funkynator | 21.09.2013 12:43 | FRST.txt Logfile
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03
Ran by Nonnweiler (administrator) on DER0815 on 21-09-2013 13:39:35
Running from C:\Users\Nonnweiler\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
() C:\Windows\system32\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Pear Media, LLC) C:\Program Files\Chatango\Chatango.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.)
HKCU\...\Run: [Google Update] - C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-16] (Google Inc.)
HKCU\...\Run: [Chatango] - C:\Program Files\Chatango\Chatango.exe [356352 2008-02-05] (Pear Media, LLC)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1811368 2013-09-06] (Valve Corporation)
BootExecute: sasnative32autocheck autochk *
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x303D08A28A75CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {34DC66DB-E913-40A1-A2DD-53A1B9E90CAC} https://col0-sec.mail.live.com/mail/resources/MailMigrationTool.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} hxxp://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.203.0.cab
DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab
DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{010CF5A2-D781-44AF-BDCC-0A72E94BA0BB}: [NameServer]62.109.121.2 62.109.121.1
FireFox:
========
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @ei.Retrogamer_4w.com/Plugin - C:\Program Files\Retrogamer_4wEI\Installr\1.bin\NP4wEISB.dll (Retrogamer)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/DownloadManager,version=1.1 - C:\Windows\ ()
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Nonnweiler\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Nonnweiler\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (Search the web (Babylon)) - hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_btis&mntrId=DC4F7071BCB83C56&affID=122147&tsp=4961
CHR DefaultSuggestURL: (Search the web (Babylon)) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Nonnweiler\AppData\Local\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Nonnweiler\AppData\Local\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Nonnweiler\AppData\Local\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Retrogamer Installer Plugin Stub) - C:\Program Files\Retrogamer_4wEI\Installr\1.bin\NP4wEISB.dll (Retrogamer)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
CHR Extension: (Google Docs) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Battlefield Heroes) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0
CHR Extension: (Google Search) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [dkinklhnkmkhkhofcnapakaoehijaoih] - C:\Program Files\OnlineHD.TV\onhd11.crx
CHR HKLM\...\Chrome\Extension: [jgceplfonlgodadnpognljgdjlcnpjnh] - C:\Program Files\NetRatingsNetSight\NetSight\meter2\extension.crx
========================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-12-19] (Advanced Micro Devices, Inc.)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1440080 2013-06-28] (LogMeIn Inc.)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-04-02] ()
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
S2 BitGuard; C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [48256 2012-04-09] (Advanced Micro Devices)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-03-05] (Duplex Secure Ltd.)
R3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [17920 2009-07-31] (Creative Technology Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 XDva397; \??\C:\Windows\system32\XDva397.sys [x]
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-20 10:51 - 2013-09-20 10:51 - 00005700 _____ C:\Users\Nonnweiler\Desktop\JRT.txt
2013-09-20 10:49 - 2013-09-20 10:49 - 01029675 _____ (Thisisu) C:\Users\Nonnweiler\Desktop\JRT.exe
2013-09-20 10:49 - 2013-09-20 10:49 - 00000000 ____D C:\Windows\ERUNT
2013-09-19 17:44 - 2013-09-19 18:53 - 00000000 ____D C:\AdwCleaner
2013-09-19 17:43 - 2013-09-19 17:44 - 01039554 _____ C:\Users\Nonnweiler\Desktop\adwcleaner.exe
2013-09-19 17:43 - 2013-09-19 17:43 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner (1).exe
2013-09-19 17:40 - 2013-09-19 17:40 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner.exe
