Di_Nozzo | 30.08.2013 18:01 | Hallo,
hier erstmal die Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-08-2013
Ran by Dennis at 2013-08-30 18:59:53
Running from C:\Users\Dennis\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
2007 Microsoft Office Suite Service Pack 2 (SP2) (x32)
64 Bit HP CIO Components Installer (Version: 6.2.1)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 10 ActiveX (x32 Version: 10.0.32.18)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
AIO_Scan (x32 Version: 130.0.365.000)
AION Free-to-Play (x32)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Ashampoo Burning Studio 2013 v.11.0.6 (x32 Version: 11.0.6)
Avira Free Antivirus (x32 Version: 13.0.0.3885)
Bandicam (x32 Version: 1.8.9.371)
Bandisoft MPEG-1 Decoder (x32)
Battlefield 3™ (x32 Version: 1.0.0.0)
Battlelog Web Plugins (x32 Version: 2.1.7)
Bonjour (Version: 3.0.0.10)
Browser Configuration Utility (x32 Version: 1.1.11.0)
BufferChm (x32 Version: 130.0.331.000)
C4380 (x32 Version: 130.0.365.000)
C4380_Help (x32 Version: 100.0.206.000)
Copy (x32 Version: 130.0.428.000)
Destinations (x32 Version: 130.0.0.0)
DeviceDiscovery (x32 Version: 130.0.465.000)
DocProc (x32 Version: 13.0.0.0)
Dropbox (HKCU Version: 2.0.26)
ESN Sonar (x32 Version: 0.70.4)
Fax (x32 Version: 130.0.418.000)
FIFA 12 (x32 Version: 1.6.0.0)
Free YouTube to MP3 Converter version 3.12.5.628 (x32 Version: 3.12.5.628)
Gameforge Live 1.6.0 "Legend" (x32 Version: 1.6.0)
Gigabyte Raid Configurer (x32 Version: 1.00.0000)
Google Chrome (x32 Version: 29.0.1547.57)
Google Update Helper (x32 Version: 1.3.21.153)
GPBaseService2 (x32 Version: 130.0.371.000)
HP Customer Participation Program 13.0 (Version: 13.0)
HP Photosmart All-In-One Driver Software 13.0 Rel. 2 (Version: 13.0)
HP Photosmart Essential 3.5 (Version: 3.5)
HP Smart Web Printing 4.51 (Version: 4.51)
HP Solution Center 13.0 (Version: 13.0)
HP Update (x32 Version: 4.000.011.006)
HPPhotoGadget (x32 Version: 130.0.282.000)
HPPhotoSmartDiscLabel_PaperLabel (x32 Version: 2.04.0000)
HPPhotoSmartDiscLabel_PrintOnDisc (x32 Version: 2.04.0000)
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000)
hpphotosmartdisclabelplugin (x32 Version: 2.04.0000)
HPPhotosmartEssential (x32 Version: 2.04.0000)
HPProductAssistant (x32 Version: 130.0.371.000)
HPSSupply (x32 Version: 130.0.371.000)
Imaging Device Functions 13.0 (Version: 13.0)
Intel® Matrix Storage Manager
iTunes (Version: 11.0.5.5)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
JDownloader 0.9 (x32 Version: 0.9)
MarketResearch (x32 Version: 130.0.374.000)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6425.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6425.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6425.1000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 17.0.8)
Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Need For Speed™ World (x32 Version: 1.0.0.1516)
Network64 (Version: 130.0.572.000)
NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49)
NVIDIA 3D Vision Treiber 320.49 (Version: 320.49)
NVIDIA GeForce Experience 1.5 (Version: 1.5)
NVIDIA Grafiktreiber 320.49 (Version: 320.49)
NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2)
NVIDIA Install Application (Version: 2.1002.124.810)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049)
NVIDIA Systemsteuerung 320.49 (Version: 320.49)
NVIDIA Update 4.11.9 (Version: 4.11.9)
NVIDIA Update Components (Version: 4.11.9)
OCR Software by I.R.I.S. 13.0 (Version: 13.0)
Origin (x32 Version: 9.2.1.4399)
Picasa 3 (x32 Version: 3.9)
PS_AIO_02_ProductContext (x32 Version: 130.0.365.000)
PS_AIO_02_Software (x32 Version: 130.0.365.000)
PS_AIO_02_Software_Min (x32 Version: 130.0.365.000)
PunkBuster Services (x32 Version: 0.991)
Realtek Ethernet Controller Driver (x32 Version: 1.00.0008)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5924)
RocketDock 1.3.5 (x32)
Scan (x32 Version: 13.0.0.0)
Shop for HP Supplies (Version: 13.0)
Skype™ 6.6 (x32 Version: 6.6.106)
SmartWebPrinting (x32 Version: 130.0.457.000)
SolutionCenter (x32 Version: 130.0.373.000)
Status (x32 Version: 130.0.469.000)
TeamSpeak 3 Client (Version: 3.0.11.1)
Toolbox (x32 Version: 130.0.648.000)
TrayApp (x32 Version: 130.0.422.000)
TuneUp Utilities (x32 Version: 9.0.2010.9)
TuneUp Utilities Language Pack (de-DE) (x32 Version: 9.0.2010.9)
UnloadSupport (x32 Version: 11.0.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
VLC media player 2.0.7 (x32 Version: 2.0.7)
WebReg (x32 Version: 130.0.132.017)
Winamp (x32 Version: 5.64 )
==================== Restore Points =========================
17-08-2013 16:02:33 DirectX wurde installiert
25-08-2013 12:52:31 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => C:\Windows\System32\ndfapi.dll [2009-07-14] (Microsoft Corporation)
Task: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => C:\Windows\System32\ndfapi.dll [2009-07-14] (Microsoft Corporation)
Task: {15CE911A-E399-430D-960F-CC677B64264B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-04] (Google Inc.)
Task: {62E6D3E0-574D-4579-A46F-09750E425E35} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\System32\srrstr.dll [2010-11-20] (Microsoft Corporation)
Task: {A3119FE1-82ED-40E6-9702-BE0AF6526213} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => C:\Windows\System32\dfdts.dll [2009-07-14] (Microsoft Corporation)
Task: {A7C73732-9F11-4281-8D19-764D4EC9D94D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\System32\aepdu.dll [2010-11-20] (Microsoft Corporation)
Task: {A94E5AFE-63FA-4963-B30B-61EAA7564118} - System32\Tasks\Automatische Problemsuche => C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-11-13] (TuneUp Software)
Task: {B3B7C723-C7FD-4E7A-B09A-0A428E422555} - \BrowserDefendert No Task File
Task: {B608DB51-76B9-4F33-835D-2FF3A27BCBC2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-04] (Google Inc.)
Task: {BF1CE034-B09C-4E97-B4D6-EE6288721812} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation)
Task: {D6D2B546-4430-420A-9A6C-67AA3381A307} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files (x86)\TuneUp Utilities 2010\OneClick.exe [2009-11-13] (TuneUp Software)
Task: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => C:\Windows\System32\acproxy.dll [2009-07-14] (Microsoft Corporation)
Task: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => C:\Windows\System32\bfe.dll [2010-11-20] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/29/2013 05:07:00 PM) (Source: Application Hang) (User: )
Description: Programm CabalMain.exe, Version 1.0.0.111 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 11cc
Startzeit: 01cea4c82ce87f13
Endzeit: 77
Anwendungspfad: F:\Downloads\BEAST Cabal EP8\CabalMain.exe
Berichts-ID: 9eaf8ba5-10bc-11e3-97f2-6cf049006291
Error: (08/22/2013 03:30:33 PM) (Source: Application Hang) (User: )
Description: Programm Origin.exe, Version 9.3.1.4482 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: c04
Startzeit: 01ce9f290ae72497
Endzeit: 10
Anwendungspfad: D:\Programme\Origin\Origin.exe
Berichts-ID: 03123367-0b2f-11e3-b8a6-6cf049006291
Error: (08/20/2013 10:19:00 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: vlc.exe, Version: 2.0.7.0, Zeitstempel: 0x51b24edb
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18205, Zeitstempel: 0x51db9710
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000ce753
ID des fehlerhaften Prozesses: 0x404
Startzeit der fehlerhaften Anwendung: 0xvlc.exe0
Pfad der fehlerhaften Anwendung: vlc.exe1
Pfad des fehlerhaften Moduls: vlc.exe2
Berichtskennung: vlc.exe3
Error: (08/07/2013 04:17:32 PM) (Source: Application Hang) (User: )
Description: Programm nfsw.exe, Version 1.0.0.1594 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: ad4
Startzeit: 01ce93760be1f3c3
Endzeit: 184
Anwendungspfad: C:\ProgramData\Electronic Arts\Need for Speed World\Data\nfsw.exe
Berichts-ID: 16b19063-ff6c-11e2-8b47-6cf049006291
Error: (08/06/2013 05:30:36 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: nfsw.exe, Version: 1.0.0.1577, Zeitstempel: 0x51eee757
Name des fehlerhaften Moduls: nfsw.exe, Version: 1.0.0.1577, Zeitstempel: 0x51eee757
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00308a90
ID des fehlerhaften Prozesses: 0xe50
Startzeit der fehlerhaften Anwendung: 0xnfsw.exe0
Pfad der fehlerhaften Anwendung: nfsw.exe1
Pfad des fehlerhaften Moduls: nfsw.exe2
Berichtskennung: nfsw.exe3
Error: (08/05/2013 09:52:28 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: nfsw.exe, Version: 1.0.0.1577, Zeitstempel: 0x51eee757
Name des fehlerhaften Moduls: nfsw.exe, Version: 1.0.0.1577, Zeitstempel: 0x51eee757
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00308a90
ID des fehlerhaften Prozesses: 0x64c
Startzeit der fehlerhaften Anwendung: 0xnfsw.exe0
Pfad der fehlerhaften Anwendung: nfsw.exe1
Pfad des fehlerhaften Moduls: nfsw.exe2
Berichtskennung: nfsw.exe3
Error: (08/05/2013 09:46:46 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: nfsw.exe, Version: 1.0.0.1577, Zeitstempel: 0x51eee757
Name des fehlerhaften Moduls: nfsw.exe, Version: 1.0.0.1577, Zeitstempel: 0x51eee757
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00308a90
ID des fehlerhaften Prozesses: 0xd20
Startzeit der fehlerhaften Anwendung: 0xnfsw.exe0
Pfad der fehlerhaften Anwendung: nfsw.exe1
Pfad des fehlerhaften Moduls: nfsw.exe2
Berichtskennung: nfsw.exe3
Error: (07/31/2013 00:12:30 PM) (Source: Application Hang) (User: )
Description: Programm fifa.exe, Version 1.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 2d4
Startzeit: 01ce8dd666263139
Endzeit: 17
Anwendungspfad: D:\Programme\Fifa 12\Game\fifa.exe
Berichts-ID:
Error: (07/17/2013 09:08:50 PM) (Source: Application Hang) (User: )
Description: Programm CabalMain.exe, Version 1.0.0.111 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 854
Startzeit: 01ce831d3182c535
Endzeit: 0
Anwendungspfad: F:\Downloads\BEAST Cabal EP8\CabalMain.exe
Berichts-ID: 4e932bbb-ef14-11e2-9ed6-6cf049006291
Error: (07/12/2013 11:30:53 PM) (Source: Application Hang) (User: )
Description: Programm CabalMain.exe, Version 1.0.0.111 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 7d0
Startzeit: 01ce7f44ec79ec50
Endzeit: 0
Anwendungspfad: F:\Downloads\BEAST Cabal EP8\CabalMain.exe
Berichts-ID: 529edf22-eb3a-11e2-b49d-6cf049006291
System errors:
=============
Error: (08/30/2013 06:58:47 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/30/2013 06:12:20 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/30/2013 06:12:20 PM) (Source: Server) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{C006A778-29E5-4663-BB15-C1AAF42767B0} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.
Error: (08/30/2013 06:12:17 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/30/2013 06:08:13 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/30/2013 04:47:48 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/30/2013 04:46:43 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/30/2013 04:46:43 PM) (Source: Server) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{C006A778-29E5-4663-BB15-C1AAF42767B0} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.
Error: (08/30/2013 04:46:42 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (08/25/2013 01:28:59 PM) (Source: NetBT) (User: )
Description: Der Name "DENNIS-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.20
registriert werden. Der Computer mit IP-Adresse 192.168.178.22 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 26%
Total physical RAM: 8187.48 MB
Available physical RAM: 6042.39 MB
Total Pagefile: 16373.15 MB
Available Pagefile: 13875.89 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.79 GB) (Free:53.92 GB) NTFS
Drive d: () (Fixed) (Total:465.76 GB) (Free:283.97 GB) NTFS
Drive f: (Elements) (Fixed) (Total:1863.01 GB) (Free:865.74 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: BCD08ED6)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DAB0D2D4)
Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 77F48992)
Partition 1: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 000658B4)
Partition 1: (Not Active) - (Size=-198627557376) - (Type=07 NTFS)
==================== End Of Log ============================
Und die FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Dennis (administrator) on 30-08-2013 18:59:25
Running from C:\Users\Dennis\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesApp64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Dropbox, Inc.) C:\Users\Dennis\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8084000 2009-08-25] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [RocketDock] - C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
MountPoints2: {60d3d663-e4c2-11e2-afd0-806e6f6e6963} - E:\Run.exe
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-04] (Avira Operations GmbH & Co. KG)
AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll [97280 2009-07-14] ()
Startup: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Dennis\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {26E41631-48C7-4d11-B501-C20AB070B206} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBD
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\0jrslzta.default
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\0jrslzta.default\Extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: "homepage": null,
CHR Extension: (ProxTube) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0
CHR Extension: (Google Docs) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-04] (Avira Operations GmbH & Co. KG)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-07-24] ()
S3 TuneUp.Defrag; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [607048 2013-07-04] (TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [1353544 2009-11-13] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-07-04] (Avira Operations GmbH & Co. KG)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [11856 2009-10-14] (TuneUp Software)
R2 WinRing0_1_2_0; C:\Users\Dennis\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries25.gadget\WinRing0x64.sys [14544 2013-07-04] (OpenLibSys.org)
S3 gdrv; \??\C:\Windows\gdrv.sys [x]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x]
S3 X6va013; \??\C:\Windows\SysWOW64\Drivers\X6va013 [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-30 18:58 - 2013-08-30 18:58 - 01579080 _____ (Farbar) C:\Users\Dennis\Desktop\FRST64.exe
2013-08-30 18:08 - 2013-08-30 18:10 - 00000000 ____D C:\AdwCleaner
2013-08-30 18:08 - 2013-08-30 18:08 - 00994642 _____ C:\Users\Dennis\Downloads\adwcleaner.exe
2013-08-18 19:53 - 2013-08-18 19:53 - 00001323 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 2013.lnk
2013-08-18 19:53 - 2013-08-18 19:53 - 00000000 ____D C:\ProgramData\Ashampoo
2013-08-18 19:53 - 2013-08-18 19:53 - 00000000 ____D C:\Program Files (x86)\Ashampoo
2013-08-18 19:48 - 2013-08-10 16:12 - 00000000 ____D C:\Users\Dennis\Downloads\Chrome Division.002
2013-08-17 18:06 - 2013-08-17 18:06 - 00000000 ____D C:\Users\Dennis\AppData\Local\Chromium
2013-08-17 15:35 - 2013-08-17 15:35 - 00000000 ____D C:\Users\Dennis\AppData\Local\Gameforge4d
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\Program Files\iTunes
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\Program Files\iPod
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-16 01:21 - 2013-08-16 01:21 - 00000098 _____ C:\Windows\DeleteOnReboot.bat
2013-08-16 01:20 - 2013-08-16 01:21 - 00004531 _____ C:\AdwCleaner[S1].txt
2013-08-15 00:27 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-15 00:27 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-15 00:27 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-15 00:27 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-15 00:27 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-15 00:27 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-15 00:27 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-15 00:27 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-15 00:27 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-15 00:27 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-15 00:27 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-15 00:27 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-15 00:27 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-15 00:27 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-15 00:24 - 2013-08-15 00:25 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 18:38 - 2013-08-14 18:38 - 00000128 _____ C:\Users\Dennis\Desktop\rfh.txt
2013-08-14 14:43 - 2013-08-14 14:43 - 00000000 ____D C:\Users\Dennis\Documents\Eigene Scans
2013-08-14 14:19 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 14:19 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 14:19 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 14:19 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 14:19 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 14:19 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 14:19 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 14:19 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 14:19 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 14:19 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 14:19 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 14:19 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 14:19 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 14:19 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 14:19 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 14:19 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 14:19 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 14:19 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 14:19 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 14:19 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 14:19 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 14:19 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 14:19 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 14:19 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 14:19 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 14:19 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 14:19 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-11 00:47 - 2013-08-11 00:47 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-08-11 00:47 - 2013-08-11 00:47 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-08-10 18:41 - 2013-08-10 18:41 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\WinRAR
2013-08-10 02:27 - 2013-08-10 18:12 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-08-07 21:32 - 2013-08-07 21:32 - 00000000 ____D C:\Users\Dennis\Documents\Need for Speed World
2013-08-07 00:18 - 2013-08-07 15:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-06 12:54 - 2013-08-30 18:12 - 00000000 ___RD C:\Users\Dennis\Dropbox
2013-08-06 12:53 - 2013-08-30 18:12 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Dropbox
2013-08-06 12:53 - 2013-08-06 12:53 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-08-04 22:24 - 2013-08-04 22:24 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Need for Speed World
2013-08-04 21:48 - 2013-08-04 21:48 - 00000000 ____D C:\Users\Dennis\AppData\Local\Electronic_Arts_Inc
2013-08-01 15:58 - 2013-08-01 15:58 - 00000000 ____D C:\Program Files\7-Zip
2013-07-31 15:45 - 2013-07-31 15:45 - 00000000 ___HD C:\Users\Dennis\Downloads\.picasaoriginals
2013-07-31 15:33 - 2013-07-31 15:45 - 00000291 ____H C:\Users\Dennis\Downloads\.picasa.ini
2013-07-31 00:29 - 2013-08-10 02:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-31 00:29 - 2013-07-31 00:29 - 00000000 ____D C:\Users\Dennis\AppData\Local\Mozilla
==================== One Month Modified Files and Folders =======
2013-08-30 18:58 - 2013-08-30 18:58 - 01579080 _____ (Farbar) C:\Users\Dennis\Desktop\FRST64.exe
2013-08-30 18:50 - 2013-07-04 18:38 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-30 18:47 - 2013-07-04 19:42 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\TS3Client
2013-08-30 18:46 - 2013-07-04 18:46 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Skype
2013-08-30 18:19 - 2009-07-14 06:45 - 00013232 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-30 18:19 - 2009-07-14 06:45 - 00013232 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-30 18:18 - 2009-07-14 19:58 - 00696620 _____ C:\Windows\system32\perfh007.dat
2013-08-30 18:18 - 2009-07-14 19:58 - 00147916 _____ C:\Windows\system32\perfc007.dat
2013-08-30 18:18 - 2009-07-14 07:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-30 18:15 - 2013-07-04 18:04 - 01237612 _____ C:\Windows\WindowsUpdate.log
2013-08-30 18:12 - 2013-08-06 12:54 - 00000000 ___RD C:\Users\Dennis\Dropbox
2013-08-30 18:12 - 2013-08-06 12:53 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Dropbox
2013-08-30 18:12 - 2013-07-04 18:38 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-30 18:12 - 2013-07-04 18:31 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-30 18:12 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-30 18:12 - 2009-07-14 06:51 - 00030407 _____ C:\Windows\setupact.log
2013-08-30 18:10 - 2013-08-30 18:08 - 00000000 ____D C:\AdwCleaner
2013-08-30 18:08 - 2013-08-30 18:08 - 00994642 _____ C:\Users\Dennis\Downloads\adwcleaner.exe
2013-08-30 00:54 - 2013-07-05 01:06 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\vlc
2013-08-29 00:11 - 2013-07-05 16:52 - 00000000 ____D C:\Users\Dennis\Documents\FIFA 12
2013-08-25 01:11 - 2013-07-06 20:16 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-08-25 01:11 - 2013-07-06 20:16 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-08-25 01:11 - 2013-07-06 20:16 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-08-18 19:53 - 2013-08-18 19:53 - 00001323 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 2013.lnk
2013-08-18 19:53 - 2013-08-18 19:53 - 00000000 ____D C:\ProgramData\Ashampoo
2013-08-18 19:53 - 2013-08-18 19:53 - 00000000 ____D C:\Program Files (x86)\Ashampoo
2013-08-18 19:53 - 2013-07-05 12:53 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Ashampoo
2013-08-18 19:53 - 2013-07-05 12:53 - 00000000 ____D C:\Users\Dennis\AppData\Local\Ashampoo
2013-08-17 18:06 - 2013-08-17 18:06 - 00000000 ____D C:\Users\Dennis\AppData\Local\Chromium
2013-08-17 18:03 - 2013-07-05 16:51 - 00080251 _____ C:\Windows\DirectX.log
2013-08-17 15:35 - 2013-08-17 15:35 - 00000000 ____D C:\Users\Dennis\AppData\Local\Gameforge4d
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\Program Files\iTunes
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\Program Files\iPod
2013-08-17 14:59 - 2013-08-17 14:59 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-08-16 15:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-16 01:21 - 2013-08-16 01:21 - 00000098 _____ C:\Windows\DeleteOnReboot.bat
2013-08-16 01:21 - 2013-08-16 01:20 - 00004531 _____ C:\AdwCleaner[S1].txt
2013-08-15 00:25 - 2013-08-15 00:24 - 00000000 ____D C:\Windows\system32\MRT
2013-08-15 00:24 - 2013-07-05 12:48 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-14 18:38 - 2013-08-14 18:38 - 00000128 _____ C:\Users\Dennis\Desktop\rfh.txt
2013-08-14 14:43 - 2013-08-14 14:43 - 00000000 ____D C:\Users\Dennis\Documents\Eigene Scans
2013-08-14 14:42 - 2013-07-06 16:17 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\HP
2013-08-11 00:47 - 2013-08-11 00:47 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-08-11 00:47 - 2013-08-11 00:47 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-08-10 18:41 - 2013-08-10 18:41 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\WinRAR
2013-08-10 18:12 - 2013-08-10 02:27 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-08-10 16:12 - 2013-08-18 19:48 - 00000000 ____D C:\Users\Dennis\Downloads\Chrome Division.002
2013-08-10 15:14 - 2013-07-05 12:24 - 00011140 _____ C:\Windows\PFRO.log
2013-08-10 02:27 - 2013-07-31 00:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-08 19:57 - 2013-07-04 19:41 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-08-07 21:32 - 2013-08-07 21:32 - 00000000 ____D C:\Users\Dennis\Documents\Need for Speed World
2013-08-07 19:33 - 2013-07-04 18:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-07 15:55 - 2013-08-07 00:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-06 23:38 - 2013-07-04 18:56 - 00000000 ____D C:\Users\Dennis\AppData\Local\Thunderbird
2013-08-06 12:54 - 2013-07-04 18:04 - 00000000 ____D C:\Users\Dennis
2013-08-06 12:53 - 2013-08-06 12:53 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-08-06 12:53 - 2013-07-04 18:04 - 00000000 ___RD C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-04 22:24 - 2013-08-04 22:24 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Need for Speed World
2013-08-04 21:48 - 2013-08-04 21:48 - 00000000 ____D C:\Users\Dennis\AppData\Local\Electronic_Arts_Inc
2013-08-04 20:44 - 2013-07-04 18:04 - 00000000 ____D C:\Users\Dennis\AppData\Local\VirtualStore
2013-08-01 15:58 - 2013-08-01 15:58 - 00000000 ____D C:\Program Files\7-Zip
2013-07-31 15:45 - 2013-07-31 15:45 - 00000000 ___HD C:\Users\Dennis\Downloads\.picasaoriginals
2013-07-31 15:45 - 2013-07-31 15:33 - 00000291 ____H C:\Users\Dennis\Downloads\.picasa.ini
2013-07-31 12:15 - 2013-07-23 15:31 - 00000006 _____ C:\folder.ini
2013-07-31 12:13 - 2013-07-22 20:45 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Origin
2013-07-31 12:13 - 2013-07-22 20:45 - 00000000 ____D C:\Users\Dennis\AppData\Local\Origin
2013-07-31 00:29 - 2013-07-31 00:29 - 00000000 ____D C:\Users\Dennis\AppData\Local\Mozilla
2013-07-31 00:29 - 2013-07-04 18:54 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Mozilla
Files to move or delete:
====================
C:\Users\Dennis\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-22 14:37
==================== End Of Log ============================ --- --- --- |