| funkynator |  21.09.2013 12:43 |        FRST.txt Logfile  
FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03 
Ran by Nonnweiler (administrator) on DER0815 on 21-09-2013 13:39:35 
Running from C:\Users\Nonnweiler\Downloads 
Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: German Standard 
Internet Explorer Version 10 
Boot Mode: Normal   
==================== Processes (Whitelisted) ===================   
(AMD) C:\Windows\system32\atiesrxx.exe 
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 
(AMD) C:\Windows\system32\atieclxx.exe 
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe 
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe 
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe 
() C:\Windows\system32\PnkBstrA.exe 
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe 
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe 
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe 
(Pear Media, LLC) C:\Program Files\Chatango\Chatango.exe 
(Valve Corporation) C:\Program Files\Steam\Steam.exe 
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe 
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe 
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe 
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe 
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.exe   
==================== Registry (Whitelisted) ==================   
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) 
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) 
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) 
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.) 
HKCU\...\Run: [Google Update] - C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-16] (Google Inc.) 
HKCU\...\Run: [Chatango] - C:\Program Files\Chatango\Chatango.exe [356352 2008-02-05] (Pear Media, LLC) 
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1811368 2013-09-06] (Valve Corporation) 
BootExecute: sasnative32autocheck autochk *    
==================== Internet (Whitelisted) ====================   
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x303D08A28A75CD01 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de 
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.de/ 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab 
SearchScopes: HKLM - DefaultScope value is missing. 
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =  
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) 
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) 
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) 
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) 
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) 
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab 
DPF: {34DC66DB-E913-40A1-A2DD-53A1B9E90CAC} https://col0-sec.mail.live.com/mail/resources/MailMigrationTool.cab 
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} hxxp://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.203.0.cab 
DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab 
DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 
Tcpip\..\Interfaces\{010CF5A2-D781-44AF-BDCC-0A72E94BA0BB}: [NameServer]62.109.121.2 62.109.121.1   
FireFox: 
======== 
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.) 
FF Plugin: @ei.Retrogamer_4w.com/Plugin - C:\Program Files\Retrogamer_4wEI\Installr\1.bin\NP4wEISB.dll (Retrogamer) 
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) 
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) 
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) 
FF Plugin: @Microsoft.com/DownloadManager,version=1.1 - C:\Windows\ () 
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File 
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Nonnweiler\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Nonnweiler\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)   
Chrome:  
======= 
CHR HomePage: hxxp://www.google.com 
CHR RestoreOnStartup: "hxxp://www.google.com" 
CHR DefaultSearchURL: (Search the web (Babylon)) - hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_btis&mntrId=DC4F7071BCB83C56&affID=122147&tsp=4961 
CHR DefaultSuggestURL: (Search the web (Babylon)) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} 
CHR Plugin: (Shockwave Flash) - C:\Users\Nonnweiler\AppData\Local\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () 
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer 
CHR Plugin: (Native Client) - C:\Users\Nonnweiler\AppData\Local\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () 
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Nonnweiler\AppData\Local\Google\Chrome\Application\29.0.1547.66\pdf.dll () 
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) 
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File 
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) 
CHR Plugin: (Retrogamer Installer Plugin Stub) - C:\Program Files\Retrogamer_4wEI\Installr\1.bin\NP4wEISB.dll (Retrogamer) 
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.) 
CHR Extension: (Google Docs) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 
CHR Extension: (Google Drive) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 
CHR Extension: (YouTube) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 
CHR Extension: (Battlefield Heroes) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0 
CHR Extension: (Google Search) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 
CHR Extension: (Chrome In-App Payments service) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 
CHR Extension: (Gmail) - C:\Users\NONNWE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 
CHR HKLM\...\Chrome\Extension: [dkinklhnkmkhkhofcnapakaoehijaoih] - C:\Program Files\OnlineHD.TV\onhd11.crx 
CHR HKLM\...\Chrome\Extension: [jgceplfonlgodadnpognljgdjlcnpjnh] - C:\Program Files\NetRatingsNetSight\NetSight\meter2\extension.crx   
========================== Services (Whitelisted) =================   
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-12-19] (Advanced Micro Devices, Inc.) 
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1440080 2013-06-28] (LogMeIn Inc.) 
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-04-02] () 
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.) 
S2 BitGuard; C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x]   
==================== Drivers (Whitelisted) ====================   
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [48256 2012-04-09] (Advanced Micro Devices) 
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) 
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) 
S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) 
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-03-05] (Duplex Secure Ltd.) 
R3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [17920 2009-07-31] (Creative Technology Ltd.) 
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) 
S3 XDva397; \??\C:\Windows\system32\XDva397.sys [x] 
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [x]   
==================== NetSvcs (Whitelisted) ===================     
==================== One Month Created Files and Folders ========   
2013-09-20 10:51 - 2013-09-20 10:51 - 00005700 _____ C:\Users\Nonnweiler\Desktop\JRT.txt 
2013-09-20 10:49 - 2013-09-20 10:49 - 01029675 _____ (Thisisu) C:\Users\Nonnweiler\Desktop\JRT.exe 
2013-09-20 10:49 - 2013-09-20 10:49 - 00000000 ____D C:\Windows\ERUNT 
2013-09-19 17:44 - 2013-09-19 18:53 - 00000000 ____D C:\AdwCleaner 
2013-09-19 17:43 - 2013-09-19 17:44 - 01039554 _____ C:\Users\Nonnweiler\Desktop\adwcleaner.exe 
2013-09-19 17:43 - 2013-09-19 17:43 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner (1).exe 
2013-09-19 17:40 - 2013-09-19 17:40 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner.exe 
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Windows\erdnt 
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Qoobox 
2013-09-19 14:51 - 2013-09-19 14:51 - 05128554 ____R (Swearware) C:\Users\Nonnweiler\Desktop\ComboFix.exe 
2013-09-18 20:16 - 2013-09-18 20:16 - 00031638 _____ C:\Users\Nonnweiler\Desktop\FRST.txt 
2013-09-18 20:16 - 2013-09-18 20:16 - 00022109 _____ C:\Users\Nonnweiler\Desktop\Addition.txt 
2013-09-18 20:13 - 2013-09-18 20:13 - 00000000 ____D C:\FRST 
2013-09-18 16:10 - 2013-09-18 16:10 - 01083437 _____ (Farbar) C:\Users\Nonnweiler\Downloads\FRST.exe 
2013-09-17 15:36 - 2013-09-17 15:38 - 00000000 ____D C:\Users\Nonnweiler\.smplayer 
2013-09-17 15:36 - 2013-09-17 15:36 - 00000971 _____ C:\Users\Public\Desktop\SMPlayer.lnk 
2013-09-17 15:36 - 2013-09-17 15:36 - 00000000 ____D C:\Program Files\SMPlayer 
2013-09-16 19:28 - 2013-09-19 17:49 - 00000601 _____ C:\Users\Nonnweiler\Desktop\Search.lnk 
2013-09-16 19:28 - 2013-09-16 19:28 - 00002235 _____ C:\Users\Public\Desktop\Free WebM Video Converter.lnk 
2013-09-16 19:28 - 2013-09-16 19:28 - 00001203 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 
2013-09-16 19:28 - 2013-09-16 19:28 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\avgchrome 
2013-09-11 12:22 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 
2013-09-11 12:22 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 
2013-09-11 12:22 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 
2013-09-11 12:22 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 
2013-09-11 12:22 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 
2013-09-11 12:22 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 
2013-09-11 12:22 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 
2013-09-11 06:58 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 
2013-09-11 06:58 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 
2013-09-11 06:58 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 
2013-09-11 06:58 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 
2013-09-11 06:58 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 
2013-09-11 06:58 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 
2013-09-11 06:58 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 
2013-09-11 06:58 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 
2013-09-11 06:58 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 
2013-08-25 10:39 - 2013-08-25 10:39 - 00000000 ____D C:\Users\Nonnweiler\Desktop\Myriam Fuerte 
2013-08-24 19:57 - 2013-08-24 16:27 - 00717609 _____ C:\Users\Nonnweiler\Desktop\Intro.wmv 
2013-08-24 19:54 - 2013-08-24 19:54 - 00000000 ____D C:\Program Files\7-Zip 
2013-08-24 16:37 - 2013-08-24 16:37 - 00542167 _____ C:\Users\Nonnweiler\Documents\Intro_BETA.zip 
2013-08-24 10:44 - 2013-09-21 10:04 - 00006552 _____ C:\Windows\setupact.log 
2013-08-24 10:44 - 2013-09-19 18:46 - 00076456 _____ C:\Windows\PFRO.log 
2013-08-24 10:44 - 2013-08-24 10:44 - 00000000 _____ C:\Windows\setuperr.log 
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Malwarebytes 
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\ProgramData\Malwarebytes   
==================== One Month Modified Files and Folders =======   
2013-09-21 13:38 - 2012-08-08 19:30 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Skype 