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Windows\erdnt
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Qoobox
2013-09-19 14:51 - 2013-09-19 14:51 - 05128554 ____R (Swearware) C:\Users\Nonnweiler\Desktop\ComboFix.exe
2013-09-18 20:16 - 2013-09-18 20:16 - 00031638 _____ C:\Users\Nonnweiler\Desktop\FRST.txt
2013-09-18 20:16 - 2013-09-18 20:16 - 00022109 _____ C:\Users\Nonnweiler\Desktop\Addition.txt
2013-09-18 20:13 - 2013-09-18 20:13 - 00000000 ____D C:\FRST
2013-09-18 16:10 - 2013-09-18 16:10 - 01083437 _____ (Farbar) C:\Users\Nonnweiler\Downloads\FRST.exe
2013-09-17 15:36 - 2013-09-17 15:38 - 00000000 ____D C:\Users\Nonnweiler\.smplayer
2013-09-17 15:36 - 2013-09-17 15:36 - 00000971 _____ C:\Users\Public\Desktop\SMPlayer.lnk
2013-09-17 15:36 - 2013-09-17 15:36 - 00000000 ____D C:\Program Files\SMPlayer
2013-09-16 19:28 - 2013-09-19 17:49 - 00000601 _____ C:\Users\Nonnweiler\Desktop\Search.lnk
2013-09-16 19:28 - 2013-09-16 19:28 - 00002235 _____ C:\Users\Public\Desktop\Free WebM Video Converter.lnk
2013-09-16 19:28 - 2013-09-16 19:28 - 00001203 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-09-16 19:28 - 2013-09-16 19:28 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\avgchrome
2013-09-11 12:22 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 12:22 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 12:22 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 12:22 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 12:22 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 12:22 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 12:22 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-11 06:58 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 06:58 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-11 06:58 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 06:58 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 06:58 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 06:58 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 06:58 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 06:58 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 06:58 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-08-25 10:39 - 2013-08-25 10:39 - 00000000 ____D C:\Users\Nonnweiler\Desktop\Myriam Fuerte
2013-08-24 19:57 - 2013-08-24 16:27 - 00717609 _____ C:\Users\Nonnweiler\Desktop\Intro.wmv
2013-08-24 19:54 - 2013-08-24 19:54 - 00000000 ____D C:\Program Files\7-Zip
2013-08-24 16:37 - 2013-08-24 16:37 - 00542167 _____ C:\Users\Nonnweiler\Documents\Intro_BETA.zip
2013-08-24 10:44 - 2013-09-21 10:04 - 00006552 _____ C:\Windows\setupact.log
2013-08-24 10:44 - 2013-09-19 18:46 - 00076456 _____ C:\Windows\PFRO.log
2013-08-24 10:44 - 2013-08-24 10:44 - 00000000 _____ C:\Windows\setuperr.log
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Malwarebytes
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\ProgramData\Malwarebytes
==================== One Month Modified Files and Folders =======
2013-09-21 13:38 - 2012-08-08 19:30 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Skype
2013-09-21 13:29 - 2013-02-16 15:59 - 00001140 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001UA.job
2013-09-21 13:09 - 2012-09-06 18:44 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-21 13:07 - 2012-08-08 19:15 - 01601347 _____ C:\Windows\WindowsUpdate.log
2013-09-21 13:05 - 2013-07-19 11:28 - 00000000 ____D C:\Program Files\Steam
2013-09-21 12:58 - 2012-08-08 19:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-21 12:44 - 2012-08-08 19:58 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\LogMeIn Hamachi
2013-09-21 12:29 - 2013-02-16 15:59 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001Core.job
2013-09-21 12:09 - 2012-09-06 18:44 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-21 10:41 - 2012-10-13 10:22 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\TS3Client
2013-09-21 10:11 - 2009-07-14 06:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-21 10:11 - 2009-07-14 06:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-21 10:04 - 2013-08-24 10:44 - 00006552 _____ C:\Windows\setupact.log
