|
Log-Analyse und Auswertung: Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PCWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
31.07.2013, 13:13 | #1 |
| Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC Hallo, Wie der Titel des Themas schon sagt, erkennt jeder Virenschutz bei Normalen Programmen wie zum Beispiel Fraps oder S4 League (ein Spiel) als Virus . Ich habe schon fasst alle Virenscanner durchgenommen (die ich kenne) dazu gehören : Avast, Avira, AVG, BitDefender, Adware. Hier ein Zusammengestellter Screen von Avira : Wie ihr dort schon sieht ist es sehr unnormal (meiner Meinung nach). Da ich mich nicht so gut mit sowas auskenne frag ich euch. Ich habe das Windows Tool gegen Malware durchlaufen lassen hat 3000 sachen gefunden (auch alles nur normale Programme für den Altag) Ich habe das schon seit ca. 2-5 Tagen. Ich wollte meinen PC Wiederherstellen aber da ich in der Zeit nichts instaliert habe oder Windows Updates gemacht habe hilft mir das auch sehr Wening Falls ihr das Problem kenn u.o. was dazu wisst, meldet euch bitte Ihr könnt mich auch auf Skype Adden : ihumanx Geändert von Kipsell (31.07.2013 um 13:26 Uhr) |
31.07.2013, 13:54 | #2 |
/// the machine /// TB-Ausbilder | Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
31.07.2013, 16:25 | #3 | |
| Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PCZitat:
Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-07-2013 03 Ran by Bastian at 2013-07-31 15:32:29 Running from C:\Users\Bastian\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= µTorrent (HKCU Version: 3.3.1.29812) Adobe AIR (x32 Version: 3.7.0.2090) Adobe Creative Cloud (x32 Version: 2.0.2.189) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Reader 9.1 MUI (x32 Version: 9.1.0) Advertising Center (x32 Version: 0.0.0.2) Agatha Christie - Death on the Nile (x32 Version: 2.2.0.95) Akamai NetSession Interface (HKCU) Apple Application Support (x32 Version: 2.3.4) Apple Software Update (x32 Version: 2.1.3.127) AutoIt v3.3.8.0 (x32) Avira Free Antivirus (x32 Version: 13.0.0.3884) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95) Build-a-lot 2 (x32 Version: 2.2.0.95) Camtasia Studio 8 (x32 Version: 8.0.4.1060) Cheat Engine 6.3 (x32) Chuzzle Deluxe (x32 Version: 2.2.0.95) CryOnline (x32) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95) eMachines Game Console (x32) eMachines Games (x32 Version: 1.0.1.3) eMachines Recovery Management (x32 Version: 4.05.3013) eMachines Registration (x32 Version: 1.03.3003) eMachines ScreenSaver (x32 Version: 1.1.0825.2010) eMachines Updater (x32 Version: 1.02.3001) erLT (x32 Version: 1.20.0137) Farm Frenzy (x32 Version: 2.2.0.95) FATE (x32 Version: 2.2.0.95) Final Drive Nitro (x32 Version: 2.2.0.95) Forsaken World (x32) Free Studio version 2013 (x32 Version: 6.1.3.622) Free YouTube Download version 3.2.2.430 (x32 Version: 3.2.2.430) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.153) Hotkey Utility (x32 Version: 2.05.3009) IconPackager (x32 Version: 5.10) Identity Card (x32 Version: 1.00.3003) ImagXpress (x32 Version: 7.0.74.0) Insaniquarium Deluxe (x32 Version: 2.2.0.95) itech Gaming Software 8.46 (Version: 8.46.27) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95) John Deere Drive Green (x32 Version: 2.2.0.95) Junk Mail filter update (x32 Version: 14.0.8117.416) Logitech Gaming Software (Version: 8.45.88) Logitech SetPoint 5.20 (Version: 5.20) Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000) Microsoft Choice Guard (x32 Version: 2.0.48.0) Microsoft Help Viewer 1.0 (Version: 1.0.30319) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft SQL Server 2008 R2 Management Objects (x32 Version: 10.50.1447.4) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1447.4) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.30319) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (x32 Version: 10.0.30319) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (Version: 10.0.30319) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) MSVCRT (x32 Version: 14.0.1468.721) MSVCRT Redists (Version: 1.0) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Need for Speed™ Undercover (x32 Version: 1.0.1.0) Nero ControlCenter (x32 Version: 9.0.0.1) Nero DiscSpeed (x32 Version: 5.4.13.100) Nero DiscSpeed Help (x32 Version: 5.4.4.100) Nero DriveSpeed (x32 Version: 4.4.12.100) Nero DriveSpeed Help (x32 Version: 4.4.4.100) Nero Express Help (x32 Version: 9.4.37.100) Nero InfoTool (x32 Version: 6.4.12.100) Nero InfoTool Help (x32 Version: 6.4.4.100) Nero Installer (x32 Version: 4.4.9.0) Nero Online Upgrade (x32 Version: 1.3.0.0) Nero StartSmart (x32 Version: 9.4.37.100) Nero StartSmart Help (x32 Version: 9.4.27.100) Nero StartSmart OEM (x32 Version: 9.15.0.100) NeroExpress (x32 Version: 9.4.37.100) neroxml (x32 Version: 1.0.0) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Display Control Panel (Version: 6.14.11.9793) NVIDIA Drivers (Version: 1.10.61.39) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA PhysX (x32 Version: 9.10.0223) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Pando Media Booster (x32 Version: 2.6.0.9) Penguins! (x32 Version: 2.2.0.95) Plants vs. Zombies (x32 Version: 2.2.0.95) Polar Bowler (x32 Version: 2.2.0.95) Polar Golfer (x32 Version: 2.2.0.95) QuickTime (x32 Version: 7.74.80.86) Rainmeter (x32 Version: 2.5 r1842) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6101) Resource Hacker Version 3.6.0 (x32) RocketDock 1.3.5 (x32) S4 League_EU (x32 Version: 1.00.0000) SciTE4AutoIt3 4/5/2013 (x32 Version: 4/5/2013) Skype™ 6.6 (x32 Version: 6.6.106) Steam (x32 Version: 1.0.0.0) Team Fortress 2 (x32) TeamSpeak 3 Client (HKCU Version: 3.0.10) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) User's Guides (Version: 1.20.0000) Vegas Pro 12.0 (64-bit) (Version: 12.0.563) Vegas Pro 9.0 (64-bit) (Version: 9.0.1146) Vegas Pro 9.0 (x32 Version: 9.0.1147) Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95) VirtualDJ Home FREE (x32 Version: 7.4) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (x32 Version: 4.0.8080.0) Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1) Welcome Center (x32 Version: 1.02.3004) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5) Windows Live Call (x32 Version: 14.0.8117.0416) Windows Live Communications Platform (x32 Version: 14.0.8117.416) Windows Live Essentials (x32 Version: 14.0.8117.0416) Windows Live Essentials (x32 Version: 14.0.8117.416) Windows Live Fotogalerie (x32 Version: 14.0.8117.416) Windows Live Mail (x32 Version: 14.0.8117.0416) Windows Live Messenger (x32 Version: 14.0.8117.0416) Windows Live Movie Maker (x32 Version: 14.0.8117.0416) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live Writer (x32 Version: 14.0.8117.0416) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinRAR 4.20 (64-Bit) (Version: 4.20.0) Zuma Deluxe (x32 Version: 2.2.0.95) Zuma's Revenge (x32 Version: 2.2.0.95) ==================== Restore Points ========================= 30-07-2013 20:36:14 avast! Free Antivirus Setup 30-07-2013 21:50:03 avast! Free Antivirus Setup 30-07-2013 23:21:28 Windows Update 31-07-2013 09:14:04 Removed QuickTime 31-07-2013 09:17:27 Removed UxStyle Core Beta 31-07-2013 09:34:54 Removed UxStyle Core Beta 31-07-2013 11:36:03 Removed GeekBuddy. 31-07-2013 11:40:46 Removed Vegas Pro 12.0 (64-bit) ==================== Hosts content: ========================== 2013-06-22 21:28 - 2013-07-31 11:03 - 00000865 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 activation.cloud.techsmith.com ==================== Scheduled Tasks (whitelisted) ============= Task: {6DFB10E6-1377-45EE-A4A8-09E8EDCEBD79} - System32\Tasks\{FD1DB7EA-AD9C-4764-9F65-181E3E4227AF} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-06-26] (Mozilla Corporation) Task: {6E6B50D7-C0CD-40DA-A767-7C4EF4906268} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-31] (Google Inc.) Task: {8EFEF4DE-A7A3-42F4-B8B9-A6B7EDA464C2} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe No File Task: {8FF948BC-E3F7-4BB0-B042-7B979FABA6EB} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {9C446AF0-CC57-46D8-9540-B55BD9956115} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-31] (Google Inc.) Task: {B6AB2232-9833-458D-A54C-03FBADEA2030} - System32\Tasks\AdobeAAMUpdater-1.0-Bastian-PC-Bastian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {E2D74963-3673-4711-A97F-2FBA2D6F1E73} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15] (Adobe Systems Incorporated) Task: {F991D4CE-E38F-441C-8A8D-9ADC8E540039} - System32\Tasks\{BD6A8DB5-4829-4F45-BD7A-90D6B63A7664} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-06-26] (Mozilla Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (07/31/2013 02:48:09 PM) (Source: .NET Runtime Optimization Service) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\bin\NETFX 4.0 Tools\ResGen.exe . Error code = 0x80131f07 Error: (07/31/2013 02:48:09 PM) (Source: .NET Runtime Optimization Service) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\bin\NETFX 4.0 Tools\ResGen.exe . Error code = 0x80131f07 Error: (07/31/2013 01:51:28 PM) (Source: Application Hang) (User: ) Description: Programm S4Client.exe, Version 0.8.32.3483 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a14 Startzeit: 01ce8de3ac2e5f95 Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\alaplaya\S4League\S4Client.exe Berichts-ID: 39ea3a98-f9d7-11e2-9a71-4487fcfa9642 Error: (07/31/2013 01:50:35 PM) (Source: Application Hang) (User: ) Description: Programm avscan.exe, Version 13.6.0.1722 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 3d0 Startzeit: 01ce8de3864c1863 Endzeit: 60000 Anwendungspfad: C:\program files (x86)\avira\antivir desktop\avscan.exe Berichts-ID: 2fe9a85a-f9d7-11e2-9a71-4487fcfa9642 Error: (07/31/2013 01:41:10 PM) (Source: MsiInstaller) (User: Bastian-PC) Description: Produkt: Vegas Pro 12.0 (64-bit) -- Fehler 1723. Es liegt ein dieses Windows Installer-Paket betreffendes Problem vor. Eine für den Abschluss der Installation erforderliche DLL konnte nicht ausgeführt werden. Wenden Sie sich an das Supportpersonal oder den Hersteller des Pakets. Aktion: SfMSILib_IsProcessRunning, Eintrag: SfMSILib_IsProcessRunning, Bibliothek: C:\ProgramData\Sony\customaction_x64.dll Error: (07/31/2013 11:17:50 AM) (Source: MsiInstaller) (User: Bastian-PC) Description: Product: UxStyle Core Beta -- Your theme subsystem (e.g. uxtheme.dll, themeui.dll) has been tampered with. UxStyle requires these files be restored before you can continue. Check the forums if you need help. Error: (07/30/2013 11:43:45 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: RocketDock.exe, Version: 0.0.0.0, Zeitstempel: 0x46db07ea Name des fehlerhaften Moduls: StackDocklet.dll, Version: 1.0.0.134, Zeitstempel: 0x2a425e19 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004dce6 ID des fehlerhaften Prozesses: 0x146c Startzeit der fehlerhaften Anwendung: 0xRocketDock.exe0 Pfad der fehlerhaften Anwendung: RocketDock.exe1 Pfad des fehlerhaften Moduls: RocketDock.exe2 Berichtskennung: RocketDock.exe3 Error: (07/30/2013 04:53:13 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec4aa8e Ausnahmecode: 0xc0000374 Fehleroffset: 0x00000000000c40f2 ID des fehlerhaften Prozesses: 0x54c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (07/30/2013 11:47:41 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CamtasiaStudio.exe, Version: 8.0.4.1060, Zeitstempel: 0x50c57c2f Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000374 Fehleroffset: 0x000ce6c3 ID des fehlerhaften Prozesses: 0x12bc Startzeit der fehlerhaften Anwendung: 0xCamtasiaStudio.exe0 Pfad der fehlerhaften Anwendung: CamtasiaStudio.exe1 Pfad des fehlerhaften Moduls: CamtasiaStudio.exe2 Berichtskennung: CamtasiaStudio.exe3 Error: (07/30/2013 10:53:24 AM) (Source: Application Hang) (User: ) Description: Programm CamtasiaStudio.exe, Version 8.0.4.1060 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1178 Startzeit: 01ce8d0201499943 Endzeit: 58 Anwendungspfad: C:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe Berichts-ID: 73a6cb56-f8f5-11e2-9a71-4487fcfa9642 System errors: ============= Error: (07/31/2013 03:25:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "VMware USB Arbitration Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/31/2013 02:04:15 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/31/2013 02:04:13 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/31/2013 01:43:13 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/31/2013 01:43:11 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/31/2013 01:37:38 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/31/2013 01:37:36 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0. Error: (07/31/2013 01:33:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "VMware USB Arbitration Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/31/2013 01:31:57 PM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "DeleteFlag" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (07/31/2013 01:31:45 PM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Microsoft Office Sessions: ========================= Error: (07/31/2013 02:48:09 PM) (Source: .NET Runtime Optimization Service)(User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\bin\NETFX 4.0 Tools\ResGen.exe . Error code = 0x80131f07 C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\bin\NETFX 4.0 Tools\ResGen.exe Error: (07/31/2013 02:48:09 PM) (Source: .NET Runtime Optimization Service)(User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\bin\NETFX 4.0 Tools\ResGen.exe . Error code = 0x80131f07 C:\Program Files (x86)\Microsoft SDKs\Windows\v7.0A\bin\NETFX 4.0 Tools\ResGen.exe Error: (07/31/2013 01:51:28 PM) (Source: Application Hang)(User: ) Description: S4Client.exe0.8.32.3483a1401ce8de3ac2e5f950C:\Program Files (x86)\alaplaya\S4League\S4Client.exe39ea3a98-f9d7-11e2-9a71-4487fcfa9642 Error: (07/31/2013 01:50:35 PM) (Source: Application Hang)(User: ) Description: avscan.exe13.6.0.17223d001ce8de3864c186360000C:\program files (x86)\avira\antivir desktop\avscan.exe2fe9a85a-f9d7-11e2-9a71-4487fcfa9642 Error: (07/31/2013 01:41:10 PM) (Source: MsiInstaller)(User: Bastian-PC) Description: Produkt: Vegas Pro 12.0 (64-bit) -- Fehler 1723. Es liegt ein dieses Windows Installer-Paket betreffendes Problem vor. Eine für den Abschluss der Installation erforderliche DLL konnte nicht ausgeführt werden. Wenden Sie sich an das Supportpersonal oder den Hersteller des Pakets. Aktion: SfMSILib_IsProcessRunning, Eintrag: SfMSILib_IsProcessRunning, Bibliothek: C:\ProgramData\Sony\customaction_x64.dll (NULL)(NULL)(NULL)(NULL)(NULL) Error: (07/31/2013 11:17:50 AM) (Source: MsiInstaller)(User: Bastian-PC) Description: Product: UxStyle Core Beta -- Your theme subsystem (e.g. uxtheme.dll, themeui.dll) has been tampered with. UxStyle requires these files be restored before you can continue. Check the forums if you need help.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (07/30/2013 11:43:45 PM) (Source: Application Error)(User: ) Description: RocketDock.exe0.0.0.046db07eaStackDocklet.dll1.0.0.1342a425e19c00000050004dce6146c01ce8d6ca9600198C:\Program Files (x86)\RocketDock\RocketDock.exeC:\Program Files (x86)\RocketDock\Docklets\StackDocklet\StackDocklet.dll1b7f2550-f961-11e2-9a55-4487fcfa9642 Error: (07/30/2013 04:53:13 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ntdll.dll6.1.7601.177254ec4aa8ec000037400000000000c40f254c01ce8d13cba5dbbaC:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dllc1db4602-f927-11e2-9ed6-4487fcfa9642 Error: (07/30/2013 11:47:41 AM) (Source: Application Error)(User: ) Description: CamtasiaStudio.exe8.0.4.106050c57c2fntdll.dll6.1.7601.177254ec49b8fc0000374000ce6c312bc01ce8d04610fc7faC:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exeC:\Windows\SysWOW64\ntdll.dll131569e7-f8fd-11e2-9a71-4487fcfa9642 Error: (07/30/2013 10:53:24 AM) (Source: Application Hang)(User: ) Description: CamtasiaStudio.exe8.0.4.1060117801ce8d020149994358C:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe73a6cb56-f8f5-11e2-9a71-4487fcfa9642 ==================== Memory info =========================== Percentage of memory in use: 70% Total physical RAM: 3071.24 MB Available physical RAM: 895.42 MB Total Pagefile: 6140.67 MB Available Pagefile: 3412.56 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (eMachines) (Fixed) (Total:453.66 GB) (Free:335.51 GB) NTFS (Disk=0 Partition=3) Drive d: (GamePanel) (CDROM) (Total:0.24 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 572EBBD4) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=454 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-07-2013 03 Ran by Bastian (administrator) on 31-07-2013 15:31:03 Running from C:\Users\Bastian\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Acer Incorporated) C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Acer Group) C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Akamai Technologies, Inc.) C:\Users\Bastian\AppData\Local\Akamai\netsession_win.exe () C:\Program Files (x86)\RocketDock\RocketDock.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe () C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Akamai Technologies, Inc.) C:\Users\Bastian\AppData\Local\Akamai\netsession_win.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech Inc.) C:\Program Files\Logitech\SetPoint II\SetPointII.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10806816 2010-04-30] (Realtek Semiconductor) HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION! HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Bastian\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [RocketDock] - C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION MountPoints2: {759a19df-c5eb-11e2-8a54-806e6f6e6963} - D:\Setup\setup.exe HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Hotkey Utility] - C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe [611872 2010-08-04] () HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-18] (Avira Operations GmbH & Co. KG) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\eMachines\Screensaver\run_eMachines.exe [154144 2010-07-29] () HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\eMachines\Screensaver\run_eMachines.exe [154144 2010-07-29] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Refresh.lnk ShortcutTarget: Refresh.lnk -> C:\Program Files (x86)\Elune Skin Pack\Tools\Refresh.cmd (No File) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SetPointII.lnk ShortcutTarget: SetPointII.lnk -> C:\Program Files\Logitech\SetPoint II\SetPointII.exe (Logitech Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SkinPackMenu.lnk ShortcutTarget: SkinPackMenu.lnk -> C:\Program Files (x86)\Elune Skin Pack\SP.exe (No File) SSODL-x32: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files (x86)\Stardock\Object Desktop\IconPackager\iprepair.dll (Stardock.net, Inc) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: 127.0.0.1 activation.cloud.techsmith.com Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default\searchplugins\webde-suche.xml FF Extension: toolbar - C:\Users\Bastian\AppData\Roaming\Mozilla\Firefox\Profiles\tub3kykl.default\Extensions\toolbar@web.de.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} Chrome: ======= CHR RestoreOnStartup: "https://www.google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (Google Docs) - C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (YouTube) - C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Marc Ecko) - C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\opjonmehjfmkejjifhhknofdnacklmjk\2_0 CHR Extension: (Gmail) - C:\Users\Bastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files (x86)\adawaretb\chrome-newtab-search.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-18] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-18] (Avira Operations GmbH & Co. KG) S3 GameConsoleService; C:\Program Files (x86)\eMachines Games\eMachines Game Console\GameConsoleService.exe [246520 2010-04-04] (WildTangent, Inc.) R2 GREGService; C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2013-05-27] () R2 Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group) S2 VMUSBArbService; "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG) S3 drvr; C:\Windows\SysWow64\drivers\drvr.sys [8704 2010-03-09] () R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-07-29] (GFI Software) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.) S3 drvr; \??\C:\Windows\system32\drivers\drvr.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S1 szwdzueb; \??\C:\Windows\system32\drivers\szwdzueb.sys [x] S3 TDPIPE; system32\drivers\tdpipe.sys [x] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-31 15:30 - 2013-07-31 15:30 - 01781589 _____ (Farbar) C:\Users\Bastian\Downloads\FRST64.exe 2013-07-31 15:30 - 2013-07-31 15:30 - 01781589 _____ (Farbar) C:\Users\Bastian\Desktop\FRST64.exe 2013-07-31 15:30 - 2013-07-31 15:30 - 00000000 ____D C:\FRST 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2013-07-31 13:59 - 2013-07-31 13:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2013-07-31 13:55 - 2013-07-31 13:55 - 00000000 ____D C:\Users\Bastian\Documents\Visual Studio 2010 2013-07-31 13:53 - 2013-07-31 14:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Windows\symbols 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Program Files\Microsoft Help Viewer 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-07-31 13:49 - 2013-07-31 13:49 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Avira 2013-07-31 13:47 - 2013-07-31 13:47 - 01293106 _____ C:\Users\Bastian\Downloads\Olympus Team Shop Hack.rar 2013-07-31 13:45 - 2013-07-31 13:45 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-07-31 13:44 - 2013-07-31 13:44 - 00002079 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-31 13:43 - 2013-07-31 13:43 - 00000000 ____D C:\Program Files (x86)\Avira 2013-07-31 13:43 - 2013-07-18 08:02 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-31 13:43 - 2013-07-18 08:02 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-31 13:43 - 2013-03-06 16:13 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-31 13:41 - 2013-07-31 13:42 - 03296584 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vbasic_web (1).exe 2013-07-31 13:37 - 2013-07-31 13:37 - 00821773 _____ C:\Users\Bastian\Downloads\[RevelatioN]Next Gen IDChanger v2.5.rar 2013-07-31 13:32 - 2013-07-31 13:32 - 00081298 _____ C:\ProgramData\1375270300.bdinstall.bin 2013-07-31 13:31 - 2013-07-31 13:31 - 00022706 _____ C:\ProgramData\1375270296.bdinstall.bin 2013-07-31 13:24 - 2013-07-31 13:24 - 01205856 _____ C:\Users\Bastian\Downloads\Olympus Team IDM+ITM.rar 2013-07-31 13:24 - 2013-07-31 13:24 - 01205856 _____ C:\Users\Bastian\Downloads\Olympus Team IDM+ITM (1).rar 2013-07-31 11:23 - 2013-07-31 11:23 - 00002268 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-31 11:23 - 2009-04-09 22:01 - 00000000 ____D C:\Users\Bastian\Desktop\UniversalThemePatcher_20090409 2013-07-31 11:22 - 2013-07-31 15:27 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-31 11:22 - 2013-07-31 15:27 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-31 11:22 - 2013-07-31 11:22 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-31 11:22 - 2013-07-31 11:22 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-31 11:21 - 2013-07-31 11:22 - 00000000 ____D C:\Users\Bastian\AppData\Local\Deployment 2013-07-31 11:21 - 2013-07-31 11:21 - 00000000 ____D C:\Users\Bastian\AppData\Local\Apps\2.0 2013-07-31 10:18 - 2013-07-31 10:18 - 00002006 _____ C:\Users\Bastian\Desktop\Paradise Online.lnk 2013-07-31 10:18 - 2013-07-31 10:18 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paradise Online 2013-07-30 23:57 - 2013-07-30 23:57 - 00192243 _____ C:\ProgramData\1375221147.bdinstall.bin 2013-07-30 22:32 - 2013-07-30 23:22 - 00000000 ____D C:\Program Files (x86)\RocketDock 2013-07-30 22:31 - 2013-07-30 22:34 - 117478104 _____ C:\Users\Bastian\Downloads\avast_free_antivirus_setup_8.0.1489.300(1).exe 2013-07-30 22:31 - 2013-07-30 22:32 - 06463660 _____ (Punk Software ) C:\Users\Bastian\Downloads\RocketDock-v1.3.5.exe 2013-07-30 21:48 - 2013-07-31 10:18 - 00000000 ____D C:\Program Files (x86)\Paradise Online 2013-07-30 21:33 - 2013-07-30 22:01 - 00001912 _____ C:\Windows\epplauncher.mif 2013-07-30 19:18 - 2013-07-30 22:17 - 00430592 _____ C:\Users\Bastian\Downloads\Mss32.dll 2013-07-30 19:18 - 2013-07-30 19:18 - 00007168 _____ (OnsOn) C:\Users\Bastian\Downloads\fiestax64.dll 2013-07-30 19:18 - 2013-07-30 19:18 - 00000010 _____ C:\Users\Bastian\Downloads\Mss33.bat 2013-07-30 18:42 - 2013-07-30 20:12 - 00000000 ____D C:\Users\Bastian\Downloads\resitem 2013-07-30 18:42 - 2013-07-30 20:02 - 00000000 ____D C:\Users\Bastian\Downloads\ressound 2013-07-30 18:39 - 2013-07-30 20:14 - 00000000 ____D C:\Users\Bastian\Downloads\ressystem 2013-07-30 18:39 - 2013-07-30 20:12 - 00000000 ____D C:\Users\Bastian\Downloads\reschar 2013-07-30 18:39 - 2013-07-30 20:06 - 00000000 ____D C:\Users\Bastian\Downloads\resmap 2013-07-30 18:39 - 2013-07-30 20:02 - 00000000 ____D C:\Users\Bastian\Downloads\resmenu 2013-07-30 18:39 - 2013-07-30 19:54 - 00000000 ____D C:\Users\Bastian\Downloads\reseffect 2013-07-30 18:38 - 2013-07-30 18:38 - 00200704 _____ (ICSharpCode.net) C:\Users\Bastian\Downloads\ICSharpCode.SharpZipLib.dll 2013-07-30 18:38 - 2013-07-30 18:38 - 00194560 _____ (-) C:\Users\Bastian\Downloads\Please_Vote_us.exe 2013-07-30 13:24 - 2013-07-30 14:39 - 00000000 ____D C:\Finalhell_v2 2013-07-30 13:23 - 2013-07-30 13:24 - 00289280 _____ C:\Users\Bastian\Downloads\Finalhell v.2 Downloader.exe 2013-07-30 13:21 - 2013-07-30 13:22 - 00914944 _____ (FinalHell Online) C:\Users\Bastian\Downloads\LauncherClient.exe 2013-07-30 13:19 - 2013-07-30 13:23 - 158227051 _____ C:\Users\Bastian\Downloads\EvasiveOnline.exe.part 2013-07-30 10:06 - 2013-07-30 10:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-29 20:17 - 2013-07-31 15:25 - 00315818 _____ C:\Windows\PFRO.log 2013-07-29 20:17 - 2013-07-31 15:25 - 00000672 _____ C:\Windows\setupact.log 2013-07-29 19:48 - 2013-07-29 19:48 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\AVG2013 2013-07-29 19:46 - 2013-07-29 20:13 - 00000000 ____D C:\ProgramData\AVG2013 2013-07-29 19:27 - 2013-07-29 19:27 - 00056072 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll 2013-07-29 19:25 - 2013-07-29 19:29 - 90239300 _____ (COMODO) C:\Users\Bastian\Downloads\cfw_installer_6.2(1).exe.part 2013-07-29 19:25 - 2013-07-29 19:25 - 00000000 _____ C:\Users\Bastian\Downloads\cfw_installer_6.2(1).exe 2013-07-29 18:59 - 2013-07-29 18:59 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll 2013-07-29 18:59 - 2013-07-29 18:59 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2013-07-29 18:55 - 2013-07-29 19:06 - 00046466 _____ C:\Windows\system32\Drivers\fvstore.dat 2013-07-29 18:55 - 2013-07-29 18:55 - 00000000 ___HD C:\VTRoot 2013-07-29 18:55 - 2013-07-29 18:55 - 00000000 ____D C:\Users\Bastian\AppData\Local\Comodo 2013-07-29 18:52 - 2013-07-31 09:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-29 18:52 - 2013-07-31 09:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-29 18:51 - 2013-07-29 18:51 - 00000000 ____D C:\ProgramData\APN 2013-07-29 18:50 - 2013-07-31 13:43 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 18:18 - 2013-07-29 19:41 - 00000000 ____D C:\Program Files (x86)\COMODO 2013-07-29 18:18 - 2013-07-29 18:20 - 00000000 ____D C:\ProgramData\COMODO 2013-07-29 18:17 - 2013-07-29 18:17 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-29 18:13 - 2013-07-29 18:13 - 03296584 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vbasic_web.exe 2013-07-29 17:56 - 2013-07-29 17:56 - 00000061 _____ C:\Users\Bastian\SciTEUser.properties 2013-07-29 17:54 - 2013-07-29 17:55 - 07377952 _____ (AutoIt Team) C:\Users\Bastian\Downloads\autoit-v3-setup.exe 2013-07-29 17:54 - 2013-07-29 17:55 - 06299911 _____ C:\Users\Bastian\Downloads\SciTE4AutoIt3.exe 2013-07-29 15:41 - 2013-07-29 15:42 - 00925184 _____ C:\Windows\expstart.exe 2013-07-29 15:39 - 2013-07-29 15:41 - 00000000 ____D C:\Windows\W7SOC 2013-07-29 15:39 - 2011-02-25 08:19 - 02795520 _____ (Microsoft Corporation) C:\Windows\explorer.backup.exe 2013-07-29 14:54 - 2013-07-29 15:39 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Rainmeter 2013-07-29 14:54 - 2013-07-29 14:54 - 00000000 ____D C:\Users\Bastian\Documents\Rainmeter 2013-07-29 14:54 - 2013-07-29 14:54 - 00000000 ____D C:\Program Files\Rainmeter 2013-07-29 14:27 - 2013-07-29 14:28 - 47400128 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\NetFx64.exe 2013-07-29 14:27 - 2013-07-29 14:28 - 07194488 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vcredist_x64(1).exe 2013-07-29 14:27 - 2013-07-29 14:28 - 05673816 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vcredist_x64.exe 2013-07-29 14:24 - 2013-07-29 14:24 - 00000000 ____D C:\ProgramData\Ad-Aware Antivirus 2013-07-29 14:23 - 2013-07-29 14:23 - 00005784 _____ C:\Users\Bastian\Downloads\TINY.ini 2013-07-29 14:23 - 2013-07-29 14:23 - 00005139 _____ C:\Users\Bastian\Downloads\WIDTH_1280.ini 2013-07-29 14:16 - 2013-07-29 14:46 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus 2013-07-29 14:16 - 2013-07-29 14:16 - 00000000 ____D C:\ProgramData\Lavasoft 2013-07-29 14:16 - 2013-07-29 14:16 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-29 14:16 - 2013-07-29 14:16 - 00000000 ____D C:\ProgramData\blekko toolbars 2013-07-29 14:15 - 2013-07-29 14:49 - 00000000 ____D C:\Rainmeter 2013-07-29 14:15 - 2013-07-29 14:15 - 00000000 ____D C:\Program Files (x86)\Toolbar Cleaner 2013-07-29 13:51 - 2013-07-29 19:56 - 00000000 ____D C:\Users\Bastian\AppData\Local\Avg2013 2013-07-29 13:45 - 2013-07-30 23:29 - 00000000 ____D C:\Users\Bastian\Desktop\Stuff 2013-07-29 13:45 - 2013-07-29 13:45 - 01386624 _____ C:\Users\Bastian\Downloads\Rainmeter-2.5.exe 2013-07-29 12:56 - 2013-07-29 12:56 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-07-29 12:55 - 2013-07-29 12:55 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\TuneUp Software 2013-07-29 12:52 - 2013-07-29 12:52 - 00000000 ____D C:\Program Files (x86)\AVG 2013-07-29 12:48 - 2013-07-29 12:48 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll.tmp 2013-07-29 12:48 - 2013-07-29 12:48 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll.tmp 2013-07-29 12:48 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-07-29 12:48 - 2011-02-25 08:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-29 12:48 - 2010-11-20 15:27 - 01808384 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll 2013-07-29 12:48 - 2010-11-20 15:27 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2013-07-29 12:48 - 2010-11-20 15:27 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll 2013-07-29 12:48 - 2010-11-20 15:26 - 01866240 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2013-07-29 12:48 - 2010-11-20 15:25 - 00780800 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll 2013-07-29 12:48 - 2010-11-20 15:25 - 00749568 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll 2013-07-29 12:48 - 2010-11-20 14:21 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll.backup 2013-07-29 12:48 - 2009-07-14 03:39 - 06676480 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe 2013-07-29 12:48 - 2009-07-14 03:39 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2013-07-29 12:48 - 2009-07-14 03:38 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe 2013-07-29 12:48 - 2009-07-14 03:28 - 20268032 _____ (Microsoft Corporation) C:\Windows\system32\imageres.dll 2013-07-29 12:48 - 2009-07-14 03:28 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\imagesp1.dll 2013-07-29 12:48 - 2009-07-14 03:11 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll.backup 2013-07-29 12:33 - 2013-07-30 12:44 - 00000000 ____D C:\ProgramData\MFAData 2013-07-29 12:33 - 2013-07-29 12:33 - 00000000 ____D C:\Users\Bastian\AppData\Local\MFAData 2013-07-28 16:10 - 2013-07-28 16:10 - 00000000 ____D C:\Users\Public\Documents\Stardock 2013-07-28 16:10 - 2013-07-28 16:10 - 00000000 ____D C:\Program Files (x86)\Stardock 2013-07-28 14:34 - 2013-07-28 14:37 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\VMware 2013-07-28 14:34 - 2013-07-28 14:37 - 00000000 ____D C:\Users\Bastian\AppData\Local\VMware 2013-07-28 14:32 - 2013-07-28 14:37 - 00000000 ____D C:\Program Files (x86)\VMware 2013-07-28 13:47 - 2013-07-28 13:58 - 450795904 _____ (VMware, Inc.) C:\Users\Bastian\Downloads\VMware-workstation-full-9.0.2-1031769.exe 2013-07-27 23:30 - 2013-07-27 23:30 - 00000000 ____D C:\Program Files (x86)\TechSmith 2013-07-27 22:49 - 2013-07-29 11:57 - 00000000 ____D C:\Program Files (x86)\AutoIt3 2013-07-27 21:38 - 2013-07-29 13:38 - 00000000 _____ C:\Users\Bastian\Documents\Pvp Stuff.txt 2013-07-27 19:19 - 2013-07-29 11:58 - 00000000 ____D C:\Program Files (x86)\CryOnline 2013-07-27 18:09 - 2013-07-27 19:12 - 2073712427 _____ () C:\Users\Bastian\Downloads\CryOnline-Installer.exe 2013-07-27 18:06 - 2013-07-27 18:07 - 42726127 _____ (ExtrinsicStudio) C:\Users\Bastian\AppData\Local\TerraSetup_v1.1.exe 2013-07-27 14:57 - 2013-07-27 14:57 - 00001024 _____ C:\Windows\SysWOW64\%TMP% 2013-07-27 14:57 - 2012-10-11 16:15 - 00052376 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys 2013-07-27 14:56 - 2013-07-28 14:37 - 00000000 ____D C:\ProgramData\VMware 2013-07-27 09:40 - 2013-07-27 09:40 - 00000076 _____ C:\Windows\ODTVIP.xt 2013-07-27 08:41 - 2013-07-27 08:41 - 00000000 ____D C:\Program Files (x86)\alaplaya 2013-07-27 07:31 - 2013-07-27 07:33 - 117478104 _____ C:\Users\Bastian\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-27 07:29 - 2013-07-29 14:46 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\LavasoftStatistics 2013-07-27 07:28 - 2013-07-29 14:45 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Ad-Aware Antivirus 2013-07-27 07:28 - 2013-07-29 14:14 - 00014456 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 2013-07-26 07:09 - 2013-07-26 10:33 - 810331685 _____ C:\Users\Bastian\Documents\Gameplay #1 Edited.wmv 2013-07-25 18:53 - 2013-07-27 11:52 - 00002050 _____ C:\Windows\IDC.RN 2013-07-23 14:39 - 2013-07-23 14:44 - 16237583 _____ C:\Users\Bastian\Documents\Ohne Titel.wmv 2013-07-22 16:47 - 2013-07-22 16:47 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\ImTOO 2013-07-22 13:49 - 2013-07-22 13:49 - 00000000 ____D C:\Users\Bastian\AppData\Local\Apple Computer 2013-07-22 13:48 - 2013-07-22 13:48 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Apple Computer 2013-07-21 15:26 - 2013-07-21 15:26 - 00000000 ____D C:\ProgramData\Apple Computer 2013-07-21 15:24 - 2013-07-21 15:24 - 00000000 ____D C:\Users\Bastian\AppData\Local\Apple 2013-07-21 15:24 - 2013-07-21 15:24 - 00000000 ____D C:\ProgramData\Apple 2013-07-21 15:24 - 2013-07-21 15:24 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2013-07-21 14:55 - 2013-07-21 15:00 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-21 14:55 - 2013-07-21 15:00 - 00000000 ____D C:\Program Files\Adobe 2013-07-21 13:42 - 2013-07-21 13:42 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\PDAppFlex 2013-07-21 13:41 - 2013-07-21 13:46 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-21 11:12 - 2013-07-21 11:31 - 00002964 _____ C:\Windows\Sandboxie.ini 2013-07-21 11:01 - 2013-07-21 11:03 - 00000000 ____D C:\ProgramData\InstallMate 2013-07-20 12:11 - 2013-07-28 20:22 - 00000000 ____D C:\Program Files (x86)\7tsp 2013-07-20 12:04 - 2013-07-20 12:04 - 00003510 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Bastian-PC-Bastian 2013-07-20 11:01 - 2013-07-20 12:47 - 00000000 ____D C:\Program Files (x86)\Resource Hacker 2013-07-20 10:14 - 2010-11-20 15:27 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll.backup 2013-07-20 10:14 - 2009-07-14 03:41 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll.backup 2013-07-20 10:14 - 2009-07-14 03:41 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\themeservice.dll.backup 2013-07-20 09:34 - 2013-07-20 09:34 - 00000000 ____D C:\Users\Bastian\Downloads\aIW-Client 2013-07-20 09:32 - 2013-07-20 09:36 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\uTorrent 2013-07-19 21:29 - 2013-07-19 21:29 - 00000000 ____D C:\AeriaGames 2013-07-18 20:48 - 2013-07-18 20:48 - 00000000 ____D C:\Program Files (x86)\NowAXInst 2013-07-17 16:26 - 2013-07-29 18:12 - 00000766 _____ C:\Users\Bastian\SciTE.session 2013-07-17 14:20 - 2013-07-17 14:45 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\eve Updater 2013-07-16 17:42 - 2013-07-29 17:48 - 00000000 ____D C:\ProgramData\Solid State Networks 2013-07-16 06:55 - 2013-07-16 06:55 - 00000000 __SHD C:\found.000 2013-07-15 19:03 - 2013-07-15 19:03 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Unity 2013-07-15 18:33 - 2013-07-31 11:16 - 00000000 ____D C:\Users\Bastian\AppData\Local\Unity 2013-07-15 18:31 - 2013-07-15 18:31 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-15 18:31 - 2013-07-15 18:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-15 18:31 - 2013-07-15 18:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-15 18:31 - 2013-07-15 18:31 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-15 18:31 - 2013-07-15 18:31 - 00000000 ____D C:\Program Files (x86)\Java 2013-07-12 13:45 - 2013-04-12 12:35 - 01678792 _____ (Microsoft Corporation) C:\Windows\system32\msvcr110d.dll 2013-07-12 13:43 - 2012-08-30 14:37 - 01498960 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100d.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-10 17:49 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-10 17:49 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-10 17:49 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-10 17:49 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-10 17:49 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-10 17:49 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-10 17:49 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-10 17:49 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-10 17:49 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-10 17:49 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-10 17:49 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-10 17:49 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-10 17:49 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-10 17:49 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-10 17:49 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-10 17:49 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-10 13:55 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 13:55 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 13:55 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-10 13:55 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 13:55 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-10 13:53 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-10 13:53 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-08 15:16 - 2013-07-08 15:16 - 00000000 ___RD C:\Sandbox 2013-07-06 21:52 - 2013-07-30 12:45 - 00000000 ____D C:\Program Files (x86)\VirtualDJ 2013-07-06 21:52 - 2013-07-06 21:52 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2013-07-01 14:10 - 2013-07-01 14:10 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-01 14:10 - 2013-07-01 14:10 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-01 14:10 - 2013-07-01 14:10 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-01 14:10 - 2013-07-01 14:10 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-01 14:10 - 2013-07-01 14:10 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-01 14:10 - 2013-07-01 14:10 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-07-01 14:10 - 2013-07-01 14:10 - 00000000 ____D C:\Program Files\Java ==================== One Month Modified Files and Folders ======= 2013-07-31 15:30 - 2013-07-31 15:30 - 01781589 _____ (Farbar) C:\Users\Bastian\Downloads\FRST64.exe 2013-07-31 15:30 - 2013-07-31 15:30 - 01781589 _____ (Farbar) C:\Users\Bastian\Desktop\FRST64.exe 2013-07-31 15:30 - 2013-07-31 15:30 - 00000000 ____D C:\FRST 2013-07-31 15:28 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-31 15:28 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-31 15:27 - 2013-07-31 11:22 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-31 15:27 - 2013-07-31 11:22 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-31 15:25 - 2013-07-29 20:17 - 00315818 _____ C:\Windows\PFRO.log 2013-07-31 15:25 - 2013-07-29 20:17 - 00000672 _____ C:\Windows\setupact.log 2013-07-31 15:25 - 2013-05-26 12:10 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-31 15:25 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-31 15:24 - 2013-05-26 22:12 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Skype 2013-07-31 15:24 - 2013-05-26 12:07 - 01906464 _____ C:\Windows\WindowsUpdate.log 2013-07-31 14:37 - 2013-05-26 13:21 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-31 14:01 - 2013-07-31 13:53 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-07-31 14:00 - 2013-07-31 14:00 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2013-07-31 13:59 - 2013-07-31 13:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2013-07-31 13:59 - 2013-05-26 12:14 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2013-07-31 13:55 - 2013-07-31 13:55 - 00000000 ____D C:\Users\Bastian\Documents\Visual Studio 2010 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Windows\symbols 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Program Files\Microsoft Help Viewer 2013-07-31 13:51 - 2013-07-31 13:51 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-07-31 13:51 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-07-31 13:49 - 2013-07-31 13:49 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Avira 2013-07-31 13:47 - 2013-07-31 13:47 - 01293106 _____ C:\Users\Bastian\Downloads\Olympus Team Shop Hack.rar 2013-07-31 13:45 - 2013-07-31 13:45 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-07-31 13:44 - 2013-07-31 13:44 - 00002079 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-31 13:43 - 2013-07-31 13:43 - 00000000 ____D C:\Program Files (x86)\Avira 2013-07-31 13:43 - 2013-07-29 18:50 - 00000000 ____D C:\ProgramData\Avira 2013-07-31 13:42 - 2013-07-31 13:41 - 03296584 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vbasic_web (1).exe 2013-07-31 13:37 - 2013-07-31 13:37 - 00821773 _____ C:\Users\Bastian\Downloads\[RevelatioN]Next Gen IDChanger v2.5.rar 2013-07-31 13:32 - 2013-07-31 13:32 - 00081298 _____ C:\ProgramData\1375270300.bdinstall.bin 2013-07-31 13:31 - 2013-07-31 13:31 - 00022706 _____ C:\ProgramData\1375270296.bdinstall.bin 2013-07-31 13:24 - 2013-07-31 13:24 - 01205856 _____ C:\Users\Bastian\Downloads\Olympus Team IDM+ITM.rar 2013-07-31 13:24 - 2013-07-31 13:24 - 01205856 _____ C:\Users\Bastian\Downloads\Olympus Team IDM+ITM (1).rar 2013-07-31 11:48 - 2013-06-26 14:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-31 11:23 - 2013-07-31 11:23 - 00002268 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-31 11:23 - 2013-06-22 14:18 - 00000000 ____D C:\Users\Bastian\AppData\Local\Google 2013-07-31 11:23 - 2013-06-22 14:18 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-31 11:22 - 2013-07-31 11:22 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-31 11:22 - 2013-07-31 11:22 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-31 11:22 - 2013-07-31 11:21 - 00000000 ____D C:\Users\Bastian\AppData\Local\Deployment 2013-07-31 11:21 - 2013-07-31 11:21 - 00000000 ____D C:\Users\Bastian\AppData\Local\Apps\2.0 2013-07-31 11:16 - 2013-07-15 18:33 - 00000000 ____D C:\Users\Bastian\AppData\Local\Unity 2013-07-31 11:16 - 2013-06-22 14:17 - 00000464 _____ C:\Windows\wininit.ini 2013-07-31 11:08 - 2013-06-20 15:25 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3 2013-07-31 10:18 - 2013-07-31 10:18 - 00002006 _____ C:\Users\Bastian\Desktop\Paradise Online.lnk 2013-07-31 10:18 - 2013-07-31 10:18 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paradise Online 2013-07-31 10:18 - 2013-07-30 21:48 - 00000000 ____D C:\Program Files (x86)\Paradise Online 2013-07-31 09:48 - 2013-07-29 18:52 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-31 09:48 - 2013-07-29 18:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-31 00:01 - 2013-06-22 09:52 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-30 23:57 - 2013-07-30 23:57 - 00192243 _____ C:\ProgramData\1375221147.bdinstall.bin 2013-07-30 23:43 - 2013-06-25 17:36 - 00000000 ____D C:\Users\Bastian\AppData\Local\CrashDumps 2013-07-30 23:29 - 2013-07-29 13:45 - 00000000 ____D C:\Users\Bastian\Desktop\Stuff 2013-07-30 23:22 - 2013-07-30 22:32 - 00000000 ____D C:\Program Files (x86)\RocketDock 2013-07-30 23:00 - 2013-06-13 10:10 - 00000000 ____D C:\Users\Bastian\AppData\Local\Akamai 2013-07-30 23:00 - 2013-05-29 16:54 - 00000000 ____D C:\Program Files\WinRAR 2013-07-30 22:37 - 2013-06-28 13:49 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-30 22:37 - 2013-06-28 13:49 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-30 22:37 - 2013-06-28 13:49 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-30 22:37 - 2013-06-22 09:56 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-30 22:36 - 2013-06-22 09:53 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-30 22:34 - 2013-07-30 22:31 - 117478104 _____ C:\Users\Bastian\Downloads\avast_free_antivirus_setup_8.0.1489.300(1).exe 2013-07-30 22:32 - 2013-07-30 22:31 - 06463660 _____ (Punk Software ) C:\Users\Bastian\Downloads\RocketDock-v1.3.5.exe 2013-07-30 22:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Cursors 2013-07-30 22:17 - 2013-07-30 19:18 - 00430592 _____ C:\Users\Bastian\Downloads\Mss32.dll 2013-07-30 22:01 - 2013-07-30 21:33 - 00001912 _____ C:\Windows\epplauncher.mif 2013-07-30 20:14 - 2013-07-30 18:39 - 00000000 ____D C:\Users\Bastian\Downloads\ressystem 2013-07-30 20:12 - 2013-07-30 18:42 - 00000000 ____D C:\Users\Bastian\Downloads\resitem 2013-07-30 20:12 - 2013-07-30 18:39 - 00000000 ____D C:\Users\Bastian\Downloads\reschar 2013-07-30 20:06 - 2013-07-30 18:39 - 00000000 ____D C:\Users\Bastian\Downloads\resmap 2013-07-30 20:02 - 2013-07-30 18:42 - 00000000 ____D C:\Users\Bastian\Downloads\ressound 2013-07-30 20:02 - 2013-07-30 18:39 - 00000000 ____D C:\Users\Bastian\Downloads\resmenu 2013-07-30 19:54 - 2013-07-30 18:39 - 00000000 ____D C:\Users\Bastian\Downloads\reseffect 2013-07-30 19:18 - 2013-07-30 19:18 - 00007168 _____ (OnsOn) C:\Users\Bastian\Downloads\fiestax64.dll 2013-07-30 19:18 - 2013-07-30 19:18 - 00000010 _____ C:\Users\Bastian\Downloads\Mss33.bat 2013-07-30 18:38 - 2013-07-30 18:38 - 00200704 _____ (ICSharpCode.net) C:\Users\Bastian\Downloads\ICSharpCode.SharpZipLib.dll 2013-07-30 18:38 - 2013-07-30 18:38 - 00194560 _____ (-) C:\Users\Bastian\Downloads\Please_Vote_us.exe 2013-07-30 18:38 - 2013-05-29 11:42 - 00000000 ____D C:\Program Files (x86)\Steam 2013-07-30 14:39 - 2013-07-30 13:24 - 00000000 ____D C:\Finalhell_v2 2013-07-30 13:24 - 2013-07-30 13:23 - 00289280 _____ C:\Users\Bastian\Downloads\Finalhell v.2 Downloader.exe 2013-07-30 13:23 - 2013-07-30 13:19 - 158227051 _____ C:\Users\Bastian\Downloads\EvasiveOnline.exe.part 2013-07-30 13:22 - 2013-07-30 13:21 - 00914944 _____ (FinalHell Online) C:\Users\Bastian\Downloads\LauncherClient.exe 2013-07-30 12:46 - 2013-06-22 21:33 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-07-30 12:45 - 2013-07-06 21:52 - 00000000 ____D C:\Program Files (x86)\VirtualDJ 2013-07-30 12:44 - 2013-07-29 12:33 - 00000000 ____D C:\ProgramData\MFAData 2013-07-30 12:43 - 2013-06-08 12:02 - 00000000 ____D C:\Users\Bastian\AppData\Local\IW4M 2013-07-30 10:09 - 2013-05-31 20:16 - 00000000 ____D C:\Users\Bastian\AppData\Local\Adobe 2013-07-30 10:06 - 2013-07-30 10:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-29 20:13 - 2013-07-29 19:46 - 00000000 ____D C:\ProgramData\AVG2013 2013-07-29 19:56 - 2013-07-29 13:51 - 00000000 ____D C:\Users\Bastian\AppData\Local\Avg2013 2013-07-29 19:48 - 2013-07-29 19:48 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\AVG2013 2013-07-29 19:41 - 2013-07-29 18:18 - 00000000 ____D C:\Program Files (x86)\COMODO 2013-07-29 19:29 - 2013-07-29 19:25 - 90239300 _____ (COMODO) C:\Users\Bastian\Downloads\cfw_installer_6.2(1).exe.part 2013-07-29 19:27 - 2013-07-29 19:27 - 00056072 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll 2013-07-29 19:25 - 2013-07-29 19:25 - 00000000 _____ C:\Users\Bastian\Downloads\cfw_installer_6.2(1).exe 2013-07-29 19:06 - 2013-07-29 18:55 - 00046466 _____ C:\Windows\system32\Drivers\fvstore.dat 2013-07-29 18:59 - 2013-07-29 18:59 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll 2013-07-29 18:59 - 2013-07-29 18:59 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2013-07-29 18:55 - 2013-07-29 18:55 - 00000000 ___HD C:\VTRoot 2013-07-29 18:55 - 2013-07-29 18:55 - 00000000 ____D C:\Users\Bastian\AppData\Local\Comodo 2013-07-29 18:51 - 2013-07-29 18:51 - 00000000 ____D C:\ProgramData\APN 2013-07-29 18:47 - 2013-05-31 21:59 - 00000000 ____D C:\Windows\pss 2013-07-29 18:47 - 2013-05-26 13:09 - 00000000 ___RD C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-29 18:20 - 2013-07-29 18:18 - 00000000 ____D C:\ProgramData\COMODO 2013-07-29 18:17 - 2013-07-29 18:17 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-29 18:13 - 2013-07-29 18:13 - 03296584 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vbasic_web.exe 2013-07-29 18:12 - 2013-07-17 16:26 - 00000766 _____ C:\Users\Bastian\SciTE.session 2013-07-29 17:56 - 2013-07-29 17:56 - 00000061 _____ C:\Users\Bastian\SciTEUser.properties 2013-07-29 17:56 - 2013-05-26 13:08 - 00000000 ____D C:\Users\Bastian 2013-07-29 17:55 - 2013-07-29 17:54 - 07377952 _____ (AutoIt Team) C:\Users\Bastian\Downloads\autoit-v3-setup.exe 2013-07-29 17:55 - 2013-07-29 17:54 - 06299911 _____ C:\Users\Bastian\Downloads\SciTE4AutoIt3.exe 2013-07-29 17:48 - 2013-07-16 17:42 - 00000000 ____D C:\ProgramData\Solid State Networks 2013-07-29 17:46 - 2010-09-10 13:33 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-29 15:42 - 2013-07-29 15:41 - 00925184 _____ C:\Windows\expstart.exe 2013-07-29 15:41 - 2013-07-29 15:39 - 00000000 ____D C:\Windows\W7SOC 2013-07-29 15:39 - 2013-07-29 14:54 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Rainmeter 2013-07-29 14:54 - 2013-07-29 14:54 - 00000000 ____D C:\Users\Bastian\Documents\Rainmeter 2013-07-29 14:54 - 2013-07-29 14:54 - 00000000 ____D C:\Program Files\Rainmeter 2013-07-29 14:49 - 2013-07-29 14:15 - 00000000 ____D C:\Rainmeter 2013-07-29 14:46 - 2013-07-29 14:16 - 00000000 ____D C:\Program Files (x86)\Ad-Aware Antivirus 2013-07-29 14:46 - 2013-07-27 07:29 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\LavasoftStatistics 2013-07-29 14:45 - 2013-07-27 07:28 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Ad-Aware Antivirus 2013-07-29 14:28 - 2013-07-29 14:27 - 47400128 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\NetFx64.exe 2013-07-29 14:28 - 2013-07-29 14:27 - 07194488 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vcredist_x64(1).exe 2013-07-29 14:28 - 2013-07-29 14:27 - 05673816 _____ (Microsoft Corporation) C:\Users\Bastian\Downloads\vcredist_x64.exe 2013-07-29 14:24 - 2013-07-29 14:24 - 00000000 ____D C:\ProgramData\Ad-Aware Antivirus 2013-07-29 14:23 - 2013-07-29 14:23 - 00005784 _____ C:\Users\Bastian\Downloads\TINY.ini 2013-07-29 14:23 - 2013-07-29 14:23 - 00005139 _____ C:\Users\Bastian\Downloads\WIDTH_1280.ini 2013-07-29 14:16 - 2013-07-29 14:16 - 00000000 ____D C:\ProgramData\Lavasoft 2013-07-29 14:16 - 2013-07-29 14:16 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-29 14:16 - 2013-07-29 14:16 - 00000000 ____D C:\ProgramData\blekko toolbars 2013-07-29 14:15 - 2013-07-29 14:15 - 00000000 ____D C:\Program Files (x86)\Toolbar Cleaner 2013-07-29 14:14 - 2013-07-27 07:28 - 00014456 _____ (GFI Software) C:\Windows\system32\Drivers\gfibto.sys 2013-07-29 13:45 - 2013-07-29 13:45 - 01386624 _____ C:\Users\Bastian\Downloads\Rainmeter-2.5.exe 2013-07-29 13:38 - 2013-07-27 21:38 - 00000000 _____ C:\Users\Bastian\Documents\Pvp Stuff.txt 2013-07-29 12:56 - 2013-07-29 12:56 - 00003230 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-07-29 12:55 - 2013-07-29 12:55 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\TuneUp Software 2013-07-29 12:52 - 2013-07-29 12:52 - 00000000 ____D C:\Program Files (x86)\AVG 2013-07-29 12:48 - 2013-07-29 12:48 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll.tmp 2013-07-29 12:48 - 2013-07-29 12:48 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll.tmp 2013-07-29 12:33 - 2013-07-29 12:33 - 00000000 ____D C:\Users\Bastian\AppData\Local\MFAData 2013-07-29 11:58 - 2013-07-27 19:19 - 00000000 ____D C:\Program Files (x86)\CryOnline 2013-07-29 11:57 - 2013-07-27 22:49 - 00000000 ____D C:\Program Files (x86)\AutoIt3 2013-07-28 20:22 - 2013-07-20 12:11 - 00000000 ____D C:\Program Files (x86)\7tsp 2013-07-28 17:30 - 2013-06-22 09:52 - 00077312 _____ (Microsoft) C:\Windows\DProgram.exe 2013-07-28 16:10 - 2013-07-28 16:10 - 00000000 ____D C:\Users\Public\Documents\Stardock 2013-07-28 16:10 - 2013-07-28 16:10 - 00000000 ____D C:\Program Files (x86)\Stardock 2013-07-28 14:37 - 2013-07-28 14:34 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\VMware 2013-07-28 14:37 - 2013-07-28 14:34 - 00000000 ____D C:\Users\Bastian\AppData\Local\VMware 2013-07-28 14:37 - 2013-07-28 14:32 - 00000000 ____D C:\Program Files (x86)\VMware 2013-07-28 14:37 - 2013-07-27 14:56 - 00000000 ____D C:\ProgramData\VMware 2013-07-28 14:33 - 2013-05-26 21:59 - 00713026 _____ C:\Windows\system32\perfh007.dat 2013-07-28 14:33 - 2013-05-26 21:59 - 00155796 _____ C:\Windows\system32\perfc007.dat 2013-07-28 14:33 - 2013-05-26 16:21 - 01681214 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-07-28 13:58 - 2013-07-28 13:47 - 450795904 _____ (VMware, Inc.) C:\Users\Bastian\Downloads\VMware-workstation-full-9.0.2-1031769.exe 2013-07-27 23:30 - 2013-07-27 23:30 - 00000000 ____D C:\Program Files (x86)\TechSmith 2013-07-27 23:30 - 2013-06-22 21:33 - 00000000 ____D C:\ProgramData\TechSmith 2013-07-27 22:49 - 2009-07-14 09:45 - 00000000 ____D C:\Windows\ShellNew 2013-07-27 19:12 - 2013-07-27 18:09 - 2073712427 _____ () C:\Users\Bastian\Downloads\CryOnline-Installer.exe 2013-07-27 18:07 - 2013-07-27 18:06 - 42726127 _____ (ExtrinsicStudio) C:\Users\Bastian\AppData\Local\TerraSetup_v1.1.exe 2013-07-27 14:57 - 2013-07-27 14:57 - 00001024 _____ C:\Windows\SysWOW64\%TMP% 2013-07-27 11:52 - 2013-07-25 18:53 - 00002050 _____ C:\Windows\IDC.RN 2013-07-27 09:40 - 2013-07-27 09:40 - 00000076 _____ C:\Windows\ODTVIP.xt 2013-07-27 08:41 - 2013-07-27 08:41 - 00000000 ____D C:\Program Files (x86)\alaplaya 2013-07-27 08:01 - 2013-06-03 15:57 - 00064016 _____ C:\Users\Bastian\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-27 07:54 - 2009-07-14 07:13 - 01593956 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-27 07:33 - 2013-07-27 07:31 - 117478104 _____ C:\Users\Bastian\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-27 07:29 - 2013-05-27 13:46 - 00000023 _____ C:\Windows\ODBCINST.INI 2013-07-27 07:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help 2013-07-27 07:15 - 2009-07-14 06:45 - 04949040 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-26 19:53 - 2013-05-26 22:12 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-26 19:53 - 2013-05-26 22:12 - 00000000 ____D C:\ProgramData\Skype 2013-07-26 14:06 - 2013-05-29 12:13 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-07-26 10:33 - 2013-07-26 07:09 - 810331685 _____ C:\Users\Bastian\Documents\Gameplay #1 Edited.wmv 2013-07-26 06:50 - 2009-07-14 07:08 - 00032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-23 17:06 - 2013-05-26 21:19 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-07-23 14:44 - 2013-07-23 14:39 - 16237583 _____ C:\Users\Bastian\Documents\Ohne Titel.wmv 2013-07-22 16:47 - 2013-07-22 16:47 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\ImTOO 2013-07-22 16:40 - 2013-05-26 13:32 - 00000000 ____D C:\Data 2013-07-22 13:49 - 2013-07-22 13:49 - 00000000 ____D C:\Users\Bastian\AppData\Local\Apple Computer 2013-07-22 13:48 - 2013-07-22 13:48 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Apple Computer 2013-07-21 15:26 - 2013-07-21 15:26 - 00000000 ____D C:\ProgramData\Apple Computer 2013-07-21 15:24 - 2013-07-21 15:24 - 00000000 ____D C:\Users\Bastian\AppData\Local\Apple 2013-07-21 15:24 - 2013-07-21 15:24 - 00000000 ____D C:\ProgramData\Apple 2013-07-21 15:24 - 2013-07-21 15:24 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2013-07-21 15:14 - 2013-05-26 13:15 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Adobe 2013-07-21 15:00 - 2013-07-21 14:55 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-21 15:00 - 2013-07-21 14:55 - 00000000 ____D C:\Program Files\Adobe 2013-07-21 14:55 - 2010-09-10 13:51 - 00000000 ____D C:\ProgramData\Adobe 2013-07-21 13:46 - 2013-07-21 13:41 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-21 13:42 - 2013-07-21 13:42 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\PDAppFlex 2013-07-21 11:31 - 2013-07-21 11:12 - 00002964 _____ C:\Windows\Sandboxie.ini 2013-07-21 11:03 - 2013-07-21 11:01 - 00000000 ____D C:\ProgramData\InstallMate 2013-07-20 12:47 - 2013-07-20 11:01 - 00000000 ____D C:\Program Files (x86)\Resource Hacker 2013-07-20 12:04 - 2013-07-20 12:04 - 00003510 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Bastian-PC-Bastian 2013-07-20 12:01 - 2010-09-10 13:50 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-20 11:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-07-20 09:36 - 2013-07-20 09:32 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\uTorrent 2013-07-20 09:34 - 2013-07-20 09:34 - 00000000 ____D C:\Users\Bastian\Downloads\aIW-Client 2013-07-19 21:29 - 2013-07-19 21:29 - 00000000 ____D C:\AeriaGames 2013-07-18 20:53 - 2013-06-17 17:22 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Process Hacker 2 2013-07-18 20:48 - 2013-07-18 20:48 - 00000000 ____D C:\Program Files (x86)\NowAXInst 2013-07-18 08:02 - 2013-07-31 13:43 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-18 08:02 - 2013-07-31 13:43 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-17 14:45 - 2013-07-17 14:20 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\eve Updater 2013-07-16 06:55 - 2013-07-16 06:55 - 00000000 __SHD C:\found.000 2013-07-15 19:03 - 2013-07-15 19:03 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Unity 2013-07-15 18:31 - 2013-07-15 18:31 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-15 18:31 - 2013-07-15 18:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-15 18:31 - 2013-07-15 18:31 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-15 18:31 - 2013-07-15 18:31 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-15 18:31 - 2013-07-15 18:31 - 00000000 ____D C:\Program Files (x86)\Java 2013-07-15 18:31 - 2013-05-26 13:22 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-07-15 18:31 - 2013-05-26 13:22 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-07-15 14:20 - 2013-05-26 13:21 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-15 14:20 - 2013-05-26 13:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-15 14:20 - 2013-05-26 13:21 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-07-10 19:27 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 19:27 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-10 19:27 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-08 15:16 - 2013-07-08 15:16 - 00000000 ___RD C:\Sandbox 2013-07-06 21:52 - 2013-07-06 21:52 - 00000000 ____D C:\Users\Bastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2013-07-02 14:18 - 2013-05-31 16:46 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 14:10 - 2013-07-01 14:10 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-01 14:10 - 2013-07-01 14:10 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-01 14:10 - 2013-07-01 14:10 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-01 14:10 - 2013-07-01 14:10 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-01 14:10 - 2013-07-01 14:10 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-01 14:10 - 2013-07-01 14:10 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-07-01 14:10 - 2013-07-01 14:10 - 00000000 ____D C:\Program Files\Java ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-23 16:27 ==================== End Of Log ============================ --- --- --- --- --- --- Kann mir wer Weiter helfen :/ ? Geändert von Kipsell (31.07.2013 um 14:35 Uhr) |
31.07.2013, 19:43 | #4 | |
/// the machine /// TB-Ausbilder | Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PCZitat:
ESET Online Scanner
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.07.2013, 19:54 | #5 | |
| Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PCZitat:
Ist das Schlimm ? |
31.07.2013, 20:11 | #6 |
/// the machine /// TB-Ausbilder | Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC löschen/Deinstallieren, sonst muss ich den Support einstellen.
__________________ --> Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC |
31.07.2013, 20:13 | #7 |
| Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC Oke mach ich gleich (nach dem prüfen) |
31.07.2013, 20:14 | #8 |
/// the machine /// TB-Ausbilder | Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.08.2013, 07:26 | #9 |
| Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC Hier die Log.txt Und ich weiß was ich habe den Ramni.a Virus Muss ich jetzt den Pc neu aufsetzten (keine ahnung wie das geht) oder gäbe es noch eine möglichkeit meinen Pc zu retten ? |
01.08.2013, 09:34 | #10 |
/// the machine /// TB-Ausbilder | Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC Deswegen wollte ich den Onlinescan, das war meine Vermutung. Alles formatieren, KEINE DATEN SICHERN, gar nix, nicht mal en pixel von irgendwas. Und abfahrt neu installiern
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Jeder Viren chutz erkennt bei normalen Programmen über 300 Viren auf meinem PC |
center, erkenn, erkennt, leute, normale, normalen, programme, programmen, viren |