2013-09-21 13:29 - 2013-02-16 15:59 - 00001140 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001UA.job 
2013-09-21 13:09 - 2012-09-06 18:44 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 
2013-09-21 13:07 - 2012-08-08 19:15 - 01601347 _____ C:\Windows\WindowsUpdate.log 
2013-09-21 13:05 - 2013-07-19 11:28 - 00000000 ____D C:\Program Files\Steam 
2013-09-21 12:58 - 2012-08-08 19:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 
2013-09-21 12:44 - 2012-08-08 19:58 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\LogMeIn Hamachi 
2013-09-21 12:29 - 2013-02-16 15:59 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001Core.job 
2013-09-21 12:09 - 2012-09-06 18:44 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 
2013-09-21 10:41 - 2012-10-13 10:22 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\TS3Client 
2013-09-21 10:11 - 2009-07-14 06:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
2013-09-21 10:11 - 2009-07-14 06:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
2013-09-21 10:04 - 2013-08-24 10:44 - 00006552 _____ C:\Windows\setupact.log 
2013-09-21 10:04 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 
2013-09-20 16:40 - 2012-08-08 20:15 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\.minecraft 
2013-09-20 16:14 - 2013-01-24 21:35 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\CrashDumps 
2013-09-20 10:51 - 2013-09-20 10:51 - 00005700 _____ C:\Users\Nonnweiler\Desktop\JRT.txt 
2013-09-20 10:49 - 2013-09-20 10:49 - 01029675 _____ (Thisisu) C:\Users\Nonnweiler\Desktop\JRT.exe 
2013-09-20 10:49 - 2013-09-20 10:49 - 00000000 ____D C:\Windows\ERUNT 
2013-09-19 20:50 - 2009-07-14 06:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 
2013-09-19 19:58 - 2012-08-08 19:24 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 
2013-09-19 19:58 - 2012-08-08 19:24 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 
2013-09-19 18:53 - 2013-09-19 17:44 - 00000000 ____D C:\AdwCleaner 
2013-09-19 18:46 - 2013-08-24 10:44 - 00076456 _____ C:\Windows\PFRO.log 
2013-09-19 18:11 - 2013-01-08 15:48 - 00000000 ____D C:\Users\Nonnweiler\Documents\Camtasia Studio 
2013-09-19 17:49 - 2013-09-16 19:28 - 00000601 _____ C:\Users\Nonnweiler\Desktop\Search.lnk 
2013-09-19 17:49 - 2013-07-23 20:07 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Common 
2013-09-19 17:49 - 2012-08-09 21:57 - 00000000 ____D C:\Program Files\Mozilla Firefox 
2013-09-19 17:44 - 2013-09-19 17:43 - 01039554 _____ C:\Users\Nonnweiler\Desktop\adwcleaner.exe 
2013-09-19 17:43 - 2013-09-19 17:43 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner (1).exe 
2013-09-19 17:40 - 2013-09-19 17:40 - 01039554 _____ C:\Users\Nonnweiler\Downloads\adwcleaner.exe 
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Windows\erdnt 
2013-09-19 14:56 - 2013-09-19 14:56 - 00000000 ____D C:\Qoobox 
2013-09-19 14:51 - 2013-09-19 14:51 - 05128554 ____R (Swearware) C:\Users\Nonnweiler\Desktop\ComboFix.exe 
2013-09-18 20:16 - 2013-09-18 20:16 - 00031638 _____ C:\Users\Nonnweiler\Desktop\FRST.txt 
2013-09-18 20:16 - 2013-09-18 20:16 - 00022109 _____ C:\Users\Nonnweiler\Desktop\Addition.txt 
2013-09-18 20:13 - 2013-09-18 20:13 - 00000000 ____D C:\FRST 
2013-09-18 16:10 - 2013-09-18 16:10 - 01083437 _____ (Farbar) C:\Users\Nonnweiler\Downloads\FRST.exe 
2013-09-17 15:38 - 2013-09-17 15:36 - 00000000 ____D C:\Users\Nonnweiler\.smplayer 
2013-09-17 15:36 - 2013-09-17 15:36 - 00000971 _____ C:\Users\Public\Desktop\SMPlayer.lnk 
2013-09-17 15:36 - 2013-09-17 15:36 - 00000000 ____D C:\Program Files\SMPlayer 
2013-09-17 15:36 - 2012-08-08 19:23 - 00000000 ____D C:\Users\Nonnweiler 
2013-09-16 19:28 - 2013-09-16 19:28 - 00002235 _____ C:\Users\Public\Desktop\Free WebM Video Converter.lnk 
2013-09-16 19:28 - 2013-09-16 19:28 - 00001203 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 
2013-09-16 19:28 - 2013-09-16 19:28 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\avgchrome 
2013-09-16 19:28 - 2013-05-10 17:35 - 00000000 ____D C:\Program Files\DVDVideoSoft 
2013-09-16 19:28 - 2013-05-10 17:35 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 
2013-09-16 19:28 - 2013-04-13 17:44 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\DVDVideoSoft 
2013-09-16 12:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 
2013-09-11 14:43 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 
2013-09-11 14:20 - 2012-08-08 20:09 - 00000000 ____D C:\Windows\Panther 
2013-09-11 14:19 - 2009-07-14 06:33 - 00276232 _____ C:\Windows\system32\FNTCACHE.DAT 
2013-09-11 14:17 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 
2013-09-11 06:59 - 2013-08-14 23:30 - 00000000 ____D C:\Windows\system32\MRT 
2013-09-11 06:57 - 2012-08-13 15:55 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 
2013-09-11 06:56 - 2012-08-08 19:32 - 01492188 _____ C:\Windows\system32\PerfStringBackup.INI 
2013-09-10 17:08 - 2013-04-17 15:06 - 00000000 ____D C:\Program Files\Common Files\Steam 
2013-09-04 16:32 - 2013-02-16 16:00 - 00002396 _____ C:\Users\Nonnweiler\Desktop\Google Chrome.lnk 
2013-08-31 12:21 - 2012-12-21 16:19 - 00000000 ____D C:\Users\Nonnweiler\AppData\Local\PokerStars.EU 
2013-08-28 19:48 - 2012-09-10 15:13 - 00282104 _____ C:\Windows\system32\PnkBstrB.xtr 
2013-08-28 19:48 - 2012-08-09 10:41 - 00282104 _____ C:\Windows\system32\PnkBstrB.exe 
2013-08-28 19:48 - 2012-08-09 10:41 - 00234768 _____ C:\Windows\system32\PnkBstrB.ex0 
2013-08-28 19:48 - 2012-08-09 10:41 - 00139424 _____ C:\Windows\system32\Drivers\PnkBstrK.sys 
2013-08-25 14:27 - 2012-10-13 10:22 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 
2013-08-25 10:39 - 2013-08-25 10:39 - 00000000 ____D C:\Users\Nonnweiler\Desktop\Myriam Fuerte 
2013-08-24 19:54 - 2013-08-24 19:54 - 00000000 ____D C:\Program Files\7-Zip 
2013-08-24 16:37 - 2013-08-24 16:37 - 00542167 _____ C:\Users\Nonnweiler\Documents\Intro_BETA.zip 
2013-08-24 16:27 - 2013-08-24 19:57 - 00717609 _____ C:\Users\Nonnweiler\Desktop\Intro.wmv 
2013-08-24 10:44 - 2013-08-24 10:44 - 00000000 _____ C:\Windows\setuperr.log 
2013-08-24 10:44 - 2013-05-05 11:19 - 00000000 ____D C:\Users\Nonnweiler\Documents\DCSCMIN 
2013-08-24 10:44 - 2012-09-25 16:17 - 00000000 ___HD C:\Windows\msdownld.tmp 
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\Users\Nonnweiler\AppData\Roaming\Malwarebytes 
2013-08-24 10:31 - 2013-08-24 10:31 - 00000000 ____D C:\ProgramData\Malwarebytes 
2013-08-23 16:10 - 2012-10-13 15:45 - 00006656 _____ C:\Users\Nonnweiler\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini   
Some content of TEMP: 
==================== 
C:\Users\Nonnweiler\AppData\Local\Temp\Quarantine.exe 
C:\Users\Nonnweiler\AppData\Local\Temp\SkypeSetup.exe 
C:\Users\Nonnweiler\AppData\Local\Temp\uninst1.exe     
==================== Bamital & volsnap Check =================   
C:\Windows\explorer.exe => MD5 is legit 
C:\Windows\System32\winlogon.exe => MD5 is legit 
C:\Windows\System32\wininit.exe => MD5 is legit 
C:\Windows\System32\svchost.exe => MD5 is legit 
C:\Windows\System32\services.exe => MD5 is legit 
C:\Windows\System32\User32.dll => MD5 is legit 
C:\Windows\System32\userinit.exe => MD5 is legit 
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit     
LastRegBack: 2013-09-16 12:06   
==================== End Of Log ============================   --- --- ---  
--- --- ---   
Addition.txt   Code:  
 Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-09-2013 03 
Ran by Nonnweiler at 2013-09-21 13:40:13 
Running from C:\Users\Nonnweiler\Downloads 
Boot Mode: Normal 
==========================================================     
==================== Installed Programs =======================   
7-Zip 9.22beta 
Adobe Flash Player 11 ActiveX (Version: 11.8.800.175) 
Adobe Shockwave Player 11.6 (Version: 11.6.8.638) 
AMD Accelerated Video Transcoding (Version: 12.5.100.21219) 
AMD APP SDK Runtime (Version: 10.0.1084.4) 
AMD Catalyst Install Manager (Version: 8.0.903.0) 
AMD Drag and Drop Transcoding (Version: 2.00.0000) 
AMD Fuel (Version: 2012.1219.1521.27485) 
AMD Media Foundation Decoders (Version: 1.0.71219.1540) 
AMD VISION Engine Control Center (Version: 2012.1219.1521.27485) 
Apple Software Update (Version: 2.1.3.127) 
AquaSoft DiaShow 8 Ultimate (Version: 8.0.19) 
Battlefield Heroes 
Battlefield Play4Free 
Call of Duty: Black Ops II 
Call of Duty: Black Ops II - Multiplayer 
Call of Duty: Black Ops II - Zombies 
Camtasia Studio 7 (Version: 7.0.1) 
Catalyst Control Center - Branding (Version: 1.00.0000) 
Catalyst Control Center Graphics Previews Common (Version: 2012.1219.1521.27485) 
Catalyst Control Center InstallProxy (Version: 2012.1219.1521.27485) 
Catalyst Control Center Localization All (Version: 2012.1219.1521.27485) 
CCC Help Chinese Standard (Version: 2012.1219.1520.27485) 
CCC Help Chinese Traditional (Version: 2012.1219.1520.27485) 
CCC Help Czech (Version: 2012.1219.1520.27485) 
CCC Help Danish (Version: 2012.1219.1520.27485) 
CCC Help Dutch (Version: 2012.1219.1520.27485) 
CCC Help English (Version: 2012.1219.1520.27485) 
CCC Help Finnish (Version: 2012.1219.1520.27485) 
CCC Help French (Version: 2012.1219.1520.27485) 
CCC Help German (Version: 2012.1219.1520.27485) 
CCC Help Greek (Version: 2012.1219.1520.27485) 
CCC Help Hungarian (Version: 2012.1219.1520.27485) 
CCC Help Italian (Version: 2012.1219.1520.27485) 
CCC Help Japanese (Version: 2012.1219.1520.27485) 
CCC Help Korean (Version: 2012.1219.1520.27485) 
CCC Help Norwegian (Version: 2012.1219.1520.27485) 
CCC Help Polish (Version: 2012.1219.1520.27485) 
CCC Help Portuguese (Version: 2012.1219.1520.27485) 
CCC Help Russian (Version: 2012.1219.1520.27485) 
CCC Help Spanish (Version: 2012.1219.1520.27485) 
CCC Help Swedish (Version: 2012.1219.1520.27485) 
CCC Help Thai (Version: 2012.1219.1520.27485) 
CCC Help Turkish (Version: 2012.1219.1520.27485) 
ccc-utility (Version: 2012.1219.1521.27485) 
CCleaner (Version: 4.02) 
Chatango Message Catcher 
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB945282) (Version: 1) 
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB946040) (Version: 1) 
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB946308) (Version: 1) 
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB947540) (Version: 1) 
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB947789) (Version: 1) 
Correctif pour Microsoft Visual*C++ 2008 Express*SP1 -*Français (KB948127) (Version: 1) 
Free Pdf Perfect Prereq (Version: 1.0.0.28) 
Free WebM Video Converter version 5.0.28.827 (Version: 5.0.28.827) 
Free YouTube to MP3 Converter version 3.12.2.430 (Version: 3.12.2.430) 
Google Chrome (HKCU Version: 29.0.1547.66) 
Google Earth (Version: 6.2.2.6613) 
Google Toolbar for Internet Explorer (Version: 1.0.0) 
Google Toolbar for Internet Explorer (Version: 7.5.4413.1752) 
Java 7 Update 25 (Version: 7.0.250) 
Java Auto Updater (Version: 2.1.9.5) 
League of Legends (Version: 3.0.1) 
LogMeIn Hamachi (Version: 2.1.0.374) 
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) 
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) 
Microsoft Download Manager (Version: 1.2.1) 
Microsoft SQL Server 2008 Management Objects (Version: 10.0.1600.22) 
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) 
Microsoft Visual C++ 2008 Express Edition with SP1 - FRA (Version: 9.0.30729) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) 
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219) 
Microsoft Visual*C++ 2008 Express*SP1 -*Français 
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries (Version: 6.1.5288.17011) 
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - fra (Version: 3.5.30729) 
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 (Version: 6.1.5295.17011) 
Notepad++ (Version: 6.4.1) 
PokerStars.eu 
PunkBuster Services (Version: 0.990) 
Realtek High Definition Audio Driver (Version: 6.0.1.6531) 
Skype™ 6.5 (Version: 6.5.158) 
SMPlayer 0.8.6.0 (Version: 0.8.6.0) 
Steam (Version: 1.0.0.0) 
swMSM (Version: 12.0.0.1) 
Synthesia (Version: 8.5) 
TeamSpeak 3 Client (Version: 3.0.11.1) 
TeamViewer 8 (Version: 8.0.16642) 
TmNationsForever 
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) 
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) 
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) 
Vandal 1.0.0.0 (D) (Version: 1.0.0.0) 
WinRAR 4.20 (32-Bit) (Version: 4.20.0) 
XMedia Recode Version 3.1.6.4 (Version: 3.1.6.4)   
==================== Restore Points  =========================     
==================== Hosts content: ==========================   
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts   
==================== Scheduled Tasks (whitelisted) =============   
Task: {048A0864-9BD7-493C-8584-139B930D0552} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-06] (Google Inc.) 
Task: {0B91A6E5-7AAB-45BD-B7FB-548F7DC97098} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) 
Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started 
Task: {23DE43AB-7704-4781-84DB-E51457BC4891} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-19] (Adobe Systems Incorporated) 
Task: {2B5E14E7-2A76-44BD-9A79-ED24E38B5127} - System32\Tasks\Driver Mender-RTMScan => C:\Program Files\Driver Mender\Driver Mender\DriverMender.exe 
Task: {4865A1AB-A055-43BD-96C3-D57A3E64F56A} - System32\Tasks\0 => Iexplore.exe  
Task: {49D40FD1-25BE-4707-BC27-46AE3BBC61D4} - System32\Tasks\Driver Mender-RTMRules => C:\Program Files\Driver Mender\Driver Mender\DriverMender.exe 
Task: {5083C5A2-BC7B-4CF8-8DC2-0A0FD4FC0591} - System32\Tasks\Express FilesUpdate => C:\Program Files\ExpressFiles\EFUpdater.exe 
Task: {55A01FB3-8B55-4B04-BEC7-DA2661171F4C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001UA => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.) 
Task: {C66473A0-4FEE-45EF-833F-2CA72CF16AE8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001Core => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-16] (Google Inc.) 
Task: {CCA536D0-7C0B-496C-B9FC-12F2E80C6126} - System32\Tasks\Driver Mender-RTMUpdater => C:\Program Files\Driver Mender\Driver Mender\DriverMender.exe 
Task: {D328BA38-D008-4F12-A205-A61661B095F2} - System32\Tasks\4825 => C:\Windows\System32\wscript.exe [2009-07-14] (Microsoft Corporation) 
Task: {D4636923-0553-4240-AA48-38AC8545B4C7} - System32\Tasks\BitGuard => Sc.exe start BitGuard 
Task: {E02FE3D8-A22D-412C-BCE4-8AD4BCE9A8C0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd) 
Task: {E559DA5A-2750-44B3-B4F5-8690BEE8A443} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) 
Task: {F42844C5-9F33-49D5-8D7A-A650F9B25F19} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-06] (Google Inc.) 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001Core.job => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2906294217-3088318799-3869448690-1001UA.job => C:\Users\Nonnweiler\AppData\Local\Google\Update\GoogleUpdate.exe   
==================== Loaded Modules (whitelisted) =============   
2013-06-03 16:21 - 2013-06-03 16:21 - 00088680 ____R (Skype Technologies) C:\Program Files\Skype\Updater\Updater.dll 
2013-09-19 19:58 - 2013-09-19 19:58 - 16244616 ____R (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\Flash32_11_8_800_175.ocx 
2013-07-01 08:20 - 2013-08-22 00:18 - 00687104 _____ () C:\Program Files\Steam\SDL2.dll 
2013-07-09 17:56 - 2013-09-06 22:55 - 01120680 _____ () C:\Program Files\Steam\bin\chromehtml.DLL 
2013-07-09 13:45 - 2013-08-07 21:31 - 20625832 _____ () C:\Program Files\Steam\bin\libcef.dll 
2013-06-14 15:49 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files\Steam\bin\avcodec-53.dll 
2013-06-14 15:49 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files\Steam\bin\avutil-51.dll 
2013-06-14 15:49 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files\Steam\bin\avformat-53.dll 
2012-12-19 17:31 - 2012-12-19 17:31 - 00095232 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 
2012-07-30 16:13 - 2013-08-25 14:27 - 00230376 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win32.dll 
2012-07-30 16:13 - 2013-08-25 14:27 - 00237032 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win32.dll 
2012-07-30 16:13 - 2013-08-25 14:27 - 00159208 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\appscanner_plugin.dll 
2012-07-30 16:13 - 2013-08-25 14:27 - 00431080 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 
2012-08-10 11:18 - 2010-11-20 14:21 - 01202176 _____ (Microsoft Corporation) C:\Windows\System32\Speech\Common\sapi.dll 
2013-09-19 19:58 - 2013-09-19 19:58 - 00479112 _____ (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.dll   
==================== Alternate Data Streams (whitelisted) ==========     
==================== Faulty Device Manager Devices =============     
==================== Event log errors: =========================   
Application errors: 
================== 
Error: (09/20/2013 04:14:52 PM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.11.0.317, Zeitstempel: 0x522fdc68 
Name des fehlerhaften Moduls: cgD3D9.dll, Version: 3.0.0.16, Zeitstempel: 0x4d55a06f 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x000b6539 
ID des fehlerhaften Prozesses: 0xd4c 
Startzeit der fehlerhaften Anwendung: 0xLeague of Legends.exe0 
Pfad der fehlerhaften Anwendung: League of Legends.exe1 
Pfad des fehlerhaften Moduls: League of Legends.exe2 
Berichtskennung: League of Legends.exe3   
Error: (09/20/2013 04:14:05 PM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: League of Legends.exe, Version: 3.11.0.317, Zeitstempel: 0x522fdc68 
Name des fehlerhaften Moduls: cgD3D9.dll, Version: 3.0.0.16, Zeitstempel: 0x4d55a06f 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x000b6539 
ID des fehlerhaften Prozesses: 0x814 
Startzeit der fehlerhaften Anwendung: 0xLeague of Legends.exe0 
Pfad der fehlerhaften Anwendung: League of Legends.exe1 
Pfad des fehlerhaften Moduls: League of Legends.exe2 
Berichtskennung: League of Legends.exe3   
Error: (09/20/2013 03:10:55 PM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: t6zm.exe, Version: 1.0.0.1, Zeitstempel: 0x52129451 
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x0012ec08 
ID des fehlerhaften Prozesses: 0x1d04 
Startzeit der fehlerhaften Anwendung: 0xt6zm.exe0 
Pfad der fehlerhaften Anwendung: t6zm.exe1 
Pfad des fehlerhaften Moduls: t6zm.exe2 
Berichtskennung: t6zm.exe3   
Error: (09/20/2013 03:07:01 PM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: t6zm.exe, Version: 1.0.0.1, Zeitstempel: 0x52129451 
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x0012ed58 
ID des fehlerhaften Prozesses: 0x1514 
Startzeit der fehlerhaften Anwendung: 0xt6zm.exe0 
Pfad der fehlerhaften Anwendung: t6zm.exe1 
Pfad des fehlerhaften Moduls: t6zm.exe2 
Berichtskennung: t6zm.exe3   
Error: (09/20/2013 03:05:57 PM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: t6zm.exe, Version: 1.0.0.1, Zeitstempel: 0x52129451 
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x0012ec08 
ID des fehlerhaften Prozesses: 0x2498 
Startzeit der fehlerhaften Anwendung: 0xt6zm.exe0 
Pfad der fehlerhaften Anwendung: t6zm.exe1 
Pfad des fehlerhaften Moduls: t6zm.exe2 
Berichtskennung: t6zm.exe3   
Error: (09/20/2013 11:47:56 AM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: t6mp.exe, Version: 1.0.0.1, Zeitstempel: 0x52103871 
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x0012edb0 
ID des fehlerhaften Prozesses: 0x758 
Startzeit der fehlerhaften Anwendung: 0xt6mp.exe0 
Pfad der fehlerhaften Anwendung: t6mp.exe1 
Pfad des fehlerhaften Moduls: t6mp.exe2 
Berichtskennung: t6mp.exe3   
Error: (09/20/2013 11:47:01 AM) (Source: Application Error) (User: ) 
Description: Name der fehlerhaften Anwendung: t6mp.exe, Version: 1.0.0.1, Zeitstempel: 0x52103871 
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 
Ausnahmecode: 0xc0000005 
Fehleroffset: 0x0012ed10 
ID des fehlerhaften Prozesses: 0x18d8 
Startzeit der fehlerhaften Anwendung: 0xt6mp.exe0 
Pfad der fehlerhaften Anwendung: t6mp.exe1 
Pfad des fehlerhaften Moduls: t6mp.exe2 
Berichtskennung: t6mp.exe3   
Error: (09/20/2013 11:10:31 AM) (Source: Application Hang) (User: ) 
Description: Programm iexplore.exe, Version 10.0.9200.16686 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.   
Prozess-ID: 14e0   
Startzeit: 01ceb5e05d3646d8   
Endzeit: 16   
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe   
Berichts-ID:   
Error: (09/20/2013 11:10:21 AM) (Source: RasClient) (User: ) 
Description: CoID={67A94FFD-A158-4A13-951C-390D4B415AD6}: Der Benutzer "Der0815\Nonnweiler" hat eine Verbindung mit dem Namen "Breitbandverbindung" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 0.     
System errors: 
============= 
Error: (09/21/2013 01:40:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:39:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:38:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:37:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:36:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:35:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:34:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:33:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:32:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2   
Error: (09/21/2013 01:31:00 PM) (Source: Service Control Manager) (User: ) 
Description: Der Dienst "BitGuard" wurde aufgrund folgenden Fehlers nicht gestartet:  
%%2     
Microsoft Office Sessions: 
========================= 
Error: (09/20/2013 04:14:52 PM) (Source: Application Error)(User: ) 
Description: League of Legends.exe3.11.0.317522fdc68cgD3D9.dll3.0.0.164d55a06fc0000005000b6539d4c01ceb60bb0500608C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\League of Legends.exeC:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\cgD3D9.dll0393d178-21ff-11e3-970d-7071bcb83c56   
Error: (09/20/2013 04:14:05 PM) (Source: Application Error)(User: ) 
Description: League of Legends.exe3.11.0.317522fdc68cgD3D9.dll3.0.0.164d55a06fc0000005000b653981401ceb60b7cb1e988C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\League of Legends.exeC:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.247\deploy\cgD3D9.dlle7e024b8-21fe-11e3-970d-7071bcb83c56   
Error: (09/20/2013 03:10:55 PM) (Source: Application Error)(User: ) 
Description: t6zm.exe1.0.0.152129451unknown0.0.0.000000000c00000050012ec081d0401ceb602503d4ab8C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exeunknown14b49428-21f6-11e3-970d-7071bcb83c56   
Error: (09/20/2013 03:07:01 PM) (Source: Application Error)(User: ) 
Description: t6zm.exe1.0.0.152129451unknown0.0.0.000000000c00000050012ed58151401ceb60246e3cc58C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exeunknown890dd8a8-21f5-11e3-970d-7071bcb83c56   
Error: (09/20/2013 03:05:57 PM) (Source: Application Error)(User: ) 
Description: t6zm.exe1.0.0.152129451unknown0.0.0.000000000c00000050012ec08249801ceb601e4ff86a8C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exeunknown63468548-21f5-11e3-970d-7071bcb83c56   
Error: (09/20/2013 11:47:56 AM) (Source: Application Error)(User: ) 
Description: t6mp.exe1.0.0.152103871unknown0.0.0.000000000c00000050012edb075801ceb5e6681ebae8C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exeunknownb95a8158-21d9-11e3-970d-7071bcb83c56   
Error: (09/20/2013 11:47:01 AM) (Source: Application Error)(User: ) 
Description: t6mp.exe1.0.0.152103871unknown0.0.0.000000000c00000050012ed1018d801ceb5e4fe1e4e48C:\Program Files\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exeunknown98c39c18-21d9-11e3-970d-7071bcb83c56   
Error: (09/20/2013 11:10:31 AM) (Source: Application Hang)(User: ) 
Description: iexplore.exe10.0.9200.1668614e001ceb5e05d3646d816C:\Program Files\Internet Explorer\iexplore.exe   
Error: (09/20/2013 11:10:21 AM) (Source: RasClient)(User: ) 
Description: {67A94FFD-A158-4A13-951C-390D4B415AD6}Der0815\NonnweilerBreitbandverbindung0     
==================== Memory info ===========================    
Percentage of memory in use: 37% 
Total physical RAM: 3583.3 MB 
Available physical RAM: 2224.13 MB 
Total Pagefile: 7164.9 MB 
Available Pagefile: 5522.29 MB 
Total Virtual: 2047.88 MB 
Available Virtual: 1891.85 MB   
==================== Drives ================================   
Drive c: (OS) (Fixed) (Total:97.66 GB) (Free:19.92 GB) NTFS ==>[System with boot components (obtained from reading drive)] 
Drive d: () (Fixed) (Total:820.15 GB) (Free:817.08 GB) NTFS 
Drive e: (HP_RECOVERY) (Fixed) (Total:13.6 GB) (Free:1.64 GB) NTFS ==>[System with boot components (obtained from reading drive)]   
==================== MBR & Partition Table ==================   
======================================================== 
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: B99DD3BF) 
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) 
Partition 2: (Not Active) - (Size=98 GB) - (Type=07 NTFS) 
Partition 3: (Not Active) - (Size=820 GB) - (Type=OF Extended) 
Partition 4: (Not Active) - (Size=14 GB) - (Type=07 NTFS)   
==================== End Of Log ============================      |