2013-09-21 10:04 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-20 16:40 - 2012-08-08 20:15 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\.minecraft
2013-09-20 16:14 - 2013-01-24 21:35 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\CrashDumps
2013-09-20 10:51 - 2013-09-20 10:51 - 00005700 _____ C:\Users\Nonnweiler\Desktop\JRT.txt
2013-09-20 10:49 - 2013-09-20 10:49 - 01029675 _____ (Thisisu) C:\Users\Nonnweiler\Desktop\JRT.exe
2013-09-20 10:49 - 2013-09-20 10:49 - 00000000 ____D C:\Windows\ERUNT
2013-09-19 20:50 - 2009-07-14 06:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-19 19:58 - 2012-08-08 19:24 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-19 19:58 - 2012-08-08 19:24 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-19 18:53 - 2013-09-19 17:44 - 00000000 ____D C:\AdwCleaner
2013-09-19 18:46 - 2013-08-24 10:44 - 00076456 _____ C:\Windows\PFRO.log
2013-09-19 18:11 - 2013-01-08 15:48 - 00000000 ____D C:\Users\Nonnweiler\Documents\Camtasia Studio
2013-09-19 17:49 - 2013-09-16 19:28 - 00000601 _____ C:\Users\Nonnweiler\Desktop\Search.lnk
2013-09-19 17:49 - 2013-07-23 20:07 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Common
2013-09-19 17:49 - 2012-08-09 21:57 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-19 17:44 - 2013-09-19 17:43 - 01039554 _____ C:\Users\Nonnweiler\Desktop\adwcleaner.exe
2013-09-19 17:43 - 2013-09-19 17:43 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner (1).exe
2013-09-19 17:40 - 2013-09-19 17:40 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner.exe
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Windows\erdnt
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Qoobox
2013-09-19 14:51 - 2013-09-19 14:51 - 05128554 ____R (Swearware) C:\Users\Nonnweiler\Desktop\ComboFix.exe
2013-09-18 20:16 - 2013-09-18 20:16 - 00031638 _____ C:\Users\Nonnweiler\Desktop\FRST.txt
2013-09-18 20:16 - 2013-09-18 20:16 - 00022109 _____ C:\Users\Nonnweiler\Desktop\Addition.txt
2013-09-18 20:13 - 2013-09-18 20:13 - 00000000 ____D C:\FRST
2013-09-18 16:10 - 2013-09-18 16:10 - 01083437 _____ (Farbar) C:\Users\Nonnweiler\Downloads\FRST.exe
2013-09-17 15:38 - 2013-09-17 15:36 - 00000000 ____D C:\Users\Nonnweiler\.smplayer
2013-09-17 15:36 - 2013-09-17 15:36 - 00000971 _____ C:\Users\Public\Desktop\SMPlayer.lnk
2013-09-17 15:36 - 2013-09-17 15:36 - 00000000 ____D C:\Program Files\SMPlayer
2013-09-17 15:36 - 2012-08-08 19:23 - 00000000 ____D C:\Users\Nonnweiler
2013-09-16 19:28 - 2013-09-16 19:28 - 00002235 _____ C:\Users\Public\Desktop\Free WebM Video Converter.lnk
2013-09-16 19:28 - 2013-09-16 19:28 - 00001203 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-09-16 19:28 - 2013-09-16 19:28 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\avgchrome
2013-09-16 19:28 - 2013-05-10 17:35 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-09-16 19:28 - 2013-05-10 17:35 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-09-16 19:28 - 2013-04-13 17:44 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\DVDVideoSoft
2013-09-16 12:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-09-11 14:43 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-09-11 14:20 - 2012-08-08 20:09 - 00000000 ____D C:\Windows\Panther
2013-09-11 14:19 - 2009-07-14 06:33 - 00276232 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-11 14:17 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-09-11 06:59 - 2013-08-14 23:30 - 00000000 ____D C:\Windows\system32\MRT
2013-09-11 06:57 - 2012-08-13 15:55 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-11 06:56 - 2012-08-08 19:32 - 01492188 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-10 17:08 - 2013-04-17 15:06 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-09-04 16:32 - 2013-02-16 16:00 - 00002396 _____ C:\Users\Nonnweiler\Desktop\Google Chrome.lnk
2013-08-31 12:21 - 2012-12-21 16:19 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\PokerStars.EU
2013-08-28 19:48 - 2012-09-10 15:13 - 00282104 _____ C:\Windows\system32\PnkBstrB.xtr
2013-08-28 19:48 - 2012-08-09 10:41 - 00282104 _____ C:\Windows\system32\PnkBstrB.exe
2013-08-28 19:48 - 2012-08-09 10:41 - 00234768 _____ C:\Windows\system32\PnkBstrB.ex0
2013-08-28 19:48 - 2012-08-09 10:41 - 00139424 _____ C:\Windows\system32\Drivers\PnkBstrK.sys
2013-08-25 14:27 - 2012-10-13 10:22 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-08-25 10:39 - 2013-08-25 10:39 - 00000000 ____D C:\Users\Nonnweiler\Desktop\Myriam Fuerte
2013-08-24 19:54 - 2013-08-24 19:54 - 00000000 ____D C:\Program Files\7-Zip
2013-08-24 16:37 - 2013-08-24 16:37 - 00542167 _____ C:\Users\Nonnweiler\Documents\Intro_BETA.zip
2013-08-24 16:27 - 2013-08-24 19:57 - 00717609 _____ C:\Users\Nonnweiler\Desktop\Intro.wmv
2013-08-24 10:44 - 2013-08-24 10:44 - 00000000 _____ C:\Windows\setuperr.log
2013-08-24 10:44 - 2013-05-05 11:19 - 00000000 ____D C:\Users\Nonnweiler\Documents\DCSCMIN
2013-08-24 10:44 - 2012-09-25 16:17 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Malwarebytes
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-23 16:10 - 2012-10-13 15:45 - 00006656 _____ C:\Users\Nonnweiler\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Users\Nonnweiler\AppData\Local\Temp\Quarantine.exe
C:\Users\Nonnweiler\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Nonnweiler\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-16 12:06
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-09-2013 03
Ran by Nonnweiler at 2013-09-21 13:40:13
Running from C:\Users\Nonnweiler\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
7-Zip 9.22beta
Adobe Flash Player 11 ActiveX (Version: 11.8.800.175)
Adobe Shockwave Player 11.6 (Version: 11.6.8.638)
AMD Accelerated Video Transcoding (Version: 12.5.100.21219)
AMD APP SDK Runtime (Version: 10.0.1084.4)
AMD Catalyst Install Manager (Version: 8.0.903.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2012.1219.1521.27485)
AMD Media Foundation Decoders (Version: 1.0.71219.1540)
AMD VISION Engine Control Center (Version: 2012.1219.1521.27485)
Apple Software Update (Version: 2.1.3.127)
AquaSoft DiaShow 8 Ultimate (Version: 8.0.19)
Battlefield Heroes
Battlefield Play4Free
Call of Duty: Black Ops II
Call of Duty: Black Ops II - Multiplayer
Call of Duty: Black Ops II - Zombies
Camtasia Studio 7 (Version: 7.0.1)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2012.1219.1521.27485)
Catalyst Control Center InstallProxy (Version: 2012.1219.1521.27485)
Catalyst Control Center Localization All (Version: 2012.1219.1521.27485)
CCC Help Chinese Standard (Version: 2012.1219.1520.27485)
CCC Help Chinese Traditional (Version: 2012.1219.1520.27485)
CCC Help Czech (Version: 2012.1219.1520.27485)
CCC Help Danish (Version: 2012.1219.1520.27485)
CCC Help Dutch (Version: 2012.1219.1520.27485)
CCC Help English (Version: 2012.1219.1520.27485)
CCC Help Finnish (Version: 2012.1219.1520.27485)
CCC Help French (Version: 2012.1219.1520.27485)
CCC Help German (Version: 2012.1219.1520.27485)
CCC Help Greek (Version: 2012.1219.1520.27485)
CCC Help Hungarian (Version: 2012.1219.1520.27485)
CCC Help Italian (Version: 2012.1219.1520.27485)
CCC Help Japanese (Version: 2012.1219.1520.27485)
CCC Help Korean (Version: 2012.1219.1520.27485)
CCC Help Norwegian (Version: 2012.1219.1520.27485)
CCC Help Polish (Version: 2012.1219.1520.27485)
CCC Help Portuguese (Version: 2012.1219.1520.27485)
CCC Help Russian (Version: 2012.1219.1520.27485)
CCC Help Spanish (Version: 2012.1219.1520.27485)
CCC Help Swedish (Version: 2012.1219.1520.27485)
CCC Help Thai (Version: 2012.1219.1520.27485)
CCC Help Turkish (Version: 2012.1219.1520.27485)
ccc-utility (Version: 2012.1219.1521.27485)
CCleaner (Version: 4.02)
Chatango Message Catcher
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB945282) (Version: 1)
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB946040) (Version: 1)
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB946308) (Version: 1)
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB947540) (Version: 1)
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB947789) (Version: 1)
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB948127) (Version: 1)
Free Pdf Perfect Prereq (Version: 1.0.0.28)
Free WebM Video Converter version 5.0.28.827 (Version: 5.0.28.827)
Free YouTube to MP3 Converter version 3.12.2.430 (Version: 3.12.2.430)
Google Chrome (HKCU Version: 29.0.1547.66)
Google Earth (Version: 6.2.2.6613)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4413.1752)
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
League of Legends (Version: 3.0.1)
LogMeIn Hamachi (Version: 2.1.0.374)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Download Manager (Version: 1.2.1)
Microsoft SQL Server 2008 Management Objects (Version: 10.0.1600.22)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Express Edition with SP1 - FRA (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual*C++ 2008 Express*SP1 -*Français
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries (Version: 6.1.5288.17011)
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - fra (Version: 3.5.30729)
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 (Version: 6.1.5295.17011)
Notepad++ (Version: 6.4.1)
PokerStars.eu
PunkBuster Services (Version: 0.990)
Realtek High Definition Audio Driver (Version: 6.0.1.6531)
Skype™ 6.5 (Version: 6.5.158)
SMPlayer 0.8.6.0 (Version: 0.8.6.0)
Steam (Version: 1.0.0.0)
swMSM (Version: 12.0.0.1)
Synthesia (Version: 8.5)
TeamSpeak 3 Client (Version: 3.0.11.1)
TeamViewer 8 (Version: 8.0.16642)
TmNationsForever
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Vandal 1.0.0.0 (D) (Version: 1.0.0.0)
WinRAR 4.20 (32-Bit) (Version: 4.20.0)
XMedia Recode Version 3.1.6.4 (Version: 3.1.6.4)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {048A0864-9BD7-493C-8584-139B930D0552} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-06] (Google Inc.)
Task: {0B91A6E5-7AAB-45BD-B7FB-548F7DC97098} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {23DE43AB-7704-4781-84DB-E51457BC4891} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-19] (Adobe Systems Incorporated)
Task: {2B5E14E7-2A76-44BD-9A79-ED24E38B5127} - System32\Tasks\Driver Mender-RTMScan => C:\Program Files\Driver Mender\Driver Mender\DriverMender.exe
Task: {4865A1AB-A055-43BD-96C3-D57A3E64F56A} - System32\Tasks\0 => Iexplore.exe
Task: {49D40FD1-25BE-4707-BC27-46AE3BBC61D4} - System32\Tasks\Driver Mender-RTMRules => C:\Program Files\Driver Mender\Driver Mender\DriverMender.exe
Task: {5083C5A2-BC7B-4CF8-8DC2-0A0FD4FC0591} - System32\Tasks\Express FilesUpdate => C:\Program Files\ExpressFiles\EFUpdater.exe
Task: {55A01FB3-8B55-4B04-BEC7-DA2661171F4C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001UA => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.)
Task: {C66473A0-4FEE-45EF-833F-2CA72CF16AE8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001Core => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.)
Task: {CCA536D0-7C0B-496C-B9FC-12F2E80C6126} - System32\Tasks\Driver Mender-RTMUpdater => C:\Program Files\Driver Mender\Driver Mender\DriverMender.exe
Task: {D328BA38-D008-4F12-A205-A61661B095F2} - System32\Tasks\4825 => C:\Windows\System32\wscript.exe [2009-07-14] (Microsoft Corporation)
Task: {D4636923-0553-4240-AA48-38AC8545B4C7} - System32\Tasks\BitGuard => Sc.exe start BitGuard
Task: {E02FE3D8-A22D-412C-BCE4-8AD4BCE9A8C0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd)
Task: {E559DA5A-2750-44B3-B4F5-8690BEE8A443} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {F42844C5-9F33-49D5-8D7A-A650F9B25F19} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-06] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001Core.job => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001UA.job => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-06-03 16:21 - 2013-06-03 16:21 - 00088680 ____R (Skype Technologies) C:\Program Files\Skype\Updater\Updater.dll
2013-09-19 19:58 - 2013-09-19 19:58 - 16244616 ____R (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\Flash32_11_8_800_175.ocx
2013-07-01 08:20 - 2013-08-22 00:18 - 00687104 _____ () C:\Program Files\Steam\SDL2.dll
2013-07-09 17:56 - 2013-09-06 22:55 - 01120680 _____ () C:\Program Files\Steam\bin\chromehtml.DLL
2013-07-09 13:45 - 2013-08-07 21:31 - 20625832 _____ () C:\Program Files\Steam\bin\libcef.dll
2013-06-14 15:49 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files\Steam\bin\avcodec-53.dll
2013-06-14 15:49 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files\Steam\bin\avutil-51.dll
2013-06-14 15:49 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files\Steam\bin\avformat-53.dll
2012-12-19 17:31 - 2012-12-19 17:31 - 00095232 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-07-30 16:13 - 2013-08-25 14:27 - 00230376 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win32.dll
2012-07-30 16:13 - 2013-08-25 14:27 - 00237032 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win32.dll
2012-07-30 16:13 - 2013-08-25 14:27 - 00159208 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\appscanner_plugin.dll
2012-07-30 16:13 - 2013-08-25 14:27 - 00431080 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
2012-08-10 11:18 - 2010-11-20 14:21 - 01202176 _____ (Microsoft Corporation) C:\Windows\System32\Speech\Common\sapi.dll
2013-09-19 19:58 - 2013-09-19 19:58 - 00479112 _____ (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/20/2013 04:14:52 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.11.0.317, Zeitstempel: 0x522fdc68
Name des fehlerhaften Moduls: cgD3D9.dll, Version: 3.0.0.16, Zeitstempel: 0x4d55a06f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000b6539
ID des fehlerhaften Prozesses: 0xd4c
Startzeit der fehlerhaften Anwendung: 0xLeague of Legends.exe0
Pfad der fehlerhaften Anwendung: League of Legends.exe1
Pfad des fehlerhaften Moduls: League of Legends.exe2
Berichtskennung: League of Legends.exe3
Error: (09/20/2013 04:14:05 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.11.0.317, Zeitstempel: 0x522fdc68
Name des fehlerhaften Moduls: cgD3D9.dll, Version: 3.0.0.16, Zeitstempel: 0x4d55a06f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000b6539
ID des fehlerhaften Prozesses: 0x814
Startzeit der fehlerhaften Anwendung: 0xLeague of Legends.exe0
Pfad der fehlerhaften Anwendung: League of Legends.exe1
Pfad des fehlerhaften Moduls: League of Legends.exe2
Berichtskennung: League of Legends.exe3
Error: (09/20/2013 03:10:55 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: t6zm.exe, Version: 1.0.0.1, Zeitstempel: 0x52129451
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0012ec08
ID des fehlerhaften Prozesses: 0x1d04
Startzeit der fehlerhaften Anwendung: 0xt6zm.exe0
Pfad der fehlerhaften Anwendung: t6zm.exe1
Pfad des fehlerhaften Moduls: t6zm.exe2
Berichtskennung: t6zm.exe3
Error: (09/20/2013 03:07:01 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: t6zm.exe, Version: 1.0.0.1, Zeitstempel: 0x52129451
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0012ed58
ID des fehlerhaften Prozesses: 0x1514
Startzeit der fehlerhaften Anwendung: 0xt6zm.exe0
Pfad der fehlerhaften Anwendung: t6zm.exe1
Pfad des fehlerhaften Moduls: t6zm.exe2
Berichtskennung: t6zm.exe3
Error: (09/20/2013 03:05:57 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: t6zm.exe, Version: 1.0.0.1, Zeitstempel: 0x52129451
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0012ec08
ID des fehlerhaften Prozesses: 0x2498
Startzeit der fehlerhaften Anwendung: 0xt6zm.exe0
Pfad der fehlerhaften Anwendung: t6zm.exe1
Pfad des fehlerhaften Moduls: t6zm.exe2
Berichtskennung: t6zm.exe3
Error: (09/20/2013 11:47:56 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: t6mp.exe, Version: 1.0.0.1, Zeitstempel: 0x52103871
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0012edb0
ID des fehlerhaften Prozesses: 0x758
Startzeit der fehlerhaften Anwendung: 0xt6mp.exe0
Pfad der fehlerhaften Anwendung: t6mp.exe1
Pfad des fehlerhaften Moduls: t6mp.exe2
Berichtskennung: t6mp.exe3
Error: (09/20/2013 11:47:01 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: t6mp.exe, Version: 1.0.0.1, Zeitstempel: 0x52103871
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0012ed10
ID des fehlerhaften Prozesses: 0x18d8
Startzeit der fehlerhaften Anwendung: 0xt6mp.exe0
Pfad der fehlerhaften Anwendung: t6mp.exe1
Pfad des fehlerhaften Moduls: t6mp.exe2
Berichtskennung: t6mp.exe3
Error: (09/20/2013 11:10:31 AM) (Source: Application Hang) (User: )
Description: Programm iexplore.exe, Version 10.0.9200.16686 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 14e0
Startzeit: 01ceb5e05d3646d8
Endzeit: 16
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID:
Error: (09/20/2013 11:10:21 AM) (Source: RasClient) (User: )
Description: CoID={67A94FFD-A158-4A13-951C-390D4B415AD6}: Der Benutzer "Der0815\Nonnweiler" hat eine Verbindung mit dem Namen "Breitbandverbindung" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 0.
