Plagegeister aller Art und deren Bekämpfung: BSI Sicherheitstest PositivWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
| ![]() BSI Sicherheitstest Positiv 4x Googlemail: alle negativ (werden von Thunderbird abgerufen) 2x Web.de: 1x positiv (werden über Browser abgerufen) 1x arcor.de: positiv (wird über Thunderbird abgerufen) Heißt also, dass von 7 E-Mail Adresse "nur" 2 in der Datenbank des BSI zu finden sind. Hat ja an sich nichts zu heißen... Kompletter Systemcheck mit Avira Free Antivirus: Keine Schadsoftware gefunden Check mit Avira PC Cleaner (wie vom BSI angeraten und bereitgestellt): Keine Schadsoftware gefunden Und da ja hier als erstes immer ein Check mit Farbar's Recovery Scan Tool gefordert und nach den Logfiles gefragt wird, habe ich das direkt schon mal in Eigeninitiative gemacht, um den ganzen Vorgang etwas zu beschleunigen ![]() (Passwörter habe ich bisher noch nicht abgeändert, da ich erst sicher gehen möchte, dass mein PC auch sauber ist.) Vielen Dank schon im Voraus für die Hilfe! Hier die Logfiles: FRST.txt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Steffen (administrator) on SPACE on 07-04-2014 20:48:01 Running from C:\Users\Steffen\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7174728 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [GamecomSound] - C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe [2453504 2013-05-03] () HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-11] (Intel Corporation) HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-08-31] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [Razer Synapse] - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [444760 2014-03-07] (Razer Inc.) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default FF SelectedSearchEngine: Google FF Homepage: https://www.google.de/ FF Keyword.URL: https://www.google.de/#q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: FoxyProxy Standard - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\foxyproxy@eric.h.jung [2014-02-05] FF Extension: TextMarker! - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\{1c530060-b0ae-11d9-9669-0800200c9a66} [2013-12-21] FF Extension: Enhanced Steam - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\jid0-SmvlvxGpvCyG252KbVMqIKR79Uc@jetpack.xpi [2013-12-21] FF Extension: Old Default Image Style - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\olddefaultimagestyle@dagger2-addons.mozilla.org.xpi [2013-12-21] FF Extension: Flagfox - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-08] FF Extension: Image Zoom - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013-12-21] FF Extension: Modify Headers - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi [2013-12-21] FF Extension: Pearl Crescent Page Saver Basic - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\{c151d79e-e61b-4a90-a887-5a46d38fba99}.xpi [2013-12-21] FF Extension: Adblock Plus - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\fd6c7ppl.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-21] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI) R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-04-18] (MICRO-STAR INTERNATIONAL CO., LTD.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-25] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2013-04-11] () ==================== Drivers (Whitelisted) ==================== R3 ASUSU7; C:\Windows\System32\DRIVERS\ASUSU7.SYS [358912 2013-05-02] (C-Media Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-21] (Avira Operations GmbH & Co. KG) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [66928 2013-04-11] (Qualcomm Atheros, Inc.) S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-02-13] () R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [165824 2013-04-11] (Qualcomm Atheros, Inc.) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-10-25] (Realtek Semiconductor Corporation ) R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39080 2013-11-15] (Razer Inc) S3 MSICDSetup; \??\E:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-07 20:48 - 2014-04-07 20:48 - 00015106 _____ () C:\Users\Steffen\Desktop\FRST.txt 2014-04-07 20:47 - 2014-04-07 20:48 - 00000000 ____D () C:\FRST 2014-04-07 19:35 - 2014-04-07 19:35 - 02157056 _____ (Farbar) C:\Users\Steffen\Desktop\FRST64.exe 2014-04-06 16:12 - 2014-04-06 16:12 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\WinRAR 2014-04-06 15:49 - 2014-04-06 18:59 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-04-05 20:28 - 2014-04-05 20:28 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\dvdcss 2014-04-05 18:43 - 2014-04-06 21:19 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\vlc 2014-04-05 18:38 - 2014-04-05 18:38 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2014-04-01 17:48 - 2014-04-01 19:27 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Awesomium 2014-04-01 17:22 - 2014-04-05 11:43 - 05454328 _____ (NCSOFT) C:\Users\Steffen\Desktop\Wildstar.exe 2014-04-01 17:22 - 2014-04-01 17:22 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\NCSOFT 2014-04-01 17:22 - 2014-04-01 17:22 - 00000000 ____D () C:\Users\Steffen\AppData\Local\NCSOFT 2014-03-31 23:13 - 2014-03-31 23:13 - 00000000 ____D () C:\Users\Steffen\Documents\Elder Scrolls Online 2014-03-31 23:13 - 2014-03-31 23:13 - 00000000 ____D () C:\ProgramData\Elder Scrolls Online 2014-03-30 21:21 - 2014-03-30 21:21 - 00000000 ___HD () C:\Program Files (x86)\Zero G Registry 2014-03-30 21:21 - 2014-03-30 21:21 - 00000000 ____D () C:\Windows\jre 2014-03-30 21:21 - 2014-03-30 21:21 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Elder Scrolls Online 2014-03-30 21:19 - 2014-03-30 21:19 - 00000000 ___HD () C:\Users\Steffen\InstallAnywhere 2014-03-30 13:57 - 2014-03-30 13:57 - 00000000 ____D () C:\Users\Steffen\Documents\Diablo III 2014-03-29 13:35 - 2014-03-29 13:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-22 14:56 - 2014-03-22 15:21 - 00000000 ____D () C:\Users\Steffen\Desktop\Kamera-Uploads 2014-03-18 20:44 - 2014-03-18 20:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\Program Files\iTunes 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\Program Files\iPod 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-13 18:09 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 18:09 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 18:09 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 18:09 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 18:09 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 18:09 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 18:09 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 18:09 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 18:09 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 18:09 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 18:09 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 18:09 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 18:09 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 18:09 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 18:09 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 18:09 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 18:09 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 18:09 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 18:09 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 18:09 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 18:09 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 18:09 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 18:09 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 18:09 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 18:09 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 18:09 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 18:09 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 18:09 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 18:09 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 18:09 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 18:09 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 18:09 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 18:09 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 18:09 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 18:09 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 18:09 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 18:09 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 18:09 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 18:09 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 18:09 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 18:09 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 18:09 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 18:09 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 18:09 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-13 18:05 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 18:05 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 18:05 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 18:05 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-12 20:56 - 2014-03-12 21:01 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\com.onemrbean.soundodgerplus 2014-03-12 20:56 - 2014-03-12 20:57 - 00000000 ____D () C:\Users\Steffen\Documents\soundodger 2014-03-11 19:08 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-03-11 19:06 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-03-11 19:06 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00484296 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00409544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00377688 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-03-11 19:06 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-03-09 20:23 - 2014-03-09 20:23 - 00000000 ____D () C:\ProgramData\Sun 2014-03-09 20:23 - 2014-03-09 20:23 - 00000000 ____D () C:\ProgramData\Oracle 2014-03-09 20:22 - 2014-03-09 20:22 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-03-09 20:22 - 2014-03-09 20:22 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-03-09 20:22 - 2014-03-09 20:22 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-03-09 20:22 - 2014-03-09 20:22 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-03-09 20:22 - 2014-03-09 20:22 - 00000000 ____D () C:\Program Files (x86)\Java ==================== One Month Modified Files and Folders ======= 2014-04-07 20:48 - 2014-04-07 20:48 - 00015106 _____ () C:\Users\Steffen\Desktop\FRST.txt 2014-04-07 20:48 - 2014-04-07 20:47 - 00000000 ____D () C:\FRST 2014-04-07 19:45 - 2013-12-26 21:12 - 00000158 _____ () C:\Users\Steffen\Desktop\Neues Textdokument.txt 2014-04-07 19:35 - 2014-04-07 19:35 - 02157056 _____ (Farbar) C:\Users\Steffen\Desktop\FRST64.exe 2014-04-07 17:26 - 2009-07-14 06:45 - 00025648 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-07 17:26 - 2009-07-14 06:45 - 00025648 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-07 17:24 - 2013-09-12 05:01 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 17:24 - 2013-09-12 05:01 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 17:24 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-07 17:22 - 2013-09-11 19:05 - 01887720 _____ () C:\Windows\WindowsUpdate.log 2014-04-07 17:18 - 2013-09-11 19:20 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-07 17:18 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-07 17:18 - 2009-07-14 06:51 - 00072326 _____ () C:\Windows\setupact.log 2014-04-06 21:19 - 2014-04-05 18:43 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\vlc 2014-04-06 18:59 - 2014-04-06 15:49 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-04-06 16:12 - 2014-04-06 16:12 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\WinRAR 2014-04-05 20:28 - 2014-04-05 20:28 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\dvdcss 2014-04-05 18:38 - 2014-04-05 18:38 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2014-04-05 14:56 - 2013-09-13 21:10 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-05 11:43 - 2014-04-01 17:22 - 05454328 _____ (NCSOFT) C:\Users\Steffen\Desktop\Wildstar.exe 2014-04-03 18:12 - 2013-12-23 18:02 - 00000000 ____D () C:\Users\Steffen\AppData\Local\Battle.net 2014-04-01 19:27 - 2014-04-01 17:48 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Awesomium 2014-04-01 17:22 - 2014-04-01 17:22 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\NCSOFT 2014-04-01 17:22 - 2014-04-01 17:22 - 00000000 ____D () C:\Users\Steffen\AppData\Local\NCSOFT 2014-03-31 23:13 - 2014-03-31 23:13 - 00000000 ____D () C:\Users\Steffen\Documents\Elder Scrolls Online 2014-03-31 23:13 - 2014-03-31 23:13 - 00000000 ____D () C:\ProgramData\Elder Scrolls Online 2014-03-30 21:23 - 2014-01-19 20:22 - 00000000 ____D () C:\ProgramData\Origin 2014-03-30 21:21 - 2014-03-30 21:21 - 00000000 ___HD () C:\Program Files (x86)\Zero G Registry 2014-03-30 21:21 - 2014-03-30 21:21 - 00000000 ____D () C:\Windows\jre 2014-03-30 21:21 - 2014-03-30 21:21 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Elder Scrolls Online 2014-03-30 21:21 - 2013-09-11 19:05 - 00000000 ____D () C:\Users\Steffen 2014-03-30 21:19 - 2014-03-30 21:19 - 00000000 ___HD () C:\Users\Steffen\InstallAnywhere 2014-03-30 19:51 - 2014-01-19 20:22 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-30 13:57 - 2014-03-30 13:57 - 00000000 ____D () C:\Users\Steffen\Documents\Diablo III 2014-03-30 12:19 - 2013-09-11 19:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 13:35 - 2014-03-29 13:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-29 13:26 - 2013-12-23 18:02 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-03-22 15:21 - 2014-03-22 14:56 - 00000000 ____D () C:\Users\Steffen\Desktop\Kamera-Uploads 2014-03-18 22:25 - 2013-09-14 23:11 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-18 22:25 - 2013-09-14 23:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 20:44 - 2014-03-18 20:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\Program Files\iTunes 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\Program Files\iPod 2014-03-16 20:33 - 2014-03-16 20:33 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-16 12:36 - 2013-09-11 20:47 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-16 12:36 - 2013-09-11 20:47 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-14 17:22 - 2009-07-14 06:45 - 00292904 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 17:21 - 2013-09-15 11:53 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 17:21 - 2013-09-15 11:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 21:01 - 2014-03-12 20:56 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\com.onemrbean.soundodgerplus 2014-03-12 20:57 - 2014-03-12 20:56 - 00000000 ____D () C:\Users\Steffen\Documents\soundodger 2014-03-11 19:08 - 2013-09-11 19:19 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-03-09 20:23 - 2014-03-09 20:23 - 00000000 ____D () C:\ProgramData\Sun 2014-03-09 20:23 - 2014-03-09 20:23 - 00000000 ____D () C:\ProgramData\Oracle 2014-03-09 20:22 - 2014-03-09 20:22 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-03-09 20:22 - 2014-03-09 20:22 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-03-09 20:22 - 2014-03-09 20:22 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-03-09 20:22 - 2014-03-09 20:22 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-03-09 20:22 - 2014-03-09 20:22 - 00000000 ____D () C:\Program Files (x86)\Java Some content of TEMP: ==================== C:\Users\Steffen\AppData\Local\Temp\avgnt.exe C:\Users\Steffen\AppData\Local\Temp\devcon64.exe C:\Users\Steffen\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Steffen\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Steffen\AppData\Local\Temp\nvStInst.exe C:\Users\Steffen\AppData\Local\Temp\sonarinst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-30 13:24 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Steffen at 2014-04-07 20:48:14 Running from C:\Users\Steffen\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 140 (HKLM-x32\...\Steam App 242820) (Version: - Carlsen Games) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: - Igor Pavlov) 9.03m (HKLM-x32\...\Steam App 263100) (Version: - Space Budgie) A Virus Named TOM (HKLM-x32\...\Steam App 207650) (Version: - Misfits Attic) A.R.E.S. (HKLM-x32\...\Steam App 92300) (Version: - Extend Studio) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) And Yet It Moves (HKLM-x32\...\Steam App 18700) (Version: - Broken Rules) Angvik (HKLM-x32\...\Steam App 278890) (Version: - Alastair John Jack) Antichamber (HKLM-x32\...\Steam App 219890) (Version: - Alexander Bruce) Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.) Assassin's Creed II (HKLM-x32\...\Steam App 33230) (Version: - Ubisoft Montreal) ASUS Xonar U7 Audio (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F39206632A}) (Version: - ASUSTeK Computer Inc.) Atom Zombie Smasher (HKLM-x32\...\Steam App 55040) (Version: - Blendo Games) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: - Avira) Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: - APN, LLC) Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games) Bad Bots (HKLM-x32\...\Steam App 235070) (Version: - Point Five Projects) Ballpoint Universe: Infinite (HKLM-x32\...\Steam App 259390) (Version: - Arachnid Games) Bastion (HKLM-x32\...\Steam App 107100) (Version: - Supergiant Games) Batman: Arkham Asylum GOTY Edition (HKLM-x32\...\Steam App 35140) (Version: - Rocksteady Studios) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Beatbuddy: Tale of the Guardians (HKLM-x32\...\Steam App 231040) (Version: - Threaks) BioShock (HKLM-x32\...\Steam App 7670) (Version: - 2K Boston) BioShock 2 (HKLM-x32\...\Steam App 8850) (Version: - 2K Marin) BIT.TRIP Presents... Runner2: Future Legend of Rhythm Alien (HKLM-x32\...\Steam App 218060) (Version: - Gaijin Games) BIT.TRIP RUNNER (HKLM-x32\...\Steam App 63710) (Version: - Gaijin Games) Blood of the Werewolf (HKLM-x32\...\Steam App 260250) (Version: - Scientifically Proven) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.) Botanicula (HKLM-x32\...\Steam App 207690) (Version: - Amanita Design) Braid (HKLM-x32\...\Steam App 26800) (Version: - Number None) Brothers - A Tale of Two Sons (HKLM-x32\...\Steam App 225080) (Version: - Starbreeze Studios AB) Brütal Legend (HKLM-x32\...\Steam App 225260) (Version: - Double Fine Productions) Call of Juarez Gunslinger (HKLM-x32\...\Steam App 204450) (Version: - Techland) Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - ) Capsized (HKLM-x32\...\Steam App 95300) (Version: - Alientrap Games Inc) Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version: - Torn Banner Studios) Cook, Serve, Delicious! (HKLM-x32\...\Steam App 247020) (Version: - Vertigo Gaming) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CPUID CPU-Z 1.67.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.23 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Darwinia (HKLM-x32\...\Steam App 1500) (Version: - Introversion Software) Dear Esther (HKLM-x32\...\Steam App 203810) (Version: - thechineseroom & Robert Briscoe) Desktop Dungeons (HKLM-x32\...\Steam App 226620) (Version: - QCF Design) Deus Ex: Game of the Year Edition (HKLM-x32\...\Steam App 6910) (Version: - Ion Storm) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) DiRT 3 (HKLM-x32\...\Steam App 44320) (Version: - Codemasters Racing Studio) Dishonored (HKLM-x32\...\Steam App 205100) (Version: - Arkane Studios) Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.17 - Dolby Laboratories Inc) Don't Starve (HKLM-x32\...\Steam App 219740) (Version: - Klei Entertainment) Dream (HKLM-x32\...\Steam App 229580) (Version: - HyperSloth) DuckTales Remastered (HKLM-x32\...\Steam App 237630) (Version: - WayForward) Duke Nukem 3D: Megaton Edition (HKLM-x32\...\Steam App 225140) (Version: - 3D Realms) Dungeons of Dredmor (HKLM-x32\...\Steam App 98800) (Version: - Gaslamp Games, Inc.) Dust: An Elysian Tail (HKLM-x32\...\Steam App 236090) (Version: - Humble Hearts LLC) Dustforce (HKLM-x32\...\Steam App 65300) (Version: - Hitbox Team) Eldritch (HKLM-x32\...\Steam App 252630) (Version: - Minor Key Games) Element4l (HKLM-x32\...\Steam App 235820) (Version: - I-Illusions) English Country Tune (HKLM-x32\...\Steam App 207570) (Version: - increpare games) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai) Fist Puncher (HKLM-x32\...\Steam App 238630) (Version: - Team2Bit) Foul Play (HKLM-x32\...\Steam App 244810) (Version: - ) Fraps (HKLM-x32\...\Fraps) (Version: - ) Frozen Synapse (HKLM-x32\...\Steam App 98200) (Version: - Mode 7) FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version: - Subset Games) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Giana Sisters: Twisted Dreams - Rise of the Owlverlord (HKLM-x32\...\Steam App 246960) (Version: - Black Forest Games) Giana Sisters: Twisted Dreams (HKLM-x32\...\Steam App 223220) (Version: - Black Forest Games) Gone Home (HKLM-x32\...\Steam App 232430) (Version: - The Fullbright Company) GRID 2 (HKLM-x32\...\Steam App 44350) (Version: - Codemasters Racing) Guacamelee! Gold Edition (HKLM-x32\...\Steam App 214770) (Version: - DrinkBox Studios) Gun Monkeys (HKLM-x32\...\Steam App 239450) (Version: - Size Five Games) Gunpoint (HKLM-x32\...\Steam App 206190) (Version: - Suspicious Developments) Hack, Slash, Loot (HKLM-x32\...\Steam App 207430) (Version: - David Williamson) Half-Life (HKLM-x32\...\Steam App 70) (Version: - Valve) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Hammerwatch (HKLM-x32\...\Steam App 239070) (Version: - ) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive) Home (HKLM-x32\...\Steam App 215670) (Version: - Benjamin Rivers) Hotline Miami (HKLM-x32\...\Steam App 219150) (Version: - Dennaton Games) Incredipede (HKLM-x32\...\Steam App 230150) (Version: - Colin Northway with art by Thomas Shahan) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.27.798.1 - Intel Corporation) Hidden Intrusion 2 (HKLM-x32\...\Steam App 214970) (Version: - Aleksey Abramenko) Ironclad Tactics (HKLM-x32\...\Steam App 226960) (Version: - Zachtronics) Ittle Dew (HKLM-x32\...\Steam App 241320) (Version: - Ludosity) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: - Apple Inc.) Jamestown (HKLM-x32\...\Steam App 94200) (Version: - Final Form Games) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Kairo (HKLM-x32\...\Steam App 233230) (Version: - Richard Perrin) Kentucky Route Zero (HKLM-x32\...\Steam App 231200) (Version: - Cardboard Computer) Knights of Pen and Paper +1 (HKLM-x32\...\Steam App 231740) (Version: - Behold Studios) La-Mulana (HKLM-x32\...\Steam App 230700) (Version: - NIGORO) Legend of Dungeon (HKLM-x32\...\Steam App 238280) (Version: - ) LIMBO (HKLM-x32\...\Steam App 48000) (Version: - Playdead) Little Inferno (HKLM-x32\...\Steam App 221260) (Version: - Tomorrow Corporation) Lost Planet 2 (HKLM-x32\...\Steam App 45750) (Version: - CAPCOM CO., LTD.) Lost Planet: Extreme Condition - Colonies Edition (HKLM-x32\...\Steam App 45720) (Version: - CAPCOM CO., LTD.) Luxuria Superbia (HKLM-x32\...\Steam App 269150) (Version: - Tale of Tales) Magic 2014 (HKLM-x32\...\Steam App 213850) (Version: - Stainless Games) Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version: - Klei Entertainment) Max Payne (HKLM-x32\...\Steam App 12140) (Version: - Remedy Entertainment) Max Payne 2: The Fall of Max Payne (HKLM-x32\...\Steam App 12150) (Version: - Remedy Entertainment) Max Payne 3 (HKLM-x32\...\Steam App 204100) (Version: - Rockstar Studios) McPixel (HKLM-x32\...\Steam App 220860) (Version: - Sos) Megabyte Punch (HKLM-x32\...\Steam App 248550) (Version: - Reptile Games) Mercenary Kings (HKLM-x32\...\Steam App 218820) (Version: - Tribute Games Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: - Microsoft) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) MirrorMoon EP (HKLM-x32\...\Steam App 231310) (Version: - Santa Ragione) MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) Multiwinia (HKLM-x32\...\Steam App 1530) (Version: - Introversion Software) Natural Selection 2 (HKLM-x32\...\Steam App 4920) (Version: - Unknown Worlds Entertainment) Nidhogg (HKLM-x32\...\Steam App 94400) (Version: - Messhof) Nihilumbra (HKLM-x32\...\Steam App 252670) (Version: - Beautifun Games) NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Orcs Must Die! (HKLM-x32\...\Steam App 102600) (Version: - Robot Entertainment) Orcs Must Die! 2 (HKLM-x32\...\Steam App 201790) (Version: - Robot Entertainment) Organ Trail: Director's Cut (HKLM-x32\...\Steam App 233740) (Version: - The Men Who Wear Many Hats) Origin (HKLM-x32\...\Origin) (Version: - Electronic Arts, Inc.) Papo & Yo (HKLM-x32\...\Steam App 227080) (Version: - Minority Media Inc.) Paranautical Activity (HKLM-x32\...\Steam App 250580) (Version: - Code Avarice) Pid (HKLM-x32\...\Steam App 218740) (Version: - Might and Delight) Pinball FX2 (HKLM-x32\...\Steam App 226980) (Version: - Zen Studios) PixelJunk Eden (HKLM-x32\...\Steam App 105800) (Version: - Q-Games, Ltd.) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) Proteus (HKLM-x32\...\Steam App 219680) (Version: - Ed Key and David Kanaga) Psychonauts (HKLM-x32\...\Steam App 3830) (Version: - Double Fine Productions) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Qualcomm Atheros Killer Network Manager (HKLM-x32\...\InstallShield_{DF446558-ADF7-4884-9B2D-281979CCE71F}) (Version: - Qualcomm Atheros) Qualcomm Atheros Killer Network Manager (Version: - Qualcomm Atheros) Hidden Race The Sun (HKLM-x32\...\Steam App 253030) (Version: - Flippfly LLC) RAGE (HKLM-x32\...\Steam App 9200) (Version: - id Software) Rapture3D 2.4.8 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.17.22 - Razer Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Receiver (HKLM-x32\...\Steam App 234190) (Version: - Wolfire Games) Red Faction: Armageddon (HKLM-x32\...\Steam App 55110) (Version: - Volition) Red Faction: Guerrilla (HKLM-x32\...\Steam App 20500) (Version: - Volition) Remember Me (HKLM-x32\...\Steam App 228300) (Version: - DONTNOD Entertainment) Retro City Rampage™ (HKLM-x32\...\Steam App 204630) (Version: - Vblank Entertainment, Inc.) Reus (HKLM-x32\...\Steam App 222730) (Version: - Abbey Games) Revenge of the Titans (HKLM-x32\...\Steam App 93200) (Version: - Puppygames) Rise of the Triad (HKLM-x32\...\Steam App 217140) (Version: - Interceptor Entertainment) Risk of Rain (HKLM-x32\...\Steam App 248820) (Version: - ) Rocketbirds: Hardboiled Chicken (HKLM-x32\...\Steam App 215510) (Version: - Ratloop Asia) Rogue Legacy (HKLM-x32\...\Steam App 241600) (Version: - Cellar Door Games) Rush Bros (HKLM-x32\...\Steam App 234490) (Version: - XYLA Entertainment) Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.3.0 - Samsung Electronics) Scribblenauts Unlimited (HKLM-x32\...\Steam App 218680) (Version: - 5th Cell Media) Serious Sam 3: BFE (HKLM-x32\...\Steam App 41070) (Version: - Croteam) Serious Sam HD: The First Encounter (HKLM-x32\...\Steam App 41000) (Version: - Croteam) Serious Sam HD: The Second Encounter (HKLM-x32\...\Steam App 41010) (Version: - Croteam) Shadow Warrior (HKLM-x32\...\Steam App 233130) (Version: - Flying Wild Hog) Shadow Warrior Classic Redux (HKLM-x32\...\Steam App 225160) (Version: - 3D Realms) Shadowrun Returns (HKLM-x32\...\Steam App 234650) (Version: - Harebrained Schemes) Shank 2 (HKLM-x32\...\Steam App 102840) (Version: - Klei Entertainment) Shelter (HKLM-x32\...\Steam App 244710) (Version: - Might and Delight) SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden Sir, You Are Being Hunted (HKLM-x32\...\Steam App 242880) (Version: - ) Skulls of the Shogun (HKLM-x32\...\Steam App 228960) (Version: - 17-BIT) Sleeping Dogs™ (HKLM-x32\...\Steam App 202170) (Version: - United Front Games) Soundodger+ (HKLM-x32\...\Steam App 247140) (Version: - Studio Bean) SpaceChem (HKLM-x32\...\Steam App 92800) (Version: - Zachtronics) Spec Ops: The Line (HKLM-x32\...\Steam App 50300) (Version: - Yager) Spelunky (HKLM-x32\...\Steam App 239350) (Version: - ) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: - Valve Corporation) Steam Marines (HKLM-x32\...\Steam App 253630) (Version: - ) Super Hexagon (HKLM-x32\...\Steam App 221640) (Version: - Terry Cavanagh) Superbrothers: Sword & Sworcery EP (HKLM-x32\...\Steam App 204060) (Version: - Capybara) Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.018 - MSI) Sword of the Stars: The Pit (HKLM-x32\...\Steam App 233700) (Version: - Kerberos Productions) System Shock 2 (HKLM-x32\...\Steam App 238210) (Version: - Irrational Games) Talisman: Prologue (HKLM-x32\...\Steam App 258200) (Version: - ) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) Teleglitch: Die More Edition (HKLM-x32\...\Steam App 234390) (Version: - Test3 Projects) The Banner Saga: Factions (HKLM-x32\...\Steam App 219340) (Version: - Stoic) The Basement Collection (HKLM-x32\...\Steam App 214790) (Version: - Edmund McMillen, Tyler Glaiel) The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl) The Cave (HKLM-x32\...\Steam App 221810) (Version: - Double Fine Productions) The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: - Zenimax Online Studios) The Lord of the Rings: War in the North (HKLM-x32\...\Steam App 32800) (Version: - Snowblind Studios) The Showdown Effect (HKLM-x32\...\Steam App 204080) (Version: - Arrowhead Game Studios) The Stanley Parable (HKLM-x32\...\Steam App 221910) (Version: - Galactic Cafe) The Swapper (HKLM-x32\...\Steam App 231160) (Version: - Olli Harjola, Otto Hantula, Tom Jubert, Carlo Castellano) The Walking Dead (HKLM-x32\...\Steam App 207610) (Version: - ) The Walking Dead: Season Two (HKLM-x32\...\Steam App 261030) (Version: - Telltale Games) They Bleed Pixels (HKLM-x32\...\Steam App 211260) (Version: - Spooky Squid Games Inc.) Thief 2 (HKLM-x32\...\Steam App 211740) (Version: - Looking Glass Studios) Thief Gold (HKLM-x32\...\Steam App 211600) (Version: - Looking Glass Studios) Thief: Deadly Shadows (HKLM-x32\...\Steam App 6980) (Version: - Ion Storm) Thirty Flights of Loving (HKLM-x32\...\Steam App 214700) (Version: - Blendo Games) Tiny and Big: Grandpa's Leftovers (HKLM-x32\...\Steam App 205910) (Version: - Black Pants Game Studio) Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics) TP-LINK 300Mbps Wireless USB Adapter Treiber (HKLM-x32\...\{852E893E-E4FD-45BB-8B17-72ADDF686974}) (Version: 1.3.1 - TP-LINK) TRAUMA (HKLM-x32\...\Steam App 98100) (Version: - Krystian Majewski) Trials Evolution Gold Edition (HKLM-x32\...\Steam App 220160) (Version: - Redlynx Ltd) Trine (HKLM-x32\...\Steam App 35700) (Version: - Frozenbyte) Trine 2 (HKLM-x32\...\Steam App 35720) (Version: - Frozenbyte) Two Brothers (HKLM-x32\...\Steam App 259760) (Version: - Ackk Studios) Type:Rider (HKLM-x32\...\Steam App 258890) (Version: - Ex Nihilo) Unepic (HKLM-x32\...\Steam App 233980) (Version: - Francisco Téllez de Meneses) Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) Uplink (HKLM-x32\...\Steam App 1510) (Version: - Introversion Software) Vampire: The Masquerade - Bloodlines (HKLM-x32\...\Steam App 2600) (Version: - Troika Games) Velvet Assassin (HKLM-x32\...\Steam App 16720) (Version: - Replay Studios) Vessel (HKLM-x32\...\Steam App 108500) (Version: - Strange Loop Games) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Waking Mars (HKLM-x32\...\Steam App 227200) (Version: - Tiger Style) WildStar (HKLM-x32\...\WildStar) (Version: - NCSOFT) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version: - Firaxis Games) Zeno Clash (HKLM-x32\...\Steam App 22200) (Version: - ACE Team) ==================== Restore Points ========================= 13-03-2014 19:34:40 Windows Update 18-03-2014 16:59:21 Windows Update 18-03-2014 20:25:13 Windows Update 25-03-2014 16:28:07 Windows Update 30-03-2014 19:21:05 DirectX wurde installiert 01-04-2014 15:22:21 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {42797E80-8BF4-44A9-A53B-BB53D2D7D221} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-14] (Intel Corporation) Task: {BE68B616-38B3-4716-A922-4602E4D84E3E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {EE8D0F27-7B00-4921-8B33-58CD0D4BDA64} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-14] (Intel Corporation) ==================== Loaded Modules (whitelisted) ============= 2013-09-11 19:20 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-12-21 19:36 - 2013-05-03 15:55 - 02453504 ____N () C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe 2014-02-25 20:32 - 2014-02-25 20:32 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2013-04-11 11:54 - 2013-04-11 11:54 - 00490496 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe 2011-05-09 20:46 - 2011-05-09 20:46 - 02760192 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtCore4.dll 2011-05-09 20:56 - 2011-05-09 20:56 - 09856000 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtGui4.dll 2011-05-09 20:47 - 2011-05-09 20:47 - 00416256 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtXml4.dll 2013-04-11 11:54 - 2013-04-11 11:54 - 00217600 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFCommon.dll 2011-05-10 12:32 - 2011-05-10 12:32 - 00731648 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\qwt5.dll 2011-05-09 20:48 - 2011-05-09 20:48 - 00990720 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtNetwork4.dll 2013-09-11 19:38 - 2013-09-11 19:37 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-09-11 19:13 - 2013-03-12 22:20 - 01199576 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-03-29 13:35 - 2014-03-29 13:35 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Qualcomm Atheros Killer Network Manager.lnk => C:\Windows\pss\Qualcomm Atheros Killer Network Manager.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Steffen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Samsung Magician.lnk => C:\Windows\pss\Samsung Magician.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: ApnTBMon => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/07/2014 05:20:36 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/06/2014 11:43:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/05/2014 02:56:53 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (04/05/2014 00:36:00 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (04/05/2014 11:30:04 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/04/2014 05:18:04 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/04/2014 05:16:28 PM) (Source: Bonjour Service) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 13 PTR Space.local. Error: (04/04/2014 05:16:28 PM) (Source: Bonjour Service) (User: ) Description: mDNSCoreReceiveResponse: Received from 15 PTR Space-2.local. Error: (04/03/2014 08:31:02 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (04/03/2014 06:11:14 PM) (Source: Application Hang) (User: ) Description: Programm Diablo III.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: b2c Startzeit: 01cf4f575082a79e Endzeit: 1 Anwendungspfad: D:\Battlenet\Diablo III\Diablo III.exe Berichts-ID: 92f16fef-bb4a-11e3-aca0-d43d7edac312 System errors: ============= Error: (04/07/2014 05:19:57 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (04/07/2014 05:18:56 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (04/06/2014 11:43:13 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (04/06/2014 11:42:12 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (04/05/2014 09:21:44 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (04/05/2014 09:21:42 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (04/05/2014 09:21:39 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (04/05/2014 09:21:36 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (04/05/2014 09:21:33 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Error: (04/05/2014 09:21:31 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk2\DR2. Microsoft Office Sessions: ========================= Error: (04/07/2014 05:20:36 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/06/2014 11:43:52 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/05/2014 02:56:53 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (04/05/2014 00:36:00 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (04/05/2014 11:30:04 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/04/2014 05:18:04 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/04/2014 05:16:28 PM) (Source: Bonjour Service)(User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 13 PTR Space.local. Error: (04/04/2014 05:16:28 PM) (Source: Bonjour Service)(User: ) Description: mDNSCoreReceiveResponse: Received from 15 PTR Space-2.local. Error: (04/03/2014 08:31:02 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (04/03/2014 06:11:14 PM) (Source: Application Hang)(User: ) Description: Diablo III.exe2.0.3.22427b2c01cf4f575082a79e1D:\Battlenet\Diablo III\Diablo III.exe92f16fef-bb4a-11e3-aca0-d43d7edac312 ==================== Memory info =========================== Percentage of memory in use: 31% Total physical RAM: 8135.95 MB Available physical RAM: 5552.94 MB Total Pagefile: 8334.13 MB Available Pagefile: 5844.75 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:111.69 GB) (Free:66.55 GB) NTFS Drive d: (Data) (Fixed) (Total:931.51 GB) (Free:349.46 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: D32FDF6A) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 9E54E4BD) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() BSI Sicherheitstest Positiv Hi,
__________________Rechner ist sauber. Passwörter ändern und gut is ![]()
__________________ |
