got a big FakeHDD Problem. I already clean up a bit with Malewarebytes Anti-Malware, but of course the problem is still there. So I guess I need a OTL Fix for that. Would be great if someone takes a look on it.
OTL logfile created on: 04.02.2012 02:43:13 - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Wolfi\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,36 Gb Available Physical Memory | 72,51% Memory free
7,08 Gb Paging File | 6,37 Gb Available in Paging File | 89,99% Paging File free
Paging file location(s): c:\pagefile.sys 4000 4000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465,76 Gb Total Space | 26,61 Gb Free Space | 5,71% Space Free | Partition Type: NTFS
Computer Name: WOLFI-PC | User Name: Wolfi | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Wolfi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
PRC - C:\Programme\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Programme\Microsoft\Office Live\OfficeLiveSignIn.exe (Microsoft Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Users\Wolfi\AppData\Local\Temp\sfamcc00001.dll ()
MOD - C:\Users\Wolfi\AppData\Local\Temp\sfareca00001.dll ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Programme\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll ()
MOD - C:\Programme\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Programme\WinRAR\RarExt.dll ()
========== Win32 Services (SafeList) ==========
SRV - (CPUCooLServer) -- File not found
SRV - (Creative ALchemy AL1 Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe (Creative Labs)
SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_e286960.dll ()
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UMVPFSrv) -- C:\Programme\Common Files\Logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WAS) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (SandraAgentSrv) -- C:\Systemerkennung\SiSoftware Sandra Lite 2010.SP3\RpcAgentSrv.exe (SiSoftware)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Cherry Device Interface) -- C:\Programme\Cherry\CDI\cdi.exe (ZF Electronics GmbH)
SRV - (AppHostSvc) -- C:\Windows\System32\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (CTAudSvcService) -- C:\Programme\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (cpuz135) -- C:\Windows\System32\drivers\cpuz135_x32.sys (CPUID)
DRV - (LVUVC) Logitech HD Webcam C270(UVC) -- C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) -- C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (speedfan) -- C:\Windows\system32\speedfan.sys (Almico Software)
DRV - (ntiopnp) -- C:\Windows\System32\drivers\ntiopnp.sys ()
DRV - (ntiomin) -- C:\Windows\System32\drivers\ntiomin.sys ()
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (LVPr2Mon) -- C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (SASENUM) -- C:\Programme\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (P17) -- C:\Windows\System32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (RivaTuner32) -- C:\Programme\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys ()
DRV - (SANDRA) -- C:\Systemerkennung\SiSoftware Sandra Lite 2010.SP3\WNt500x86\sandra.sys (SiSoftware)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (cFosNT) -- C:\Windows\System32\Drivers\cFosNT.sys (cFos Software GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH)
DRV - (VX3000) -- C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (ha20x2k) -- C:\Windows\System32\drivers\HA20X2K.SYS (Creative Technology Ltd)
DRV - (emupia) -- C:\Windows\System32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\Windows\System32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\Windows\System32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) -- C:\Windows\System32\drivers\CTOSS2K.SYS (Creative Technology Ltd.)
DRV - (ctdvda2k) -- C:\Windows\System32\drivers\CTDVDA2K.SYS (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\Windows\System32\drivers\CTAUD2K.SYS (Creative Technology Ltd)
DRV - (ctac32k) -- C:\Windows\System32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (CTEXFIFX.DLL) -- C:\Windows\System32\CTEXFIFX.DLL (Creative Technology Ltd.)
DRV - (CTEDSPSY.DLL) -- C:\Windows\System32\CTEDSPSY.DLL (Creative Technology Ltd)
DRV - (CTEDSPIO.DLL) -- C:\Windows\System32\CTEDSPIO.DLL (Creative Technology Ltd)
DRV - (CT20XUT.DLL) -- C:\Windows\System32\CT20XUT.DLL (Creative Technology Ltd.)
DRV - (CTHWIUT.DLL) -- C:\Windows\System32\CTHWIUT.DLL (Creative Technology Ltd.)
DRV - (CTERFXFX.DLL) -- C:\Windows\System32\CTERFXFX.DLL (Creative Technology Ltd)
DRV - (CTEDSPFX.DLL) -- C:\Windows\System32\CTEDSPFX.DLL (Creative Technology Ltd)
DRV - (CTEAPSFX.DLL) -- C:\Windows\System32\CTEAPSFX.DLL (Creative Technology Ltd)
DRV - (CTSBLFX.DLL) -- C:\Windows\System32\CTSBLFX.DLL (Creative Technology Ltd)
DRV - (CTAUDFX.DLL) -- C:\Windows\System32\CTAUDFX.DLL (Creative Technology Ltd)
DRV - (COMMONFX.DLL) -- C:\Windows\System32\COMMONFX.DLL (Creative Technology Ltd)
DRV - (MTOnlPktAlyX) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
DRV - (RTCore32) -- C:\Programme\MSI Afterburner\RTCore32.sys ()
DRV - (giveio) -- C:\Windows\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online....ie_t-online.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.t-online....ir/ie_suche.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online....ie_t-online.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 6F F4 EC 49 B5 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.t-online.de;localhost;<local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=www-proxy.t-online.de:80;ftp=ftp-proxy.t-online.de:80
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: ""
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.104.0: C:\Program Files\Battlelog Web Plugins\1.104.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX Runtime 2.0\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPMPDRM: C:\Program Files\Common Files\mpDRM\NPMPDRM.dll ( )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Wolfi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.12.31 02:34:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.13 19:48:48 | 000,000,000 | ---D | M]
[2009.02.09 11:19:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Extensions
[2012.01.28 21:25:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Firefox\Profiles\r6307irc.default\extensions
[2011.12.24 22:24:16 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Firefox\Profiles\r6307irc.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.03.30 01:05:23 | 000,000,000 | ---D | M] (NoRedirect) -- C:\Users\Wolfi\AppData\Roaming\mozilla\Firefox\Profiles\r6307irc.default\extensions\{c1970c0d-dbe6-4d91-804f-c9c0de643a57}
[2010.04.25 12:30:38 | 000,001,840 | ---- | M] () -- C:\Users\Wolfi\AppData\Roaming\Mozilla\Firefox\Profiles\r6307irc.default\searchplugins\bing.xml
[2012.02.01 14:15:21 | 000,001,056 | ---- | M] () -- C:\Users\Wolfi\AppData\Roaming\Mozilla\Firefox\Profiles\r6307irc.default\searchplugins\icqplugin.xml
[2009.08.29 16:25:07 | 000,000,952 | ---- | M] () -- C:\Users\Wolfi\AppData\Roaming\Mozilla\Firefox\Profiles\r6307irc.default\searchplugins\youtube-videosuche.xml
[2011.12.17 11:12:32 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{79C50F9A-2FFE-4EE0-8A37-FAE4F5DACD4F}.XPI
() (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\WOLFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R6307IRC.DEFAULT\EXTENSIONS\[email protected]
[2011.12.31 02:34:23 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.04 14:49:02 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.04 14:49:02 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.04 14:49:02 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.04 14:49:02 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.04 14:49:02 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.04 14:49:02 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2011.12.06 08:50:07 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programme\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX Runtime 2.0\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programme\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTHelper] C:\Windows\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [P17RunE] C:\Windows\System32\P17RunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [QFIbEoUCQmCWD.exe] C:\ProgramData\QFIbEoUCQmCWD.exe ()
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.2.1)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creat...13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...15116/CTPID.cab (Creative Software AutoUpdate Support Package 1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.0.43.1 217.0.43.193
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9ED490E5-A5D2-442E-9EA0-75DE411CAA91}: DhcpNameServer = 217.0.43.1 217.0.43.193
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programme\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.02.03 17:18:09 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Wolfi\Desktop\esetsmartinstaller_enu.exe
[2012.02.03 15:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.02.03 15:00:42 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\Desktop\Malwarebytes' Anti-Malware
[2012.02.02 16:53:46 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2012.02.01 13:12:02 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Creative
[2012.02.01 13:12:02 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Creative
[2012.02.01 12:58:52 | 000,090,112 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\Updreg.EXE
[2012.02.01 12:58:05 | 000,094,208 | ---- | C] (Creative Technology Ltd) -- C:\Windows\System32\cttele32.dll
[2012.02.01 12:56:04 | 000,048,400 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\AddCat.exe
[2012.02.01 12:54:28 | 000,011,264 | ---- | C] (Creative Technology Ltd) -- C:\Windows\CTDCRGER.DLL
[2012.02.01 12:53:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center
[2012.01.27 19:01:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
[2012.01.26 15:43:50 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Magic Set Editor
[2012.01.26 15:43:17 | 000,000,000 | ---D | C] -- C:\Program Files\Magic Set Editor 2
[2012.01.25 20:34:36 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\.minecraft
[2012.01.22 12:35:41 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Roaming\Day 1 Studios
[2012.01.22 10:24:52 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2012.01.22 10:24:52 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2012.01.11 11:20:07 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciseq.dll
[2012.01.11 11:20:03 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012.01.11 11:20:01 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012.01.11 11:19:57 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012.01.11 11:19:57 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012.01.10 12:28:34 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\AppData\Local\SWTOR
[2012.01.10 12:28:31 | 000,000,000 | ---D | C] -- C:\Users\Wolfi\Documents\HeroBlade Logs
[2012.01.10 11:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
[2012.01.10 11:10:08 | 000,000,000 | ---D | C] -- C:\Star Wars-The Old Republic
[2012.01.09 11:17:56 | 000,000,000 | ---D | C] -- C:\Microsoft Games
[2012.01.06 18:22:23 | 000,021,992 | ---- | C] (CPUID) -- C:\Windows\System32\drivers\cpuz135_x32.sys
[2012.01.06 18:22:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2012.01.06 18:22:23 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2007.10.25 14:57:44 | 000,034,816 | ---- | C] ( ) -- C:\Windows\System32\A3D.DLL
[2007.10.25 14:42:46 | 000,010,240 | ---- | C] ( ) -- C:\Windows\System32\KILLAPPS.EXE
[7 C:\Users\Wolfi\Documents\*.tmp files -> C:\Users\Wolfi\Documents\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.02.03 17:18:14 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Wolfi\Desktop\esetsmartinstaller_enu.exe
[2012.02.03 17:10:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.02.03 17:06:59 | 000,003,840 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.02.03 17:06:59 | 000,003,840 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.02.03 14:50:05 | 000,002,116 | ---- | M] () -- C:\Users\Wolfi\0302backup.zip
[2012.02.02 17:26:42 | 000,000,456 | ---- | M] () -- C:\ProgramData\ekMFD1W9NQq5nU
[2012.02.02 17:25:29 | 000,000,304 | ---- | M] () -- C:\ProgramData\~ekMFD1W9NQq5nU
[2012.02.02 17:25:29 | 000,000,224 | ---- | M] () -- C:\ProgramData\~ekMFD1W9NQq5nUr
[2012.02.02 17:18:57 | 449,706,338 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.02.02 16:53:46 | 000,000,605 | ---- | M] () -- C:\Users\Wolfi\Desktop\System Check.lnk
[2012.02.02 16:53:36 | 000,336,520 | ---- | M] () -- C:\ProgramData\ekMFD1W9NQq5nU.exe
[2012.02.02 16:51:54 | 000,064,756 | ---- | M] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx
[2012.02.02 16:51:54 | 000,054,156 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx
[2012.02.02 16:51:54 | 000,054,156 | ---- | M] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx
[2012.02.02 16:45:36 | 000,427,144 | -HS- | M] () -- C:\ProgramData\QFIbEoUCQmCWD.exe
[2012.02.02 14:54:43 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.02.02 14:51:18 | 000,193,379 | ---- | M] () -- C:\Users\Wolfi\Documents\gesamt.pdf
[2012.02.02 00:03:25 | 000,001,080 | ---- | M] () -- C:\Windows\System32\settingsbkup.sfm
[2012.02.02 00:03:25 | 000,001,080 | ---- | M] () -- C:\Windows\System32\settings.sfm
[2012.01.31 22:38:56 | 000,000,200 | ---- | M] () -- C:\Users\Wolfi\Desktop\Hitman Blood Money.url
[2012.01.31 13:29:09 | 000,361,256 | ---- | M] () -- C:\Users\Wolfi\Documents\Schulgesetz.pdf
[2012.01.30 21:49:04 | 000,105,984 | ---- | M] () -- C:\Users\Wolfi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.27 08:35:54 | 000,337,320 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.01.26 12:49:22 | 000,738,974 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.26 12:49:22 | 000,687,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.26 12:49:22 | 000,168,432 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.26 12:49:22 | 000,138,060 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.24 16:46:14 | 000,017,885 | ---- | M] () -- C:\Users\Wolfi\.recently-used.xbel
[2012.01.18 03:34:58 | 000,089,114 | ---- | M] () -- C:\Users\Wolfi\Documents\satzung_jusos_region_hannover.pdf
[2012.01.13 18:12:23 | 000,766,388 | ---- | M] () -- C:\Users\Wolfi\Documents\Antragspaket 2012 UBK.pdf
[7 C:\Users\Wolfi\Documents\*.tmp files -> C:\Users\Wolfi\Documents\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.02.03 14:50:05 | 000,002,116 | ---- | C] () -- C:\Users\Wolfi\0302backup.zip
[2012.02.02 16:57:47 | 000,000,304 | ---- | C] () -- C:\ProgramData\~ekMFD1W9NQq5nU
[2012.02.02 16:57:47 | 000,000,224 | ---- | C] () -- C:\ProgramData\~ekMFD1W9NQq5nUr
[2012.02.02 16:53:46 | 000,000,605 | ---- | C] () -- C:\Users\Wolfi\Desktop\System Check.lnk
[2012.02.02 16:53:43 | 000,000,456 | ---- | C] () -- C:\ProgramData\ekMFD1W9NQq5nU
[2012.02.02 16:53:32 | 000,336,520 | ---- | C] () -- C:\ProgramData\ekMFD1W9NQq5nU.exe
[2012.02.02 16:48:39 | 000,427,144 | -HS- | C] () -- C:\ProgramData\QFIbEoUCQmCWD.exe
[2012.02.02 14:51:18 | 000,193,379 | ---- | C] () -- C:\Users\Wolfi\Documents\gesamt.pdf
[2012.02.02 00:03:25 | 000,001,080 | ---- | C] () -- C:\Windows\System32\settingsbkup.sfm
[2012.02.02 00:03:25 | 000,001,080 | ---- | C] () -- C:\Windows\System32\settings.sfm
[2012.02.01 13:03:35 | 000,064,756 | ---- | C] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx
[2012.02.01 13:03:35 | 000,054,156 | ---- | C] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx
[2012.02.01 13:03:35 | 000,054,156 | ---- | C] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000003-00001102-00000005-00311102}.rfx
[2012.02.01 12:58:52 | 000,006,123 | ---- | C] () -- C:\Windows\System32\AudioDrv.ini
[2012.02.01 12:56:04 | 001,048,576 | ---- | C] () -- C:\Windows\System32\CT1MGM.ROM
[2012.02.01 12:56:03 | 000,098,174 | ---- | C] () -- C:\Windows\System32\instwdm.ini
[2012.02.01 12:56:03 | 000,003,128 | ---- | C] () -- C:\Windows\System32\XFi.bmp
[2012.02.01 12:56:03 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini
[2012.02.01 12:54:28 | 000,003,072 | ---- | C] () -- C:\Windows\CTXFIGER.DLL
[2012.02.01 12:53:39 | 007,572,224 | ---- | C] () -- C:\Windows\System32\CT8MGM.SF2
[2012.02.01 12:53:38 | 004,174,814 | ---- | C] () -- C:\Windows\System32\CT4MGM.SF2
[2012.02.01 12:53:37 | 002,167,684 | ---- | C] () -- C:\Windows\System32\CT2MGM.SF2
[2012.02.01 12:53:29 | 029,705,938 | ---- | C] () -- C:\Windows\System32\28MBGM.sf2
[2012.01.31 22:38:56 | 000,000,200 | ---- | C] () -- C:\Users\Wolfi\Desktop\Hitman Blood Money.url
[2012.01.31 13:29:09 | 000,361,256 | ---- | C] () -- C:\Users\Wolfi\Documents\Schulgesetz.pdf
[2012.01.24 16:46:14 | 000,017,885 | ---- | C] () -- C:\Users\Wolfi\.recently-used.xbel
[2012.01.18 03:34:58 | 000,089,114 | ---- | C] () -- C:\Users\Wolfi\Documents\satzung_jusos_region_hannover.pdf
[2012.01.13 18:12:22 | 000,766,388 | ---- | C] () -- C:\Users\Wolfi\Documents\Antragspaket 2012 UBK.pdf
[2011.11.08 15:50:51 | 000,110,592 | ---- | C] () -- C:\Windows\System32\rtvcvfw32.dll
[2011.10.26 13:47:55 | 000,007,672 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\.freeciv-client-rc-2.3
[2011.10.14 23:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2011.08.27 11:56:33 | 000,000,133 | ---- | C] () -- C:\Windows\Wininit.INI
[2011.08.19 10:26:20 | 010,898,456 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2011.08.19 10:26:20 | 000,336,408 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2011.08.19 10:26:20 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011.08.12 12:20:14 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011.07.28 06:36:43 | 000,136,448 | ---- | C] () -- C:\Windows\RMTOOLS.DLL
[2011.07.26 07:48:54 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011.07.19 20:33:02 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011.06.13 17:45:05 | 000,038,912 | ---- | C] () -- C:\Windows\System32\NVDevTray.dll
[2011.06.13 17:44:02 | 000,151,552 | ---- | C] () -- C:\Windows\System32\nvRegDev.dll
[2011.06.13 17:43:47 | 001,388,544 | ---- | C] () -- C:\Windows\System32\nvpmapi.dll
[2011.06.13 17:43:38 | 000,040,960 | ---- | C] () -- C:\Windows\System32\nvISWOW64.dll
[2011.05.27 02:40:40 | 000,166,912 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2011.05.27 02:40:40 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2011.05.15 20:49:27 | 000,008,541 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.bko
[2011.05.15 13:02:48 | 000,008,564 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.bk!
[2011.05.15 13:01:47 | 000,008,541 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.bak
[2011.05.15 01:01:59 | 000,008,564 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PStrip.ini
[2011.05.13 21:01:49 | 000,000,001 | ---- | C] () -- C:\Windows\System32\SI.bin
[2011.04.26 20:43:07 | 000,036,892 | ---- | C] () -- C:\Windows\System32\bassmod.dll
[2011.04.25 21:52:34 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.03.11 17:17:58 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.03.11 17:17:58 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.12.25 09:10:28 | 000,056,320 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
[2010.12.24 05:06:16 | 000,028,052 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\OFMissionEditorConfig.xml
[2010.11.11 20:19:24 | 000,021,080 | ---- | C] () -- C:\Windows\System32\drivers\ntiopnp.sys
[2010.10.03 10:24:10 | 000,000,760 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\setup_ldm.iss
[2010.09.07 11:36:06 | 000,860,160 | ---- | C] () -- C:\Windows\System32\spk.dll
[2010.08.27 14:07:05 | 000,090,624 | ---- | C] () -- C:\Windows\VSUNINST.EXE
[2010.08.22 22:39:32 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2010.08.10 14:49:36 | 000,011,392 | ---- | C] () -- C:\Windows\System32\drivers\ntiomin.sys
[2010.07.18 17:20:48 | 000,000,760 | ---- | C] () -- C:\Windows\eReg.dat
[2010.07.04 13:21:02 | 000,089,446 | ---- | C] () -- C:\Windows\War3Unin.dat
[2010.06.09 19:35:51 | 000,000,069 | ---- | C] () -- C:\Windows\cc.ini
[2010.06.02 18:01:52 | 002,580,552 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010.05.26 22:44:22 | 000,000,022 | ---- | C] () -- C:\Windows\WET.INI
[2010.05.07 18:43:30 | 000,025,824 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2010.05.01 15:14:23 | 000,000,083 | ---- | C] () -- C:\Windows\CIV.INI
[2010.04.27 21:36:04 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2010.04.17 20:01:25 | 000,000,026 | ---- | C] () -- C:\Windows\buffygame.INI
[2010.03.27 23:22:37 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2010.03.25 15:29:11 | 000,020,992 | ---- | C] () -- C:\Windows\jestertb.dll
[2010.02.21 09:42:56 | 000,000,551 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\AutoGK.ini
[2010.02.18 07:09:56 | 000,261,632 | ---- | C] () -- C:\Windows\PEV.exe
[2010.02.18 07:09:56 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010.02.18 07:09:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010.02.18 07:09:55 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010.02.18 07:09:55 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010.02.06 19:39:08 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.02.06 19:37:52 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.01.28 01:09:54 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.12.23 19:15:47 | 000,113,152 | -HS- | C] () -- C:\Windows\System32\SCX.dll
[2009.11.04 17:21:31 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini
[2009.10.16 06:50:54 | 000,003,930 | ---- | C] () -- C:\Windows\System32\ludap17.ini
[2009.10.04 07:13:20 | 000,000,292 | ---- | C] () -- C:\Windows\vtmb.ini
[2009.09.24 02:52:56 | 000,008,312 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\.civclientrc
[2009.09.23 16:26:29 | 000,030,439 | ---- | C] () -- C:\Windows\scunin.dat
[2009.09.22 19:01:35 | 000,000,179 | ---- | C] () -- C:\Windows\IfoEdit.INI
[2009.09.22 17:21:28 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2009.09.04 05:46:33 | 000,000,437 | ---- | C] () -- C:\Windows\ACTIVEJP.INI
[2009.09.03 02:53:33 | 000,000,307 | ---- | C] () -- C:\Windows\Romme.INI
[2009.09.03 02:48:27 | 000,080,896 | ---- | C] () -- C:\Windows\cadkasdeinst01.exe
[2009.08.09 22:10:56 | 000,004,620 | ---- | C] () -- C:\Windows\XChange.dat
[2009.08.03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009.08.03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009.06.02 09:57:24 | 000,138,056 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\PnkBstrK.sys
[2009.05.30 00:37:40 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.05.30 00:31:52 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.05.26 01:38:29 | 000,000,000 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\AVSMediaPlayer.m3u
[2009.05.19 02:05:54 | 000,000,340 | ---- | C] () -- C:\Windows\scummvm.ini
[2009.03.30 04:16:00 | 000,000,072 | ---- | C] () -- C:\Windows\mix-fx.ini
[2009.03.28 20:26:00 | 000,069,632 | R--- | C] () -- C:\Windows\System32\xmltok.dll
[2009.03.28 20:26:00 | 000,036,864 | R--- | C] () -- C:\Windows\System32\xmlparse.dll
[2009.03.19 16:23:28 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2009.03.10 11:14:20 | 000,073,728 | ---- | C] () -- C:\Windows\System32\GkSui18.EXE
[2009.03.09 14:25:55 | 000,000,711 | ---- | C] () -- C:\Windows\SIERRA.INI
[2009.02.18 17:44:08 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2009.02.18 17:42:22 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2009.02.17 18:01:28 | 000,000,099 | ---- | C] () -- C:\Windows\cdplayer.ini
[2009.02.14 13:52:27 | 000,046,592 | ---- | C] () -- C:\Windows\System32\DrvMgt.dll
[2009.02.14 13:52:27 | 000,000,712 | ---- | C] () -- C:\Windows\System32\layout.bin
[2009.02.12 17:08:00 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.02.11 05:25:53 | 000,140,072 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009.02.11 05:25:46 | 000,280,904 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2009.02.11 05:25:36 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2009.02.10 06:48:37 | 000,105,984 | ---- | C] () -- C:\Users\Wolfi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.02.09 10:56:30 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.02.09 10:18:12 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.02.09 09:52:42 | 000,000,093 | ---- | C] () -- C:\Users\Wolfi\AppData\Local\fusioncache.dat
[2009.02.09 09:18:02 | 000,023,888 | ---- | C] () -- C:\Users\Wolfi\AppData\Roaming\UserTile.png
[2009.02.09 09:08:01 | 000,000,169 | ---- | C] () -- C:\Windows\uno.ini
[2009.02.09 09:07:58 | 000,287,744 | ---- | C] () -- C:\Windows\uno364mi.dll
[2009.02.09 09:07:58 | 000,109,568 | ---- | C] () -- C:\Windows\vos364mi.dll
[2009.02.09 09:07:58 | 000,091,648 | ---- | C] () -- C:\Windows\osl364mi.dll
[2009.02.06 17:17:50 | 000,001,356 | ---- | C] () -- C:\Users\Wolfi\AppData\Local\d3d9caps.dat
[2008.11.13 06:07:24 | 000,002,177 | ---- | C] () -- C:\Windows\P17EP.ini
[2008.01.21 08:15:58 | 000,738,974 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008.01.21 08:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008.01.21 08:15:58 | 000,168,432 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008.01.21 08:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007.12.04 05:20:30 | 000,001,489 | ---- | C] () -- C:\Windows\P17EP51.ini
[2007.10.25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007.10.25 14:59:44 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CTBURST.DLL
[2007.10.25 14:56:28 | 000,037,888 | ---- | C] () -- C:\Windows\System32\PSCONV.EXE
[2007.10.25 14:46:54 | 000,325,724 | ---- | C] () -- C:\Windows\System32\CTDLANG.DAT
[2007.10.25 14:46:54 | 000,055,904 | ---- | C] () -- C:\Windows\System32\CTDNLSTR.DAT
[2007.10.25 14:45:08 | 000,048,128 | ---- | C] () -- C:\Windows\System32\REGPLIB.EXE
[2007.10.25 14:44:52 | 000,149,838 | ---- | C] () -- C:\Windows\System32\CTBAS2W.DAT
[2007.10.25 14:43:10 | 000,274,587 | ---- | C] () -- C:\Windows\System32\CTSBAS2W.DAT
[2007.10.25 14:43:04 | 000,241,084 | ---- | C] () -- C:\Windows\System32\CTSBASW.DAT
[2007.10.25 14:43:04 | 000,115,166 | ---- | C] () -- C:\Windows\System32\CTBASICW.DAT
[2007.10.25 14:42:50 | 000,313,207 | ---- | C] () -- C:\Windows\System32\CTSTATIC.DAT
[2007.10.25 14:42:50 | 000,053,932 | ---- | C] () -- C:\Windows\System32\CTDAUGHT.DAT
[2007.10.25 14:42:48 | 000,005,120 | ---- | C] () -- C:\Windows\System32\ENLOCSTR.EXE
[2007.09.04 10:56:10 | 000,164,352 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2007.08.13 13:45:02 | 000,077,824 | ---- | C] () -- C:\Windows\System32\CTMMACTL.DLL
[2007.06.07 05:25:42 | 000,001,578 | ---- | C] () -- C:\Windows\P17EPLS.ini
[2007.04.10 22:46:48 | 000,015,498 | ---- | C] () -- C:\Windows\VX3000.ini
[2007.02.05 19:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,337,320 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,687,942 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,138,060 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.02 10:25:18 | 000,000,307 | ---- | C] () -- C:\Windows\System32\KILL.INI
[2000.02.09 23:00:00 | 000,047,104 | ---- | C] () -- C:\Windows\System32\wrkgadm.exe
[2000.02.09 23:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL
[1998.06.13 21:53:26 | 000,044,544 | ---- | C] () -- C:\Windows\System32\Gif89.dll
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
========== Files - Unicode (All) ==========
(C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\?????) -- C:\Users\Wolfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\クレージュ
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\クレージュ
< End of report >