System errors:
=============
Error: (09/21/2013 01:40:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:39:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:38:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:37:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:36:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:35:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:34:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:33:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:32:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (09/21/2013 01:31:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (09/20/2013 04:14:52 PM) (Source: Application Error)(User: )
Description: League of Legends.exe3.11.0.317522fdc68cgD3D9.dll3.0.0.164d55a06fc0000005000b6539d4c01ceb60bb0500608C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\League of Legends.exeC:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\cgD3D9.dll0393d178-21ff-11e3-970d-7071bcb83c56
Error: (09/20/2013 04:14:05 PM) (Source: Application Error)(User: )
Description: League of Legends.exe3.11.0.317522fdc68cgD3D9.dll3.0.0.164d55a06fc0000005000b653981401ceb60b7cb1e988C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\League of Legends.exeC:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\cgD3D9.dlle7e024b8-21fe-11e3-970d-7071bcb83c56
Error: (09/20/2013 03:10:55 PM) (Source: Application Error)(User: )
Description: t6zm.exe1.0.0.152129451unknown0.0.0.000000000c00000050012ec081d0401ceb602503d4ab8C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exeunknown14b49428-21f6-11e3-970d-7071bcb83c56
Error: (09/20/2013 03:07:01 PM) (Source: Application Error)(User: )
Description: t6zm.exe1.0.0.152129451unknown0.0.0.000000000c00000050012ed58151401ceb60246e3cc58C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exeunknown890dd8a8-21f5-11e3-970d-7071bcb83c56
Error: (09/20/2013 03:05:57 PM) (Source: Application Error)(User: )
Description: t6zm.exe1.0.0.152129451unknown0.0.0.000000000c00000050012ec08249801ceb601e4ff86a8C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exeunknown63468548-21f5-11e3-970d-7071bcb83c56
Error: (09/20/2013 11:47:56 AM) (Source: Application Error)(User: )
Description: t6mp.exe1.0.0.152103871unknown0.0.0.000000000c00000050012edb075801ceb5e6681ebae8C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exeunknownb95a8158-21d9-11e3-970d-7071bcb83c56
Error: (09/20/2013 11:47:01 AM) (Source: Application Error)(User: )
Description: t6mp.exe1.0.0.152103871unknown0.0.0.000000000c00000050012ed1018d801ceb5e4fe1e4e48C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exeunknown98c39c18-21d9-11e3-970d-7071bcb83c56
Error: (09/20/2013 11:10:31 AM) (Source: Application Hang)(User: )
Description: iexplore.exe10.0.9200.1668614e001ceb5e05d3646d816C:\Program Files\Internet Explorer\iexplore.exe
Error: (09/20/2013 11:10:21 AM) (Source: RasClient)(User: )
Description: {67A94FFD-A158-4A13-951C-390D4B415AD6}Der0815\NonnweilerBreitbandverbindung0
==================== Memory info ===========================
Percentage of memory in use: 37%
Total physical RAM: 3583.3 MB
Available physical RAM: 2224.13 MB
Total Pagefile: 7164.9 MB
Available Pagefile: 5522.29 MB
Total Virtual: 2047.88 MB
Available Virtual: 1891.85 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:97.66 GB) (Free:19.92 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: () (Fixed) (Total:820.15 GB) (Free:817.08 GB) NTFS
Drive e: (HP_RECOVERY) (Fixed) (Total:13.6 GB) (Free:1.64 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: B99DD3BF)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=820 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |