Hallo schrauber,
vielen Dank für die schnelle Antwort. Hier die von dir gewünschten Logdaten:
Additional Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-08-2013
Ran by Infar at 2013-08-17 12:12:29
Running from C:\Users\Infar\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
AMD Accelerated Video Transcoding (Version: 12.10.100.30328)
AMD Catalyst Install Manager (Version: 8.0.911.0)
AMD Media Foundation Decoders (Version: 1.0.80328.2204)
avast! Free Antivirus (x32 Version: 7.0.1474.0)
Bluetooth Win7 Suite (64) (Version: 7.2.0.40)
Canon Easy-PhotoPrint EX (x32)
Canon IJ Network Scanner Selector EX (x32)
Canon IJ Network Tool (x32)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32)
Canon MG5300 series MP Drivers
Canon My Printer (x32)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center InstallProxy (x32 Version: 2012.0611.1251.21046)
Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225)
CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225)
CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225)
CCC Help Czech (x32 Version: 2013.0328.2217.38225)
CCC Help Danish (x32 Version: 2013.0328.2217.38225)
CCC Help Dutch (x32 Version: 2013.0328.2217.38225)
CCC Help English (x32 Version: 2013.0328.2217.38225)
CCC Help Finnish (x32 Version: 2013.0328.2217.38225)
CCC Help French (x32 Version: 2013.0328.2217.38225)
CCC Help German (x32 Version: 2013.0328.2217.38225)
CCC Help Greek (x32 Version: 2013.0328.2217.38225)
CCC Help Hungarian (x32 Version: 2013.0328.2217.38225)
CCC Help Italian (x32 Version: 2013.0328.2217.38225)
CCC Help Japanese (x32 Version: 2013.0328.2217.38225)
CCC Help Korean (x32 Version: 2013.0328.2217.38225)
CCC Help Norwegian (x32 Version: 2013.0328.2217.38225)
CCC Help Polish (x32 Version: 2013.0328.2217.38225)
CCC Help Portuguese (x32 Version: 2013.0328.2217.38225)
CCC Help Russian (x32 Version: 2013.0328.2217.38225)
CCC Help Spanish (x32 Version: 2013.0328.2217.38225)
CCC Help Swedish (x32 Version: 2013.0328.2217.38225)
CCC Help Thai (x32 Version: 2013.0328.2217.38225)
CCC Help Turkish (x32 Version: 2013.0328.2217.38225)
ccc-utility64 (Version: 2013.0328.2218.38225)
Company of Heroes 2 (x32)
DAEMON Tools Lite (x32 Version: 4.40.2.0131)
Divinity: Dragon Commander (x32 Version: 1)
Dota 2 (x32)
eaner (Version: 3.02)
erLT (x32 Version: 1.20.0137)
FlashFXP (x32 Version: 4.3.0.1904)
FlashFXP 4.3.0.1904 (x32 Version: 4.3.0.1904)
ImgBurn (x32 Version: 2.5.5.0)
IrfanView (remove only) (x32 Version: 4.32)
Java 7 Update 21 (x32 Version: 7.0.210)
Java Auto Updater (x32 Version: 2.1.9.5)
Logitech G11 Keyboard Software 1.03 (Version: 1.3.166.0)
Logitech Harmony Remote Software (x86) (x32 Version: 2.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
marvell 91xx console driver (x32 Version: 1.0.0.1045)
MechWarrior Online (x32 Version: 1.4.1.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (x32 Version: 4.20.9818.0)
NVIDIA Install Application (Version: 2.1002.62.312)
OpenOffice.org 3.3 (x32 Version: 3.3.9567)
Origin (x32 Version: 9.1.13.85)
Realtek Ethernet Controller Driver (x32 Version: 7.31.1025.2010)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6235)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0)
Sid Meier's Civilization V Brave New World (x32 Version: 1)
Skype™ 5.10 (x32 Version: 5.10.116)
Steam (x32 Version: 1.0.0.0)
SumatraPDF (x32 Version: 1.9)
System Requirements Lab for Intel (x32 Version: 4.5.5.0)
TeamSpeak 3 Client (Version: 3.0.11.1)
Ulead PhotoImpact 12 (x32 Version: 12.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
VLC media player 2.0.4 (Version: 2.0.4)
WinRAR
==================== Restore Points =========================
14-08-2013 13:03:53 Windows Update
14-08-2013 18:39:02 Windows Update
==================== Hosts content: ==========================
2013-08-17 11:17 - 2013-08-17 11:18 - 00000025 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {01F12F72-6552-4D69-862E-DA9856A19B8D} - System32\Tasks\9625c7e0 => C:\Users\Infar\AppData\Local\Temp\\setup1280905984.exe No File
Task: {17CE7C73-0917-4449-9262-63F9216A605E} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {1E68A066-1766-4FA5-919C-C2095E778786} - System32\Tasks\fc55d6c0 => C:\Users\Infar\AppData\Local\Temp\\setup3322390240.exe No File
Task: {267C20B3-8062-4AAC-A8A0-049433939B11} - System32\Tasks\User_Feed_Synchronization-{E32FF8B6-3DA1-40CE-9FEC-BE9BD0085B0F} => C:\Windows\system32\msfeedssync.exe [2013-04-02] (Microsoft Corporation)
Task: {26F9F759-4111-4C6A-A465-B373BFAC0D8E} - System32\Tasks\c20c4a00 => C:\Users\Infar\AppData\Local\Temp\\setup3092055936.exe No File
Task: {33489E1B-29BA-4FD3-8AB0-244B576A1C27} - System32\Tasks\e52f9740 => C:\Users\Infar\AppData\Local\Temp\\setup3004092320.exe No File
Task: {3AFE7A13-A293-4F31-BBC3-0B00EDB8CD40} - System32\Tasks\68b11ec0 => C:\Users\Infar\AppData\Local\Temp\\setup1546186528.exe No File
Task: {3F0D9AED-91CE-48AB-B909-414F9B1B1CE7} - System32\Tasks\59cfc740 => C:\Users\Infar\AppData\Local\Temp\\setup1273175168.exe No File
Task: {69305CED-2633-4C7B-87E8-F73C9BD09A96} - System32\Tasks\b95ef480 => C:\Users\Infar\AppData\Local\Temp\\setup2152194208.exe No File
Task: {6CB6A6E2-2D44-4F76-9874-5792760B6749} - System32\Tasks\385c8bc0 => C:\Users\Infar\AppData\Local\Temp\\setup455001152.exe No File
Task: {7ABA8DD1-B35C-4A36-A46B-83182D0559A2} - System32\Tasks\64adbf40 => C:\Users\Infar\AppData\Local\Temp\\setup778016896.exe No File
Task: {83416F08-FBA6-4917-A50F-7F0CDB5A5B52} - System32\Tasks\a1945f00 => C:\Users\Infar\AppData\Local\Temp\\setup2477241408.exe No File
Task: {8FA7EF5C-C4A9-410C-B456-5AA48DD63459} - System32\Tasks\c9a238a0 => C:\Users\Infar\AppData\Local\Temp\\setup2144701664.exe No File
Task: {961285AB-8BA3-46C7-8676-5D60980C3746} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-10-31] (AVAST Software)
Task: {9F8CC47E-3CDE-4A21-8807-24CB510743B2} - System32\Tasks\{F2C16F8C-53CC-49B0-8DE3-102A0D9D93E3} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.)
Task: {BB79EA4E-B064-406B-B5A2-FDC59666FA9E} - System32\Tasks\d77f9220 => C:\Users\Infar\AppData\Local\Temp\\setup2727730528.exe No File
Task: {C960F8EE-304C-42FA-947B-BAAF38459912} - System32\Tasks\7a727260 => C:\Users\Infar\AppData\Local\Temp\\setup3522564512.exe No File
Task: {D2F9C5B8-CA86-4712-A7CA-27B0D6F97C1D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: {D88CB77E-C9B0-40BA-BF28-69C5423556C2} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {E3B4099A-63F1-4DCE-8DD2-56F24013BAC5} - System32\Tasks\10a885c0 => C:\Users\Infar\AppData\Local\Temp\\setup3733440320.exe No File
Task: {EAC93F13-0F1A-4517-8B9D-C14AE012A115} - System32\Tasks\1b3cb880 => C:\Users\Infar\AppData\Local\Temp\\setup3934284800.exe No File
Task: {F495F307-1CD7-41F3-8ED8-91BF0695AE21} - System32\Tasks\473b5de0 => C:\Users\Infar\AppData\Local\Temp\\setup400786272.exe No File
==================== Faulty Device Manager Devices =============
Name: ASUS Bluetooth
Description: ASUS Bluetooth
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Atheros Communications
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/11/2013 00:41:39 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: DCApp.exe, Version: 1.0.10.0, Zeitstempel: 0x51ffa3da
Name des fehlerhaften Moduls: CoreLib.dll, Version: 0.0.0.0, Zeitstempel: 0x51ff8d37
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005c1d0
ID des fehlerhaften Prozesses: 0x1174
Startzeit der fehlerhaften Anwendung: 0xDCApp.exe0
Pfad der fehlerhaften Anwendung: DCApp.exe1
Pfad des fehlerhaften Moduls: DCApp.exe2
Berichtskennung: DCApp.exe3
Error: (08/11/2013 10:24:17 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 23.0.0.4959, Zeitstempel: 0x51f84049
Name des fehlerhaften Moduls: xul.dll, Version: 23.0.0.4959, Zeitstempel: 0x51f83f58
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0015b268
ID des fehlerhaften Prozesses: 0xa68
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Error: (08/10/2013 09:11:59 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: DCApp.exe, Version: 1.0.10.0, Zeitstempel: 0x51ffa3da
Name des fehlerhaften Moduls: CoreLib.dll, Version: 0.0.0.0, Zeitstempel: 0x51ff8d37
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005c1d0
ID des fehlerhaften Prozesses: 0xa44
Startzeit der fehlerhaften Anwendung: 0xDCApp.exe0
Pfad der fehlerhaften Anwendung: DCApp.exe1
Pfad des fehlerhaften Moduls: DCApp.exe2
Berichtskennung: DCApp.exe3
Error: (06/29/2013 03:18:09 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: PlanetSide2.exe, Version: 0.0.0.0, Zeitstempel: 0x51ca248d
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x30363838
ID des fehlerhaften Prozesses: 0xe04
Startzeit der fehlerhaften Anwendung: 0xPlanetSide2.exe0
Pfad der fehlerhaften Anwendung: PlanetSide2.exe1
Pfad des fehlerhaften Moduls: PlanetSide2.exe2
Berichtskennung: PlanetSide2.exe3
Error: (06/09/2013 07:47:47 PM) (Source: BugSplat) (User: )
Description: coh2CoH293147
Error: (05/21/2013 07:31:17 PM) (Source: Application Hang) (User: )
Description: Programm MechWarriorOnline.exe, Version 1.2.10.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 85c
Startzeit: 01ce5644f417444d
Endzeit: 2
Anwendungspfad: C:\Program Files (x86)\Piranha Games\MechWarrior Online\Bin32\MechWarriorOnline.exe
Berichts-ID: b43c040a-c23a-11e2-94bd-bcaec5ab10ea
Error: (05/10/2013 09:01:56 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 20.0.1.4847, Zeitstempel: 0x51650aee
Name des fehlerhaften Moduls: xul.dll, Version: 20.0.1.4847, Zeitstempel: 0x51650a09
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000b10e8
ID des fehlerhaften Prozesses: 0xcf0
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Error: (04/30/2013 04:47:17 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 20.0.1.4847 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 648
Startzeit: 01ce45a67f2f3bfd
Endzeit: 32
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: cefa492c-b1a4-11e2-93e4-bcaec5ab10ea
Error: (02/09/2013 11:22:19 AM) (Source: Application Hang) (User: )
Description: Programm tbb-firefox.exe, Version 10.0.12.4752 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 6a0
Startzeit: 01ce06a5a04248c3
Endzeit: 31
Anwendungspfad: C:\Users\Infar\Downloads\Tor Browser\FirefoxPortable\App\Firefox\tbb-firefox.exe
Berichts-ID: 29aa24bb-729a-11e2-ad92-bcaec5ab10ea
Error: (01/26/2013 00:16:15 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: XComGame.exe, Version: 1.0.0.11052, Zeitstempel: 0x5075b2c5
Name des fehlerhaften Moduls: XComGame.exe, Version: 1.0.0.11052, Zeitstempel: 0x5075b2c5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x002dbe56
ID des fehlerhaften Prozesses: 0x528
Startzeit der fehlerhaften Anwendung: 0xXComGame.exe0
Pfad der fehlerhaften Anwendung: XComGame.exe1
Pfad des fehlerhaften Moduls: XComGame.exe2
Berichtskennung: XComGame.exe3
System errors:
=============
Error: (08/10/2013 08:19:19 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 10.08.2013 um 08:17:55 unerwartet heruntergefahren.
Error: (07/31/2013 04:20:29 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/31/2013 04:20:29 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.
Error: (07/28/2013 09:14:17 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error: (07/27/2013 04:00:19 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht.
Error: (07/16/2013 06:09:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (07/16/2013 06:09:52 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%50
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (07/16/2013 06:09:52 PM) (Source: DCOM) (User: )
Description: 1069upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56}
Error: (07/13/2013 02:36:45 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
Error: (07/12/2013 03:35:46 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 10.07.2013 um 18:39:44 unerwartet heruntergefahren.
Microsoft Office Sessions:
=========================
Error: (08/11/2013 00:41:39 PM) (Source: Application Error)(User: )
Description: DCApp.exe1.0.10.051ffa3daCoreLib.dll0.0.0.051ff8d37c00000050005c1d0117401ce967028cf7be8C:\Program Files (x86)\Divinity Dragon Commander\Shipping\DCApp.exeC:\Program Files (x86)\Divinity Dragon Commander\Shipping\CoreLib.dll9a331e50-0272-11e3-8daf-bcaec5ab10ea
Error: (08/11/2013 10:24:17 AM) (Source: Application Error)(User: )
Description: firefox.exe23.0.0.495951f84049xul.dll23.0.0.495951f83f58c00000050015b268a6801ce965a8f422133C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dll6938b6fd-025f-11e3-8daf-bcaec5ab10ea
Error: (08/10/2013 09:11:59 PM) (Source: Application Error)(User: )
Description: DCApp.exe1.0.10.051ffa3daCoreLib.dll0.0.0.051ff8d37c00000050005c1d0a4401ce95e6e6a98345C:\Program Files (x86)\Divinity Dragon Commander\Shipping\DCApp.exeC:\Program Files (x86)\Divinity Dragon Commander\Shipping\CoreLib.dllba8814f1-01f0-11e3-84c1-bcaec5ab10ea
Error: (06/29/2013 03:18:09 PM) (Source: Application Error)(User: )
Description: PlanetSide2.exe0.0.0.051ca248dunknown0.0.0.000000000c000000530363838e0401ce74c4f0ed4a4bC:\Program Files (x86)\Steam\steamapps\common\PlanetSide 2\PlanetSide2.exeunknown576a56ee-e0be-11e2-9287-bcaec5ab10ea
Error: (06/09/2013 07:47:47 PM) (Source: BugSplat)(User: )
Description: coh2CoH293147
Error: (05/21/2013 07:31:17 PM) (Source: Application Hang)(User: )
Description: MechWarriorOnline.exe1.2.10.085c01ce5644f417444d2C:\Program Files (x86)\Piranha Games\MechWarrior Online\Bin32\MechWarriorOnline.exeb43c040a-c23a-11e2-94bd-bcaec5ab10ea
Error: (05/10/2013 09:01:56 AM) (Source: Application Error)(User: )
Description: firefox.exe20.0.1.484751650aeexul.dll20.0.1.484751650a09c0000005000b10e8cf001ce4d4be6442dd2C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dll8032f548-b93f-11e2-bc5f-bcaec5ab10ea
Error: (04/30/2013 04:47:17 PM) (Source: Application Hang)(User: )
Description: firefox.exe20.0.1.484764801ce45a67f2f3bfd32C:\Program Files (x86)\Mozilla Firefox\firefox.execefa492c-b1a4-11e2-93e4-bcaec5ab10ea
Error: (02/09/2013 11:22:19 AM) (Source: Application Hang)(User: )
Description: tbb-firefox.exe10.0.12.47526a001ce06a5a04248c331C:\Users\Infar\Downloads\Tor Browser\FirefoxPortable\App\Firefox\tbb-firefox.exe29aa24bb-729a-11e2-ad92-bcaec5ab10ea
Error: (01/26/2013 00:16:15 PM) (Source: Application Error)(User: )
Description: XComGame.exe1.0.0.110525075b2c5XComGame.exe1.0.0.110525075b2c5c0000005002dbe5652801cdfba7e83c7142C:\Program Files (x86)\XCOM Enemy Unknown\Binaries\Win32\XComGame.exeC:\Program Files (x86)\XCOM Enemy Unknown\Binaries\Win32\XComGame.exe6a2b5865-67a1-11e2-aae5-bcaec5ab10ea
CodeIntegrity Errors:
===================================
Date: 2011-05-17 15:54:55.671
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\cofi\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2011-05-17 15:54:55.656
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\cofi\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 30%
Total physical RAM: 8168.77 MB
Available physical RAM: 5654.06 MB
Total Pagefile: 16335.72 MB
Available Pagefile: 13658.33 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.41 GB) (Free:596.7 GB) NTFS
Drive e: (Transcend) (Removable) (Total:29.44 GB) (Free:29.31 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 48605CD9)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 29 GB) (Disk ID: 66205247)
No partition Table on disk 1.
==================== End Of Log ============================
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2013
Ran by Infar (administrator) on 17-08-2013 12:11:57
Running from C:\Users\Infar\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
() C:\Windows\SysWOW64\PnkBstrA.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\system32\calc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11545192 2010-11-02] (Realtek Semiconductor)
HKLM\...\Run: [Launch LGDCore] - C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe [1783296 2006-07-23] (Logitech Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKLM-x32\...\Run: [avast] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [4297136 2012-10-31] (AVAST Software)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\avast! Free Antivirus.lnk
ShortcutTarget: avast! Free Antivirus.lnk -> C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
SearchScopes: HKCU - DefaultScope {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=ddr&s={searchTerms}&f=4
SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=ddr&s={searchTerms}&f=4
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: No Name - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Infar\AppData\Roaming\Mozilla\Firefox\Profiles\cmjaxt5e.default
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.0 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.102.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.104.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.116.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchddr.xml
FF Extension: No Name - C:\Users\Infar\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
FF Extension: Deutsches Wörterbuch - C:\Users\Infar\AppData\Roaming\Mozilla\Firefox\Profiles\cmjaxt5e.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: firefox - C:\Users\Infar\AppData\Roaming\Mozilla\Firefox\Profiles\cmjaxt5e.default\Extensions\firefox@ghostery.com.xpi
FF Extension: No Name - C:\Users\Infar\AppData\Roaming\Mozilla\Firefox\Profiles\cmjaxt5e.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\Infar\AppData\Roaming\Mozilla\Firefox\Profiles\cmjaxt5e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files (x86)\congstar\Internet-Manager\Bin\addon
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [44808 2012-10-31] (AVAST Software)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-02] ()
U4 avast! Firewall; "C:\Program Files\Alwil Software\Avast5\afwServ.exe" [x]
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-10-31] (AVAST Software)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21136 2012-10-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [71600 2012-10-31] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-10-15] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [984144 2012-10-31] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [370288 2012-10-31] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-05-20] (DT Soft Ltd)
S3 Ser2at; C:\Windows\System32\DRIVERS\ser2at64.sys [90112 2007-06-08] (Prolific Technology Inc.)
S3 catchme; \??\C:\cofi\catchme.sys [x]
S3 HSPADataCardusbmdm; system32\DRIVERS\HSPADataCardusbmdm.sys [x]
S3 HSPADataCardusbnmea; system32\DRIVERS\HSPADataCardusbnmea.sys [x]
S3 HSPADataCardusbser; system32\DRIVERS\HSPADataCardusbser.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
S4 NVHDA; system32\drivers\nvhda64v.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-17 11:53 - 2013-08-17 11:54 - 01575580 _____ (Farbar) C:\Users\Infar\Downloads\FRST64.exe
2013-08-17 11:22 - 2013-08-17 11:18 - 00000025 _____ C:\Users\Infar\Desktop\hosts.txt
2013-08-17 11:19 - 2013-08-17 11:20 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Infar\Downloads\spybotsd-2.1.21-SR2.exe
2013-08-14 20:44 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 20:44 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 20:44 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 20:44 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 20:44 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 20:44 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 20:44 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 20:44 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 20:44 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 20:44 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 20:44 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 20:44 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 20:44 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 20:44 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 20:40 - 2013-08-14 20:41 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 15:07 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 15:07 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 15:07 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 15:07 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 15:07 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 15:07 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 15:07 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 15:07 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 15:07 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 15:07 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 15:07 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 15:07 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 15:07 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 15:07 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 15:07 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 15:07 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 15:07 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 15:07 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 15:07 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 15:07 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 15:07 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 15:07 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 15:07 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 15:07 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 15:07 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 15:07 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 15:07 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-11 12:52 - 2013-08-17 10:17 - 00000336 _____ C:\Windows\setupact.log
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 _____ C:\Windows\setuperr.log
2013-08-11 08:49 - 2013-08-11 08:51 - 17737608 _____ (Adobe Systems Incorporated) C:\Users\Infar\Downloads\install_flash_player.exe
2013-08-10 18:30 - 2013-08-10 18:30 - 00000428 _____ C:\Users\Infar\Documents\telemetry.lsx
2013-08-10 18:30 - 2013-08-10 18:30 - 00000000 ____D C:\Users\Infar\Documents\Larian Studios
2013-08-10 18:23 - 2013-08-10 18:23 - 00001014 _____ C:\Users\Public\Desktop\Divinity Dragon Commander.lnk
2013-08-10 18:09 - 2013-08-10 18:23 - 00000000 ____D C:\Program Files (x86)\Divinity Dragon Commander
2013-08-10 17:59 - 2013-08-07 23:06 - 450856960 _____ C:\Users\Infar\Downloads\de-didra.iso
2013-08-03 12:14 - 2013-08-03 13:37 - 00001666 _____ C:\Users\Infar\Desktop\Neues Textdokument.txt
2013-07-27 10:51 - 2013-07-27 10:51 - 00000000 ____D C:\Users\Infar\AppData\Local\My Games
2013-07-27 10:51 - 2013-07-27 10:51 - 00000000 ____D C:\ProgramData\Steam
2013-07-27 10:31 - 2013-07-27 10:31 - 00001028 _____ C:\Users\Public\Desktop\Sid Meier's Civilization V Brave New World.lnk
2013-07-27 10:23 - 2013-07-27 10:33 - 00000000 ____D C:\Program Files (x86)\Sid Meier's Civilization V Brave New World
2013-07-25 18:03 - 2013-07-25 18:03 - 00000219 _____ C:\Users\Infar\Desktop\Dota 2.url
2013-07-21 13:30 - 2013-07-21 13:40 - 00000000 ____D C:\Users\Infar\Desktop\Nwllgfd
2013-07-21 13:12 - 2013-07-21 13:31 - 00000000 ____D C:\Users\Infar\Desktop\garnelenverkauf
2013-07-21 10:42 - 2013-07-21 10:42 - 00000906 _____ C:\Users\Infar\Desktop\Tor.lnk
2013-07-21 10:42 - 2013-06-24 04:50 - 00000000 ____D C:\Users\Infar\Downloads\Tor Browser
==================== One Month Modified Files and Folders =======
2013-08-17 12:11 - 2013-08-17 12:11 - 00000000 ____D C:\FRST
2013-08-17 11:54 - 2013-08-17 11:53 - 01575580 _____ (Farbar) C:\Users\Infar\Downloads\FRST64.exe
2013-08-17 11:32 - 2011-01-20 19:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-17 11:23 - 2012-01-15 19:45 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-17 11:23 - 2011-05-22 09:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-17 11:20 - 2013-08-17 11:19 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\Infar\Downloads\spybotsd-2.1.21-SR2.exe
2013-08-17 11:18 - 2013-08-17 11:22 - 00000025 _____ C:\Users\Infar\Desktop\hosts.txt
2013-08-17 10:24 - 2009-07-14 06:45 - 00013424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-17 10:24 - 2009-07-14 06:45 - 00013424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-17 10:22 - 2012-05-08 21:01 - 01483106 _____ C:\Windows\WindowsUpdate.log
2013-08-17 10:21 - 2011-01-21 19:21 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E32FF8B6-3DA1-40CE-9FEC-BE9BD0085B0F}
2013-08-17 10:17 - 2013-08-11 12:52 - 00000336 _____ C:\Windows\setupact.log
2013-08-17 10:17 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-15 20:58 - 2011-07-14 15:03 - 00000000 ____D C:\Users\Infar\AppData\Roaming\TS3Client
2013-08-15 20:50 - 2012-12-13 17:58 - 00000000 ____D C:\Users\Infar\AppData\Roaming\vlc
2013-08-15 20:50 - 2012-10-10 18:29 - 00000000 ____D C:\Program Files (x86)\Steam
2013-08-14 20:42 - 2009-07-14 19:58 - 00696832 _____ C:\Windows\system32\perfh007.dat
2013-08-14 20:42 - 2009-07-14 19:58 - 00148128 _____ C:\Windows\system32\perfc007.dat
2013-08-14 20:42 - 2009-07-14 07:13 - 01634396 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-14 20:41 - 2013-08-14 20:40 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 20:40 - 2011-02-25 21:45 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 _____ C:\Windows\setuperr.log
2013-08-11 12:41 - 2012-08-07 21:49 - 00000000 ____D C:\Users\Infar\AppData\Local\CrashDumps
2013-08-11 10:24 - 2012-12-23 13:35 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-11 10:24 - 2012-12-23 13:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-11 08:51 - 2013-08-11 08:49 - 17737608 _____ (Adobe Systems Incorporated) C:\Users\Infar\Downloads\install_flash_player.exe
2013-08-10 18:30 - 2013-08-10 18:30 - 00000428 _____ C:\Users\Infar\Documents\telemetry.lsx
2013-08-10 18:30 - 2013-08-10 18:30 - 00000000 ____D C:\Users\Infar\Documents\Larian Studios
2013-08-10 18:23 - 2013-08-10 18:23 - 00001014 _____ C:\Users\Public\Desktop\Divinity Dragon Commander.lnk
2013-08-10 18:23 - 2013-08-10 18:09 - 00000000 ____D C:\Program Files (x86)\Divinity Dragon Commander
2013-08-08 06:00 - 2011-11-18 21:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbirt
2013-08-07 23:06 - 2013-08-10 17:59 - 450856960 _____ C:\Users\Infar\Downloads\de-didra.iso
2013-08-07 16:04 - 2011-07-14 15:00 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-08-05 17:10 - 2012-07-26 16:43 - 00014821 _____ C:\Users\Infar\Documents\Signal Iduna dynamik.odt
2013-08-05 16:57 - 2012-10-28 11:50 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-08-04 17:40 - 2013-06-09 09:49 - 00000000 ____D C:\Users\Infar\Downloads\A_Filme
2013-08-04 10:16 - 2013-04-06 14:24 - 00000000 ____D C:\Users\Infar\Desktop\Season 03
2013-08-03 13:37 - 2013-08-03 12:14 - 00001666 _____ C:\Users\Infar\Desktop\Neues Textdokument.txt
2013-07-27 10:51 - 2013-07-27 10:51 - 00000000 ____D C:\Users\Infar\AppData\Local\My Games
2013-07-27 10:51 - 2013-07-27 10:51 - 00000000 ____D C:\ProgramData\Steam
2013-07-27 10:51 - 2012-12-16 13:30 - 00000000 ____D C:\Users\Infar\Documents\My Games
2013-07-27 10:33 - 2013-07-27 10:23 - 00000000 ____D C:\Program Files (x86)\Sid Meier's Civilization V Brave New World
2013-07-27 10:31 - 2013-07-27 10:31 - 00001028 _____ C:\Users\Public\Desktop\Sid Meier's Civilization V Brave New World.lnk
2013-07-26 07:13 - 2013-08-14 20:44 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 07:13 - 2013-08-14 20:44 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 07:13 - 2013-08-14 20:44 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 07:12 - 2013-08-14 20:44 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 07:12 - 2013-08-14 20:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 05:35 - 2013-08-14 20:44 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 05:13 - 2013-08-14 20:44 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-26 05:13 - 2013-08-14 20:44 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-26 05:12 - 2013-08-14 20:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-26 05:11 - 2013-08-14 20:44 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-26 05:11 - 2013-08-14 20:44 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-26 04:49 - 2013-08-14 20:44 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-26 04:39 - 2013-08-14 20:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-26 03:59 - 2013-08-14 20:44 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-25 18:03 - 2013-07-25 18:03 - 00000219 _____ C:\Users\Infar\Desktop\Dota 2.url
2013-07-25 18:03 - 2012-10-10 18:35 - 00000000 ____D C:\Users\Infar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-07-25 11:25 - 2013-08-14 15:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-21 13:40 - 2013-07-21 13:30 - 00000000 ____D C:\Users\Infar\Desktop\Nwllgfd
2013-07-21 13:31 - 2013-07-21 13:12 - 00000000 ____D C:\Users\Infar\Desktop\garnelenverkauf
2013-07-21 10:42 - 2013-07-21 10:42 - 00000906 _____ C:\Users\Infar\Desktop\Tor.lnk
2013-07-19 03:58 - 2013-08-14 15:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-07-19 03:41 - 2013-08-14 15:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-14 15:28
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |