd) DRV - (ctsfm2k) -- C:\Windows\System32\drivers\CTSFM2K.SYS (Creative Technology Ltd) DRV - (ctprxy2k) -- C:\Windows\System32\drivers\CTPRXY2K.SYS (Creative Technology Ltd) DRV - (ossrv) -- C:\Windows\System32\drivers\CTOSS2K.SYS (Creative Technology Ltd.) DRV - (ctdvda2k) -- C:\Windows\System32\drivers\CTDVDA2K.SYS (Creative Technology Ltd) DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\Windows\System32\drivers\CTAUD2K.SYS (Creative Technology Ltd) DRV - (ctac32k) -- C:\Windows\System32\drivers\CTAC32K.SYS (Creative Technology Ltd) DRV - (CTEXFIFX.DLL) -- C:\Windows\System32\CTEXFIFX.DLL (Creative Technology Ltd.) DRV - (CTEDSPSY.DLL) -- C:\Windows\System32\CTEDSPSY.DLL (Creative Technology Ltd) DRV - (CTEDSPIO.DLL) -- C:\Windows\System32\CTEDSPIO.DLL (Creative Technology Ltd) DRV - (CT20XUT.DLL) -- C:\Windows\System32\CT20XUT.DLL (Creative Technology Ltd.) DRV - (CTHWIUT.DLL) -- C:\Windows\System32\CTHWIUT.DLL (Creative Technology Ltd.) DRV - (CTERFXFX.DLL) -- C:\Windows\System32\CTERFXFX.DLL (Creative Technology Ltd) DRV - (CTEDSPFX.DLL) -- C:\Windows\System32\CTEDSPFX.DLL (Creative Technology Ltd) DRV - (CTEAPSFX.DLL) -- C:\Windows\System32\CTEAPSFX.DLL (Creative Technology Ltd) DRV - (CTSBLFX.DLL) -- C:\Windows\System32\CTSBLFX.DLL (Creative Technology Ltd) DRV - (CTAUDFX.DLL) -- C:\Windows\System32\CTAUDFX.DLL (Creative Technology Ltd) DRV - (COMMONFX.DLL) -- C:\Windows\System32\COMMONFX.DLL (Creative Technology Ltd) DRV - (MTOnlPktAlyX) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) DRV - (RTCore32) -- C:\Programme\MSI Afterburner\RTCore32.sys () DRV - (giveio) -- C:\Windows\system32\giveio.sys () [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de/service/redir/ie_t-online.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.t-online.de/service/redir/ie_suche.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/service/redir/ie_t-online.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 6F F4 EC 49 B5 CC 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.t-online.de;localhost; IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=www-proxy.t-online.de:80;ftp=ftp-proxy.t-online.de:80 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.useDBForOrder: "" FF - prefs.js..browser.startup.homepage: "" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.104.0: C:\Program Files\Battlelog Web Plugins\1.104.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX Runtime 2.0\bin\new_plugin\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPMPDRM: C:\Program Files\Common Files\mpDRM\NPMPDRM.dll ( ) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Wolfi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.12.31 02:34:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.13 19:48:48 | 000,000,000 | ---D | M] [2009.02.09 11:19:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Extensions [2012.01.28 21:25:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Firefox\Profiles\r6307irc.default\extensions [2011.12.24 22:24:16 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Firefox\Profiles\r6307irc.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011.03.30 01:05:23 | 000,000,000 | ---D | M] (NoRedirect) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Firefox\Profiles\r6307irc.default\extensions\{c1970c0d-dbe6-4d91-804f-c9c0de643a57} [2010.04.25 12:30:38 | 000,001,840 | ---- | M] () -- C:\Users\Wolfi\AppData\Roaming\Mozilla\Firefox\Profiles\r6307irc.default\searchplugins\bing.xml [2012.02.01 14:15:21 | 000,001,056 | ---- | M] () -- C:\Users\Wolfi\AppData\Roaming\Mozilla\Firefox\Profiles\r6307irc.default\searchplugins\icqplugin.xml [2009.08.29 16:25:07 | 000,000,952 | ---- | M] () -- C:\Users\Wolfi\AppData\Roaming\Mozilla\Firefox\Profiles\r6307irc.default\searchplugins\youtube-videosuche.xml [2011.12.17 11:12:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions () (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{79C50F9A-2FFE-4EE0-8A37-FAE4F5DACD4F}.XPI () (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI () (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI () (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI () (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\COMPATIBILITY@ADDONS.MOZILLA.ORG.XPI () (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\UNPLUG@COMPUNACH.XPI [2011.12.31 02:34:23 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011.10.04 14:49:02 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2011.10.04 14:49:02 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011.10.04 14:49:02 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2011.10.04 14:49:02 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2011.10.04 14:49:02 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2011.10.04 14:49:02 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2011.12.06 08:50:07 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programme\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX Runtime 2.0\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programme\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CTHelper] C:\Windows\System32\CTHELPER.EXE (Creative Technology Ltd) O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\CTXFIHLP.EXE (Creative Technology Ltd) O4 - HKLM..\Run: [P17RunE] C:\Windows\System32\P17RunE.dll (Creative Technology Ltd.) O4 - HKLM..\Run: [QFIbEoUCQmCWD.exe] C:\ProgramData\QFIbEoUCQmCWD.exe () O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.1) O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab (Creative Software AutoUpdate Support Package 1) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.0.43.1 217.0.43.193 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9ED490E5-A5D2-442E-9EA0-75DE411CAA91}: DhcpNameServer = 217.0.43.1 217.0.43.193 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O24 - Desktop BackupWallPaper: C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programme\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012.02.03 17:18:09 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Wolfi\Desktop\esetsmartinstaller_enu.exe [2012.02.03 15:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.02.03 15:00:42 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\Desktop\Malwarebytes' Anti-Malware [2012.02.02 16:53:46 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check [2012.02.01 13:12:02 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Creative [2012.02.01 13:12:02 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Creative [2012.02.01 12:58:52 | 000,090,112 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\Updreg.EXE [2012.02.01 12:58:05 | 000,094,208 | ---- | C] (Creative Technology Ltd) -- C:\Windows\System32\cttele32.dll [2012.02.01 12:56:04 | 000,048,400 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\AddCat.exe [2012.02.01 12:54:28 | 000,011,264 | ---- | C] (Creative Technology Ltd) -- C:\Windows\CTDCRGER.DLL [2012.02.01 12:53:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center [2012.01.27 19:01:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs [2012.01.26 15:43:50 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Magic Set Editor [2012.01.26 15:43:17 | 000,000,000 | ---D | C] -- C:\Program Files\Magic Set Editor 2 [2012.01.25 20:34:36 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\.minecraft [2012.01.22 12:35:41 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Day 1 Studios [2012.01.22 10:24:52 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll [2012.01.22 10:24:52 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll [2012.01.11 11:20:07 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciseq.dll [2012.01.11 11:20:03 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll [2012.01.11 11:20:01 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll [2012.01.11 11:19:57 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll [2012.01.11 11:19:57 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll [2012.01.10 12:28:34 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Local\SWTOR [2012.01.10 12:28:31 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\Documents\HeroBlade Logs [2012.01.10 11:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA [2012.01.10 11:10:08 | 000,000,000 | ---D | C] -- C:\Star Wars-The Old Republic [2012.01.09 11:17:56 | 000,000,000 | ---D | C] -- C:\Microsoft Games [2012.01.06 18:22:23 | 000,021,992 | ---- | C] (CPUID) -- C:\Windows\System32\drivers\cpuz135_x32.sys [2012.01.06 18:22:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID [2012.01.06 18:22:23 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID [2007.10.25 14:57:44 | 000,034,816 | ---- | C] ( ) -- C:\Windows\System32\A3D.DLL [2007.10.25 14:42:46 | 000,010,240 | ---- | C] ( ) -- C:\Windows\System32\KILLAPPS.EXE [7 C:\Users\Wolfi\Documents\*.tmp files -> C:\Users\Wolfi\Documents\*.tmp -> ] [3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012.02.03 17:18:14 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Wolfi\Desktop\esetsmartinstaller_enu.exe [2012.02.03 17:10:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012.02.03 17:06:59 | 000,003,840 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012.02.03 17:06:59 | 000,003,840 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012.02.03 14:50:05 | 000,002,116 | ---- | M] () -- C:\Users\Wolfi\0302backup.zip [2012.02.02 17:26:42 | 000,000,456 | ---- | M] () -- C:\ProgramData\ekMFD1W9NQq5nU [2012.02.02 17:25:29 | 000,000,304 | ---- | M] () -- C:\ProgramData\~ekMFD1W9NQq5nU [2012.02.02 17:25:29 | 000,000,224 | ---- | M] () -- C:\ProgramData\~ekMFD1W9NQq5nUr [2012.02.02 17:18:57 | 449,706,338 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012.02.02 16:53:46 | 000,000,605 | ---- | M] () -- C:\Users\Wolfi\Desktop\System Check.lnk [2012.02.02 16:53:36 | 000,336,520 | ---- | M] () -- C:\ProgramData\ekMFD1W9NQq5nU.exe [2012.02.02 16:51:54 | 000,064,756 | ---- | M] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx [2012.02.02 16:51:54 | 000,054,156 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx [2012.02.02 16:51:54 | 000,054,156 | ---- | M] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx [2012.02.02 16:45:36 | 000,427,144 | -HS- | M] () -- C:\ProgramData\QFIbEoUCQmCWD.exe [2012.02.02 14:54:43 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini [2012.02.02 14:51:18 | 000,193,379 | ---- | M] () -- C:\Users\Wolfi\Documents\gesamt.pdf [2012.02.02 00:03:25 | 000,001,080 | ---- | M] () -- C:\Windows\System32\settingsbkup.sfm [2012.02.02 00:03:25 | 000,001,080 | ---- | M] () -- C:\Windows\System32\settings.sfm [2012.01.31 22:38:56 | 000,000,200 | ---- | M] () -- C:\Users\Wolfi\Desktop\Hitman Blood Money.url [2012.01.31 13:29:09 | 000,361,256 | ---- | M] () -- C:\Users\Wolfi\Documents\Schulgesetz.pdf [2012.01.30 21:49:04 | 000,105,984 | ---- | M] () -- C:\Users\Wolfi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012.01.27 08:35:54 | 000,337,320 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012.01.26 12:49:22 | 000,738,974 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2012.01.26 12:49:22 | 000,687,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012.01.26 12:49:22 | 000,168,432 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2012.01.26 12:49:22 | 000,138,060 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012.01.24 16:46:14 | 000,017,885 | ---- | M] () -- C:\Users\Wolfi\.recently-used.xbel [2012.01.18 03:34:58 | 000,089,114 | ---- | M] () -- C:\Users\Wolfi\Documents\satzung_jusos_region_hannover.pdf [2012.01.13 18:12:23 | 000,766,388 | ---- | M] () -- C:\Users\Wolfi\Documents\Antragspaket 2012 UBK.pdf [7 C:\Users\Wolfi\Documents\*.tmp files -> C:\Users\Wolfi\Documents\*.tmp -> ] [3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012.02.03 14:50:05 | 000,002,116 | ---- | C] () -- C:\Users\Wolfi\0302backup.zip [2012.02.02 16:57:47 | 000,000,304 | ---- | C] () -- C:\ProgramData\~ekMFD1W9NQq5nU [2012.02.02 16:57:47 | 000,000,224 | ---- | C] () -- C:\ProgramData\~ekMFD1W9NQq5nUr [2012.02.02 16:53:46 | 000,000,605 | ---- | C] () -- C:\Users\Wolfi\Desktop\System Check.lnk [2012.02.02 16:53:43 | 000,000,456 | ---- | C] () -- C:\ProgramData\ekMFD1W9NQq5nU [2012.02.02 16:53:32 | 000,336,520 | ---- | C] () -- C:\ProgramData\ekMFD1W9NQq5nU.exe [2012.02.02 16:48:39 | 000,427,144 | -HS- | C] () -- C:\ProgramData\QFIbEoUCQmCWD.exe [2012.02.02 14:51:18 | 000,193,379 | ---- | C] () -- C:\Users\Wolfi\Documents\gesamt.pdf [2012.02.02 00:03:25 | 000,001,080 | ---- | C] () -- C:\Windows\System32\settingsbkup.sfm [2012.02.02 00:03:25 | 000,001,080 | ---- | C] () -- C:\Windows\System32\settings.sfm [2012.02.01 13:03:35 | 000,064,756 | ---- | C] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx [2012.02.01 13:03:35 | 000,054,156 | ---- | C] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx [2012.02.01 13:03:35 | 000,054,156 | ---- | C] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx [2012.02.01 12:58:52 | 000,006,123 | ---- | C] () -- C:\Windows\System32\AudioDrv.ini [2012.02.01 12:56:04 | 001,048,576 | ---- | C] () -- C:\Windows\System32\CT1MGM.ROM [2012.02.01 12:56:03 | 000,098,174 | ---- | C] () -- C:\Windows\System32\instwdm.ini [2012.02.01 12:56:03 | 000,003,128 | ---- | C] () -- C:\Windows\System32\XFi.bmp [2012.02.01 12:56:03 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini [2012.02.01 12:54:28 | 000,003,072 | ---- | C] () -- C:\Windows\CTXFIGER.DLL [2012.02.01 12:53:39 | 007,572,224 | ---- | C] () -- C:\Windows\System32\CT8MGM.SF2 [2012.02.01 12:53:38 | 004,174,814 | ---- | C] () -- C:\Windows\System32\CT4MGM.SF2 [2012.02.01 12:53:37 | 002,167,684 | ---- | C] () -- C:\Windows\System32\CT2MGM.SF2 [2012.02.01 12:53:29 | 029,705,938 | ---- | C] () -- C:\Windows\System32\28MBGM.sf2 [2012.01.31 22:38:56 | 000,000,200 | ---- | C] () -- C:\Users\Wolfi\Desktop\Hitman Blood Money.url [2012.01.31 13:29:09 | 000,361,256 | ---- | C] () -- C:\Users\Wolfi\Documents\Schulgesetz.pdf [2012.01.24 16:46:14 | 000,017,885 | ---- | C] () -- C:\Users\Wolfi\.recently-used.xbel [2012.01.18 03:34:58 | 000,089,114 | ---- | C] () -- C:\Users\Wolfi\Documents\satzung_jusos_region_hannover.pdf [2012.01.13 18:12:22 | 000,766,388 | ---- | C] () -- C:\Users\Wolfi\Documents\Antragspaket 2012 UBK.pdf [2011.11.08 15:50:51 | 000,110,592 | ---- | C] () -- C:\Windows\System32\rtvcvfw32.dll [2011.10.26 13:47:55 | 000,007,672 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\.freeciv-client-rc-2.3 [2011.10.14 23:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2011.08.27 11:56:33 | 000,000,133 | ---- | C] () -- C:\Windows\Wininit.INI [2011.08.19 10:26:20 | 010,898,456 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll [2011.08.19 10:26:20 | 000,336,408 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll [2011.08.19 10:26:20 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe [2011.08.12 12:20:14 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll [2011.07.28 06:36:43 | 000,136,448 | ---- | C] () -- C:\Windows\RMTOOLS.DLL [2011.07.26 07:48:54 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini [2011.07.19 20:33:02 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib [2011.06.13 17:45:05 | 000,038,912 | ---- | C] () -- C:\Windows\System32\NVDevTray.dll [2011.06.13 17:44:02 | 000,151,552 | ---- | C] () -- C:\Windows\System32\nvRegDev.dll [2011.06.13 17:43:47 | 001,388,544 | ---- | C] () -- C:\Windows\System32\nvpmapi.dll [2011.06.13 17:43:38 | 000,040,960 | ---- | C] () -- C:\Windows\System32\nvISWOW64.dll [2011.05.27 02:40:40 | 000,166,912 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL [2011.05.27 02:40:40 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL [2011.05.15 20:49:27 | 000,008,541 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.bko [2011.05.15 13:02:48 | 000,008,564 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.bk! [2011.05.15 13:01:47 | 000,008,541 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.bak [2011.05.15 01:01:59 | 000,008,564 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.ini [2011.05.13 21:01:49 | 000,000,001 | ---- | C] () -- C:\Windows\System32\SI.bin [2011.04.26 20:43:07 | 000,036,892 | ---- | C] () -- C:\Windows\System32\bassmod.dll [2011.04.25 21:52:34 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI [2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011.03.11 17:17:58 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll [2011.03.11 17:17:58 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys [2010.12.25 09:10:28 | 000,056,320 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll [2010.12.24 05:06:16 | 000,028,052 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\OFMissionEditorConfig.xml [2010.11.11 20:19:24 | 000,021,080 | ---- | C] () -- C:\Windows\System32\drivers\ntiopnp.sys [2010.10.03 10:24:10 | 000,000,760 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\setup_ldm.iss [2010.09.07 11:36:06 | 000,860,160 | ---- | C] () -- C:\Windows\System32\spk.dll [2010.08.27 14:07:05 | 000,090,624 | ---- | C] () -- C:\Windows\VSUNINST.EXE [2010.08.22 22:39:32 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini [2010.08.10 14:49:36 | 000,011,392 | ---- | C] () -- C:\Windows\System32\drivers\ntiomin.sys [2010.07.18 17:20:48 | 000,000,760 | ---- | C] () -- C:\Windows\eReg.dat [2010.07.04 13:21:02 | 000,089,446 | ---- | C] () -- C:\Windows\War3Unin.dat [2010.06.09 19:35:51 | 000,000,069 | ---- | C] () -- C:\Windows\cc.ini [2010.06.02 18:01:52 | 002,580,552 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2010.05.26 22:44:22 | 000,000,022 | ---- | C] () -- C:\Windows\WET.INI [2010.05.07 18:43:30 | 000,025,824 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys [2010.05.01 15:14:23 | 000,000,083 | ---- | C] () -- C:\Windows\CIV.INI [2010.04.27 21:36:04 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll [2010.04.17 20:01:25 | 000,000,026 | ---- | C] () -- C:\Windows\buffygame.INI [2010.03.27 23:22:37 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll [2010.03.25 15:29:11 | 000,020,992 | ---- | C] () -- C:\Windows\jestertb.dll [2010.02.21 09:42:56 | 000,000,551 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\AutoGK.ini [2010.02.18 07:09:56 | 000,261,632 | ---- | C] () -- C:\Windows\PEV.exe [2010.02.18 07:09:56 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe [2010.02.18 07:09:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2010.02.18 07:09:55 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2010.02.18 07:09:55 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2010.02.06 19:39:08 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010.02.06 19:37:52 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010.01.28 01:09:54 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2009.12.23 19:15:47 | 000,113,152 | -HS- | C] () -- C:\Windows\System32\SCX.dll [2009.11.04 17:21:31 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini [2009.10.16 06:50:54 | 000,003,930 | ---- | C] () -- C:\Windows\System32\ludap17.ini [2009.10.04 07:13:20 | 000,000,292 | ---- | C] () -- C:\Windows\vtmb.ini [2009.09.24 02:52:56 | 000,008,312 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\.civclientrc [2009.09.23 16:26:29 | 000,030,439 | ---- | C] () -- C:\Windows\scunin.dat [2009.09.22 19:01:35 | 000,000,179 | ---- | C] () -- C:\Windows\IfoEdit.INI [2009.09.22 17:21:28 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll [2009.09.04 05:46:33 | 000,000,437 | ---- | C] () -- C:\Windows\ACTIVEJP.INI [2009.09.03 02:53:33 | 000,000,307 | ---- | C] () -- C:\Windows\Romme.INI [2009.09.03 02:48:27 | 000,080,896 | ---- | C] () -- C:\Windows\cadkasdeinst01.exe [2009.08.09 22:10:56 | 000,004,620 | ---- | C] () -- C:\Windows\XChange.dat [2009.08.03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll [2009.08.03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe [2009.06.02 09:57:24 | 000,138,056 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PnkBstrK.sys [2009.05.30 00:37:40 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2009.05.30 00:31:52 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2009.05.26 01:38:29 | 000,000,000 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\AVSMediaPlayer.m3u [2009.05.19 02:05:54 | 000,000,340 | ---- | C] () -- C:\Windows\scummvm.ini [2009.03.30 04:16:00 | 000,000,072 | ---- | C] () -- C:\Windows\mix-fx.ini [2009.03.28 20:26:00 | 000,069,632 | R--- | C] () -- C:\Windows\System32\xmltok.dll [2009.03.28 20:26:00 | 000,036,864 | R--- | C] () -- C:\Windows\System32\xmlparse.dll [2009.03.19 16:23:28 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat [2009.03.10 11:14:20 | 000,073,728 | ---- | C] () -- C:\Windows\System32\GkSui18.EXE [2009.03.09 14:25:55 | 000,000,711 | ---- | C] () -- C:\Windows\SIERRA.INI [2009.02.18 17:44:08 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2009.02.18 17:42:22 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2009.02.17 18:01:28 | 000,000,099 | ---- | C] () -- C:\Windows\cdplayer.ini [2009.02.14 13:52:27 | 000,046,592 | ---- | C] () -- C:\Windows\System32\DrvMgt.dll [2009.02.14 13:52:27 | 000,000,712 | ---- | C] () -- C:\Windows\System32\layout.bin [2009.02.12 17:08:00 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2009.02.11 05:25:53 | 000,140,072 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2009.02.11 05:25:46 | 000,280,904 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2009.02.11 05:25:36 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2009.02.10 06:48:37 | 000,105,984 | ---- | C] () -- C:\Users\Wolfi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.02.09 10:56:30 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2009.02.09 10:18:12 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2009.02.09 09:52:42 | 000,000,093 | ---- | C] () -- C:\Users\Wolfi\AppData\Local\fusioncache.dat [2009.02.09 09:18:02 | 000,023,888 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\UserTile.png [2009.02.09 09:08:01 | 000,000,169 | ---- | C] () -- C:\Windows\uno.ini [2009.02.09 09:07:58 | 000,287,744 | ---- | C] () -- C:\Windows\uno364mi.dll [2009.02.09 09:07:58 | 000,109,568 | ---- | C] () -- C:\Windows\vos364mi.dll [2009.02.09 09:07:58 | 000,091,648 | ---- | C] () -- C:\Windows\osl364mi.dll [2009.02.06 17:17:50 | 000,001,356 | ---- | C] () -- C:\Users\Wolfi\AppData\Local\d3d9caps.dat [2008.11.13 06:07:24 | 000,002,177 | ---- | C] () -- C:\Windows\P17EP.ini [2008.01.21 08:15:58 | 000,738,974 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2008.01.21 08:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2008.01.21 08:15:58 | 000,168,432 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2008.01.21 08:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2007.12.04 05:20:30 | 000,001,489 | ---- | C] () -- C:\Windows\P17EP51.ini [2007.10.25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2007.10.25 14:59:44 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CTBURST.DLL [2007.10.25 14:56:28 | 000,037,888 | ---- | C] () -- C:\Windows\System32\PSCONV.EXE [2007.10.25 14:46:54 | 000,325,724 | ---- | C] () -- C:\Windows\System32\CTDLANG.DAT [2007.10.25 14:46:54 | 000,055,904 | ---- | C] () -- C:\Windows\System32\CTDNLSTR.DAT [2007.10.25 14:45:08 | 000,048,128 | ---- | C] () -- C:\Windows\System32\REGPLIB.EXE [2007.10.25 14:44:52 | 000,149,838 | ---- | C] () -- C:\Windows\System32\CTBAS2W.DAT [2007.10.25 14:43:10 | 000,274,587 | ---- | C] () -- C:\Windows\System32\CTSBAS2W.DAT [2007.10.25 14:43:04 | 000,241,084 | ---- | C] () -- C:\Windows\System32\CTSBASW.DAT [2007.10.25 14:43:04 | 000,115,166 | ---- | C] () -- C:\Windows\System32\CTBASICW.DAT [2007.10.25 14:42:50 | 000,313,207 | ---- | C] () -- C:\Windows\System32\CTSTATIC.DAT [2007.10.25 14:42:50 | 000,053,932 | ---- | C] () -- C:\Windows\System32\CTDAUGHT.DAT [2007.10.25 14:42:48 | 000,005,120 | ---- | C] () -- C:\Windows\System32\ENLOCSTR.EXE [2007.09.04 10:56:10 | 000,164,352 | ---- | C] () -- C:\Windows\System32\unrar.dll [2007.08.13 13:45:02 | 000,077,824 | ---- | C] () -- C:\Windows\System32\CTMMACTL.DLL [2007.06.07 05:25:42 | 000,001,578 | ---- | C] () -- C:\Windows\P17EPLS.ini [2007.04.10 22:46:48 | 000,015,498 | ---- | C] () -- C:\Windows\VX3000.ini [2007.02.05 19:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI [2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 13:47:37 | 000,337,320 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 11:33:01 | 000,687,942 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 11:33:01 | 000,138,060 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006.10.02 10:25:18 | 000,000,307 | ---- | C] () -- C:\Windows\System32\KILL.INI [2000.02.09 23:00:00 | 000,047,104 | ---- | C] () -- C:\Windows\System32\wrkgadm.exe [2000.02.09 23:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL [1998.06.13 21:53:26 | 000,044,544 | ---- | C] () -- C:\Windows\System32\Gif89.dll [1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys [color=#E56717]========== Files - Unicode (All) ==========[/color] (C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\?????) -- C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\クレージュ (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\クレージュ < End of report >