FRST.txt
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-11-2013
Ran by Benny (administrator) on BENNY-PC on 19-11-2013 16:42:58
Running from C:\Users\Benny\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(devolo AG) C:\Program Files\devolo\dlan\devolonetsvc.exe
() C:\Users\Benny\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Curse) C:\Users\Benny\AppData\Local\Apps\2.0\KADLHYEL.R9L\4MQJ43NQ.A3E\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Ocs_SM] - C:\Users\Benny\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [106496 2012-09-04] (OCS)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [6210840 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [747264 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM Group Policy restriction on software: C:\Program Files\Avira\AntiVir Desktop\avnotify.exe <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
HKCU\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-08-31] ()
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
MountPoints2: {6cb8c1ea-b7e9-11e1-a711-dc2f3025143a} - F:\pushinst.exe
Startup: C:\Users\Benny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Benny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk
ShortcutTarget: Product Registration.lnk -> C:\Users\Benny\AppData\Local\Temp\is-5PEJP.tmp\ATR1.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9A1BA3BDBD24CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKCU - {061584DB-638E-4F00-BEF2-C7C721B143F6} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&mode=bounce&k=0
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=E6C350E549C80ACC&affID=121565&tt=010913_12&tsp=4993
SearchScopes: HKCU - {19F078A2-C8DB-4342-9C39-D604794FCF5F} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&mode=bounce&k=0
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {678A6920-0934-4E33-A0C6-3491249B3556} URL = hxxp://websearch.ask.com.anonymize-me.de/?anonymto=687474703A2F2F7765627365617263682E61736B2E636F6D2F72656469726563743F636C69656E743D69652674623D4156522D33266F3D41504E3130333935267372633D63726D26713D7B7365617263685465726D737D266C6F63616C653D64655F44452661706E5F70746E72733D5E4142542661706E5F647469643D5E5959595959595E59595E44452661706E5F7569643D36363839363236342D353839362D343735612D383639622D3936653630653061363162322661706E5F73617569643D46363733344641342D324641322D344132352D393343312D413042373937364635413941&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&k=0
SearchScopes: HKCU - {7B7500FC-972C-4768-96D7-7825167B78B9} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&mode=bounce&k=0
SearchScopes: HKCU - {9C57E9A3-A058-4FE4-A27D-7F18BA0261AB} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&mode=bounce&k=0
SearchScopes: HKCU - {A244A10C-00E2-4707-B803-CEEB77B142D1} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&mode=bounce&k=0
SearchScopes: HKCU - {CCCEF095-F960-4D7F-A926-D003D0B3B15F} URL = hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - {DC1D8746-B04B-420A-99C1-9F18E307522F} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=f96863d3-b230-4088-a1d9-ff714ed19387&pid=murb&mode=bounce&k=0
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default
FF user.js: detected! => C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\user.js
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\searchplugins\delta.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\Extensions\ich@maltegoetz.de
FF Extension: firefox - C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\Extensions\firefox@ghostery.com.xpi
FF Extension: stefanvandamme - C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\Extensions\stefanvandamme@stefanvd.net.xpi
FF Extension: Adblock Plus - C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKCU\...\Firefox\Extensions: [extension@preispilot.com] - C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\extensions\extension@preispilot.com
FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\Benny\AppData\Roaming\Mozilla\Firefox\Profiles\f79adqr4.default\extensions\firejump@firejump.net
========================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2013-08-30] (Advanced Micro Devices, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 DevoloNetworkService; C:\Program Files\devolo\dlan\devolonetsvc.exe [3304768 2010-12-23] (devolo AG)
R2 SearchAnonymizer; C:\Users\Benny\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2012-09-04] ()
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [48808 2012-11-20] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-11-07] (AVM Berlin)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-06-25] (DT Soft Ltd)
S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [401920 2007-12-19] (AVM GmbH)
R3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-24] (Logitech Inc.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [39960 2013-05-30] (Logitech Inc.)
R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [29976 2013-05-30] (Logitech Inc.)
R3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-24] (Logitech Inc.)
R2 NPF_devolo; C:\Windows\system32\drivers\npf_devolo.sys [35840 2010-06-10] (CACE Technologies)
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2011-06-15] (Realtek )
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2011-06-15] (Realtek Corporation)
S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan620.sys [27752 2011-09-16] (Realtek Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [50280 2011-06-15] (Realtek Corporation)
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-19 16:42 - 2013-11-19 16:43 - 00013607 _____ C:\Users\Benny\Desktop\FRST.txt
2013-11-19 16:42 - 2013-11-19 16:42 - 00000000 ____D C:\FRST
2013-11-19 16:41 - 2013-11-19 16:41 - 01090881 _____ (Farbar) C:\Users\Benny\Desktop\FRST.exe
2013-11-18 21:41 - 2013-11-18 21:41 - 00007312 _____ C:\Users\Benny\Desktop\Neues Textdokument.txt
2013-11-18 21:30 - 2013-11-18 21:30 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-18 21:30 - 2013-11-18 21:30 - 00000000 ____D C:\Users\Benny\AppData\Roaming\Malwarebytes
2013-11-18 21:30 - 2013-11-18 21:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-18 21:30 - 2013-11-18 21:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-18 21:30 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-18 21:25 - 2013-11-18 21:25 - 00618912 _____ C:\Users\Benny\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe
2013-11-18 01:04 - 2013-11-18 21:05 - 06636379 _____ C:\Users\Benny\Downloads\pokemon.exe
2013-11-18 00:58 - 2012-06-18 09:29 - 00000000 ____D C:\Users\Benny\Downloads\wxDevCppP7-64b
2013-11-18 00:41 - 2013-11-18 00:41 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-11-18 00:40 - 2013-11-18 00:45 - 00000000 ____D C:\Users\Benny\Documents\Visual Studio 2010
2013-11-18 00:39 - 2013-11-18 00:56 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-11-18 00:39 - 2013-11-18 00:39 - 00000000 ____D C:\Program Files\Microsoft Help Viewer
2013-11-17 15:36 - 2013-11-17 15:36 - 00000959 _____ C:\Users\Benny\AppData\Roaming\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk
2013-11-17 15:34 - 2013-11-17 15:47 - 00000000 ____D C:\MinGW
2013-11-17 15:16 - 2013-11-18 00:26 - 00000000 ____D C:\Users\Benny\AppData\Roaming\CodeBlocks
2013-11-15 19:32 - 2013-11-15 19:32 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-14 23:08 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-14 23:08 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 23:08 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 23:08 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-14 23:08 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 23:08 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-14 19:35 - 2013-11-14 19:50 - 00005754 __RSH C:\ProgramData\ntuser.pol
2013-11-14 17:38 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 17:38 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 17:38 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 17:38 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 17:38 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 17:38 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 17:38 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 17:38 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 17:38 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 17:38 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 17:38 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 17:38 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 17:38 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 17:38 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 17:38 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 17:38 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 17:38 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 17:38 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-10-21 20:38 - 2013-10-21 20:47 - 00000000 ____D C:\Users\Benny\Desktop\Neuer Ordner
==================== One Month Modified Files and Folders =======
2013-11-19 16:43 - 2013-11-19 16:42 - 00013607 _____ C:\Users\Benny\Desktop\FRST.txt
2013-11-19 16:42 - 2013-11-19 16:42 - 00000000 ____D C:\FRST
2013-11-19 16:41 - 2013-11-19 16:41 - 01090881 _____ (Farbar) C:\Users\Benny\Desktop\FRST.exe
2013-11-19 16:33 - 2012-06-16 21:34 - 00000000 ____D C:\Users\Benny\AppData\Roaming\Skype
2013-11-19 16:20 - 2012-06-16 20:12 - 01165856 _____ C:\Windows\WindowsUpdate.log
2013-11-19 16:18 - 2013-10-16 18:07 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-19 16:02 - 2009-07-14 05:34 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-19 16:02 - 2009-07-14 05:34 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-19 16:00 - 2012-09-01 17:49 - 00000000 ____D C:\Users\Benny\AppData\Local\Deployment
2013-11-19 15:58 - 2013-10-16 18:07 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-19 15:57 - 2013-04-04 01:36 - 00027752 _____ C:\Windows\setupact.log
2013-11-19 15:57 - 2012-06-28 22:30 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2013-11-19 15:57 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-18 21:49 - 2012-06-18 15:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-18 21:43 - 2013-04-04 01:36 - 00245030 _____ C:\Windows\PFRO.log
2013-11-18 21:41 - 2013-11-18 21:41 - 00007312 _____ C:\Users\Benny\Desktop\Neues Textdokument.txt
2013-11-18 21:30 - 2013-11-18 21:30 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-18 21:30 - 2013-11-18 21:30 - 00000000 ____D C:\Users\Benny\AppData\Roaming\Malwarebytes
2013-11-18 21:30 - 2013-11-18 21:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-18 21:30 - 2013-11-18 21:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-18 21:25 - 2013-11-18 21:25 - 00618912 _____ C:\Users\Benny\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe
2013-11-18 21:05 - 2013-11-18 01:04 - 06636379 _____ C:\Users\Benny\Downloads\pokemon.exe
2013-11-18 19:30 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-18 01:22 - 2013-06-25 20:20 - 00000000 ___RD C:\Users\Benny\Dropbox
2013-11-18 01:22 - 2013-06-25 20:17 - 00000000 ____D C:\Users\Benny\AppData\Roaming\Dropbox
2013-11-18 00:56 - 2013-11-18 00:39 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0
2013-11-18 00:56 - 2012-06-30 15:19 - 00000000 ____D C:\Program Files\Microsoft.NET
2013-11-18 00:56 - 2009-07-14 05:52 - 00000000 ____D C:\Program Files\MSBuild
2013-11-18 00:56 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-18 00:45 - 2013-11-18 00:40 - 00000000 ____D C:\Users\Benny\Documents\Visual Studio 2010
2013-11-18 00:41 - 2013-11-18 00:41 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-11-18 00:41 - 2012-08-05 21:24 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-11-18 00:39 - 2013-11-18 00:39 - 00000000 ____D C:\Program Files\Microsoft Help Viewer
2013-11-18 00:38 - 2012-06-16 20:18 - 01593044 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-18 00:32 - 2012-09-04 19:02 - 00000000 ____D C:\Program Files\ICQ Ignore Checker
2013-11-18 00:26 - 2013-11-17 15:16 - 00000000 ____D C:\Users\Benny\AppData\Roaming\CodeBlocks
2013-11-17 15:47 - 2013-11-17 15:34 - 00000000 ____D C:\MinGW
2013-11-17 15:36 - 2013-11-17 15:36 - 00000959 _____ C:\Users\Benny\AppData\Roaming\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk
2013-11-16 13:13 - 2012-12-16 13:36 - 00000000 ____D C:\Users\Benny\Desktop\Neue Musik
2013-11-16 12:44 - 2012-06-16 21:04 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-15 20:10 - 2013-08-14 11:38 - 00000000 ____D C:\Users\Benny\Desktop\Games
2013-11-15 20:10 - 2012-06-16 20:32 - 00000000 ____D C:\Users\Benny\Desktop\Bilder
2013-11-15 20:09 - 2013-01-17 17:14 - 00000000 ____D C:\Users\Benny\Desktop\Crap
2013-11-15 19:32 - 2013-11-15 19:32 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-15 18:25 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 23:08 - 2013-08-16 00:30 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 23:07 - 2012-07-02 08:51 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-14 19:50 - 2013-11-14 19:35 - 00005754 __RSH C:\ProgramData\ntuser.pol
2013-11-14 19:34 - 2009-07-14 03:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-11-14 18:41 - 2013-08-25 13:54 - 00000000 ____D C:\Users\Benny\Desktop\Ausbildung
2013-11-13 23:29 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\LiveKernelReports
2013-11-11 17:54 - 2012-06-16 21:34 - 00000000 ___RD C:\Program Files\Skype
2013-11-11 17:54 - 2012-06-16 21:34 - 00000000 ____D C:\ProgramData\Skype
2013-11-08 18:20 - 2013-01-04 14:29 - 00000000 ____D C:\Program Files\Steam
2013-11-07 16:29 - 2013-01-04 14:29 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-10-28 16:43 - 2013-08-18 18:36 - 00001768 _____ C:\Users\Benny\Desktop\The West.txt
2013-10-24 15:41 - 2009-07-14 05:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-23 20:51 - 2013-10-01 15:31 - 00000000 ____D C:\Program Files\RIFT
2013-10-21 20:47 - 2013-10-21 20:38 - 00000000 ____D C:\Users\Benny\Desktop\Neuer Ordner
2013-10-20 17:28 - 2013-03-19 16:52 - 00002391 _____ C:\Users\Benny\Desktop\Youtube Abonnenten.txt
2013-10-20 03:12 - 2012-09-01 17:07 - 00000000 ____D C:\Users\Benny\AppData\Roaming\TS3Client
Some content of TEMP:
====================
C:\Users\Benny\AppData\Local\Temp\aoe3-111-german.exe
C:\Users\Benny\AppData\Local\Temp\aoe3-112-german.exe
C:\Users\Benny\AppData\Local\Temp\aoe3-113-german.exe
C:\Users\Benny\AppData\Local\Temp\aoe3-114-german.exe
C:\Users\Benny\AppData\Local\Temp\AskSLib.dll
C:\Users\Benny\AppData\Local\Temp\SIntf16.dll
C:\Users\Benny\AppData\Local\Temp\SIntf32.dll
C:\Users\Benny\AppData\Local\Temp\SIntfNT.dll
C:\Users\Benny\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Benny\AppData\Local\Temp\standalonepatcher.exe
C:\Users\Benny\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-11 20:58
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-11-2013
Ran by Benny at 2013-11-19 16:43:36
Running from C:\Users\Benny\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
µTorrent (Version: 3.2.0)
7-Zip 9.20
ActiveState ActivePython 2.7.2.5 (32-bit) (Version: 2.7.5)
Adobe AIR (Version: 2.5.1.17730)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
Age of Empires III (Version: 1.00.0000)
Amazon MP3-Downloader 1.0.17 (Version: 1.0.17)
AMD Accelerated Video Transcoding (Version: 13.15.100.30830)
AMD APP SDK Runtime (Version: 10.0.1084.4)
AMD Catalyst Control Center (Version: 2013.0830.1944.33589)
AMD Catalyst Install Manager (Version: 8.0.915.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2013.0830.1944.33589)
AMD Media Foundation Decoders (Version: 1.0.80830.1925)
Armies of Exigo (Version: 1.00.0000)
Avira Free Antivirus (Version: 13.0.0.4052)
BattleForge™ (Version: 1.0.0.0)
CameraHelperMsi (Version: 13.50.854.0)
Canon MG5100 series MP Drivers
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2013.0830.1944.33589)
Catalyst Control Center InstallProxy (Version: 2013.0830.1944.33589)
Catalyst Control Center Localization All (Version: 2013.0830.1944.33589)
CCC Help Chinese Standard (Version: 2013.0830.1943.33589)
CCC Help Chinese Traditional (Version: 2013.0830.1943.33589)
CCC Help Czech (Version: 2013.0830.1943.33589)
CCC Help Danish (Version: 2013.0830.1943.33589)
CCC Help Dutch (Version: 2013.0830.1943.33589)
CCC Help English (Version: 2013.0830.1943.33589)
CCC Help Finnish (Version: 2013.0830.1943.33589)
CCC Help French (Version: 2013.0830.1943.33589)
CCC Help German (Version: 2013.0830.1943.33589)
CCC Help Greek (Version: 2013.0830.1943.33589)
CCC Help Hungarian (Version: 2013.0830.1943.33589)
CCC Help Italian (Version: 2013.0830.1943.33589)
CCC Help Japanese (Version: 2013.0830.1943.33589)
CCC Help Korean (Version: 2013.0830.1943.33589)
CCC Help Norwegian (Version: 2013.0830.1943.33589)
CCC Help Polish (Version: 2013.0830.1943.33589)
CCC Help Portuguese (Version: 2013.0830.1943.33589)
CCC Help Russian (Version: 2013.0830.1943.33589)
CCC Help Spanish (Version: 2013.0830.1943.33589)
CCC Help Swedish (Version: 2013.0830.1943.33589)
CCC Help Thai (Version: 2013.0830.1943.33589)
CCC Help Turkish (Version: 2013.0830.1943.33589)
ccc-utility (Version: 2013.0830.1944.33589)
CCleaner (Version: 3.19)
Cube World version 0.0.1 (Version: 0.0.1)
Curse Client (HKCU Version: 5.1.1.792)
D3DX10 (Version: 15.4.2368.0902)
DAEMON Tools Lite (Version: 4.47.1.0333)
Day of Defeat: Source
Dead Island
Desktop Icon für Amazon (Version: 1.0.1 (de))
devolo dLAN Cockpit (Version: 3.0.0.0)
Diablo III (Version: 1.0.6.13644)
dLAN Cockpit (Version: 3 (23.12.2010))
dLAN Cockpit (Version: 3.23.12)
Dragons Prophet (Version: )
Dropbox (HKCU Version: 2.2.13)
erLT (Version: 1.20.138.34)
FireJump (Version: 1.0.2.5)
Fraps (remove only)
Free Mp3 Wma Converter V 2.2 (Version: 2.2.0.0)
Free Screen Video Recorder version 2.5.30.827 (Version: 2.5.30.827)
Free YouTube to MP3 Converter version 3.12.2.419 (Version: 3.12.2.419)
GIMP 2.8.4 (Version: 2.8.4)
Google Earth Plug-in (Version: 7.1.1.1888)
Google Update Helper (Version: 1.3.21.165)
HyperCam 2 (Version: 2.28.01)
Java 7 Update 15 (Version: 7.0.150)
Java Auto Updater (Version: 2.1.9.0)
K-Lite Codec Pack 9.9.0 (Basic) (Version: 9.9.0)
Logitech Gaming Software (Version: 8.45.88)
Logitech Gaming Software 8.50 (Version: 8.50.281)
Logitech Webcam-Software (Version: 2.31)
LWS Facebook (Version: 13.50.854.0)
LWS Gallery (Version: 13.50.854.0)
LWS Help_main (Version: 13.50.862.0)
LWS Launcher (Version: 13.50.859.0)
LWS Motion Detection (Version: 13.30.1395.0)
LWS Pictures And Video (Version: 13.50.861.0)
LWS Twitter (Version: 13.30.1346.0)
LWS Video Mask Maker (Version: 13.30.1379.0)
LWS VideoEffects (Version: 13.30.1379.0)
LWS Webcam Software (Version: 13.31.1038.0)
LWS WLM Plugin (Version: 1.30.1201.0)
LWS YouTube Plugin (Version: 13.31.1038.0)
Mafia II - Demo
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Multi-Targeting Pack (Version: 4.0.30319)
Microsoft .NET Framework 4.5 (Version: 4.5.50709)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Help Viewer 1.0 (Version: 1.0.30319)
Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server Compact 3.5 SP2 DEU (Version: 3.5.8080.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (Version: 11.0.50727.1)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (Version: 11.0.50727)
Movie Maker 6.0 for Windows 7 (32-bit) (Version: 6.0.0)
Mozilla Firefox 25.0.1 (x86 de) (Version: 25.0.1)
Mozilla Maintenance Service (Version: 25.0.1)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MyFreeCodec
Neverwinter
No23 Recorder (Version: 2.1.0.3)
OpenOffice.org 3.4 (Version: 3.4.9590)
Origin (Version: 9.1.11.2678)
Pando Media Booster (Version: 2.6.0.8)
Preispilot für Firefox (Version: 2.0)
RaiderZ (Version: 1.0.0.36787)
Realtek Ethernet Controller Driver (Version: 7.49.927.2011)
Realtek Ethernet Diagnostic Utility (Version: 1.006)
RIFT
RollerCoaster Tycoon 3
Samsung Kies (Version: 2.3.2.12074_13)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.9.0)
SearchAnonymizer (Version: 1.0.1 (de))
Skype™ 6.10 (Version: 6.10.104)
Steam (Version: 1.0.0.0)
TeamSpeak 3 Client (Version: 3.0.13)
Trine 2 Demo
Tunatic
Update for Microsoft .NET Framework 4.5 (KB2750147) (Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805221) (Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805226) (Version: 1)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
WinRAR 4.20 (32-Bit) (Version: 4.20.0)
World of Warcraft (Version: 5.4.0.17371)
==================== Restore Points =========================
29-10-2013 15:37:45 Windows Update
05-11-2013 15:38:14 Windows Update
08-11-2013 17:22:31 Windows Update
14-11-2013 16:32:42 Windows Update
14-11-2013 22:06:49 Windows Update
17-11-2013 23:32:41 Removed Python 2.7.3
17-11-2013 23:33:28 Removed Python 3.3.0
19-11-2013 15:19:01 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0AE5E348-B24C-42CE-A784-55DF98DA060F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-16] (Google Inc.)
Task: {0CFA73DE-CE69-4728-8E67-223C14FC7006} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {12DEDCEC-16BE-4EDF-A189-1E1364A308A5} - System32\Tasks\{C62EAEC3-CA98-404C-9901-B6B0BA509425} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1E364CBA-1503-4F59-80A5-2D0C6C878600} - System32\Tasks\{8A3FE622-5879-46FC-BF24-3AA46065BDD2} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {23D1CB01-7B79-4CD3-9709-95A93FA29DF9} - System32\Tasks\{8434A40E-43C6-4DFB-8232-1B14AE314BD5} => C:\Users\Benny\Downloads\pokemon.exe [2013-11-18] ()
Task: {49F71D13-CAC7-42A7-B872-8D9C9EC86ED4} - System32\Tasks\{49674B06-D09A-48B5-A0B0-61BFB038961A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CCEDA7E6-7FE4-4783-9C03-8ED61F28A12A} - System32\Tasks\{E02849DE-86D6-44B7-B291-0C4552AA5D93} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E86D079E-4850-41AD-83E9-39AF9713BC31} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-16] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-04-08 19:29 - 2013-04-08 19:29 - 00115137 _____ () C:\Users\Benny\AppData\Local\Temp\fbe2808e-2380-4f14-a1fa-3fa9c3a364e8\CliSecureRT.dll
2013-06-05 15:20 - 2013-06-05 15:19 - 00035840 _____ () C:\Users\Benny\AppData\Local\Apps\2.0\KADLHYEL.R9L\4MQJ43NQ.A3E\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.Advertising.dll
2013-06-05 15:20 - 2013-06-05 15:19 - 00014848 _____ () C:\Users\Benny\AppData\Local\Apps\2.0\KADLHYEL.R9L\4MQJ43NQ.A3E\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.WowDb.dll
2013-06-05 15:20 - 2013-06-05 15:19 - 00099840 _____ () C:\Users\Benny\AppData\Local\Apps\2.0\KADLHYEL.R9L\4MQJ43NQ.A3E\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.CMOD2.dll
2013-08-30 18:45 - 2013-08-30 18:45 - 00095744 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-11-15 19:32 - 2013-11-15 19:32 - 03363952 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-10-09 19:49 - 2013-10-09 19:49 - 16233864 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Benny\Documents\clip0001.avi:TOC.WMV
AlternateDataStreams: C:\Users\Benny\Documents\clip0003.avi:TOC.WMV
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/18/2013 01:34:44 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: conhost.exe, Version: 6.1.7601.18229, Zeitstempel: 0x51fb02e5
Name des fehlerhaften Moduls: conhost.exe, Version: 6.1.7601.18229, Zeitstempel: 0x51fb02e5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001977
ID des fehlerhaften Prozesses: 0x1188
Startzeit der fehlerhaften Anwendung: 0xconhost.exe0
Pfad der fehlerhaften Anwendung: conhost.exe1
Pfad des fehlerhaften Moduls: conhost.exe2
Berichtskennung: conhost.exe3
Error: (11/18/2013 01:31:20 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: conhost.exe, Version: 6.1.7601.18229, Zeitstempel: 0x51fb02e5
Name des fehlerhaften Moduls: conhost.exe, Version: 6.1.7601.18229, Zeitstempel: 0x51fb02e5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001990
ID des fehlerhaften Prozesses: 0x13fc
Startzeit der fehlerhaften Anwendung: 0xconhost.exe0
Pfad der fehlerhaften Anwendung: conhost.exe1
Pfad des fehlerhaften Moduls: conhost.exe2
Berichtskennung: conhost.exe3
Error: (11/18/2013 01:30:25 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: conhost.exe, Version: 6.1.7601.18229, Zeitstempel: 0x51fb02e5
Name des fehlerhaften Moduls: conhost.exe, Version: 6.1.7601.18229, Zeitstempel: 0x51fb02e5
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001990
ID des fehlerhaften Prozesses: 0x1ba0
Startzeit der fehlerhaften Anwendung: 0xconhost.exe0
Pfad der fehlerhaften Anwendung: conhost.exe1
Pfad des fehlerhaften Moduls: conhost.exe2
Berichtskennung: conhost.exe3
Error: (11/18/2013 00:31:48 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: ICQ7.exe, Version: 14.0.0.162, Zeitstempel: 0x4626b2f4
Name des fehlerhaften Moduls: MoveIt.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4f9d5ceb
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0f67cf7e
ID des fehlerhaften Prozesses: 0x108c
Startzeit der fehlerhaften Anwendung: 0xICQ7.exe0
Pfad der fehlerhaften Anwendung: ICQ7.exe1
Pfad des fehlerhaften Moduls: ICQ7.exe2
Berichtskennung: ICQ7.exe3
Error: (11/18/2013 00:24:06 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: helloworld.exe, Version: 0.0.0.0, Zeitstempel: 0x52895016
Name des fehlerhaften Moduls: libstdc++-6.dll, Version: 0.0.0.0, Zeitstempel: 0x4bc96cae
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000442f4
ID des fehlerhaften Prozesses: 0x264
Startzeit der fehlerhaften Anwendung: 0xhelloworld.exe0
Pfad der fehlerhaften Anwendung: helloworld.exe1
Pfad des fehlerhaften Moduls: helloworld.exe2
Berichtskennung: helloworld.exe3
Error: (11/18/2013 00:23:02 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: helloworld.exe, Version: 0.0.0.0, Zeitstempel: 0x52894fd5
Name des fehlerhaften Moduls: libstdc++-6.dll, Version: 0.0.0.0, Zeitstempel: 0x4bc96cae
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000442f4
ID des fehlerhaften Prozesses: 0x14f4
Startzeit der fehlerhaften Anwendung: 0xhelloworld.exe0
Pfad der fehlerhaften Anwendung: helloworld.exe1
Pfad des fehlerhaften Moduls: helloworld.exe2
Berichtskennung: helloworld.exe3
Error: (11/18/2013 00:20:59 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: helloworld.exe, Version: 0.0.0.0, Zeitstempel: 0x52894dc6
Name des fehlerhaften Moduls: libstdc++-6.dll, Version: 0.0.0.0, Zeitstempel: 0x4bc96cae
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000442f4
ID des fehlerhaften Prozesses: 0x734
Startzeit der fehlerhaften Anwendung: 0xhelloworld.exe0
Pfad der fehlerhaften Anwendung: helloworld.exe1
Pfad des fehlerhaften Moduls: helloworld.exe2
Berichtskennung: helloworld.exe3
Error: (11/18/2013 00:20:35 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: helloworld.exe, Version: 0.0.0.0, Zeitstempel: 0x52894dc6
Name des fehlerhaften Moduls: libstdc++-6.dll, Version: 0.0.0.0, Zeitstempel: 0x4bc96cae
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000442f4
ID des fehlerhaften Prozesses: 0x860
Startzeit der fehlerhaften Anwendung: 0xhelloworld.exe0
Pfad der fehlerhaften Anwendung: helloworld.exe1
Pfad des fehlerhaften Moduls: helloworld.exe2
Berichtskennung: helloworld.exe3
Error: (11/18/2013 00:20:30 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: helloworld.exe, Version: 0.0.0.0, Zeitstempel: 0x52894dc6
Name des fehlerhaften Moduls: libstdc++-6.dll, Version: 0.0.0.0, Zeitstempel: 0x4bc96cae
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000442f4
ID des fehlerhaften Prozesses: 0xa28
Startzeit der fehlerhaften Anwendung: 0xhelloworld.exe0
Pfad der fehlerhaften Anwendung: helloworld.exe1
Pfad des fehlerhaften Moduls: helloworld.exe2
Berichtskennung: helloworld.exe3
Error: (11/18/2013 00:14:14 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: helloworld.exe, Version: 0.0.0.0, Zeitstempel: 0x52894dc6
Name des fehlerhaften Moduls: libstdc++-6.dll, Version: 0.0.0.0, Zeitstempel: 0x4bc96cae
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000442f4
ID des fehlerhaften Prozesses: 0x157c
Startzeit der fehlerhaften Anwendung: 0xhelloworld.exe0
Pfad der fehlerhaften Anwendung: helloworld.exe1
Pfad des fehlerhaften Moduls: helloworld.exe2
Berichtskennung: helloworld.exe3
System errors:
=============
Error: (11/19/2013 04:00:11 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (11/18/2013 09:46:15 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (11/18/2013 09:45:54 PM) (Source: DCOM) (User: )
Description: {CC957078-B838-47C4-A7CF-626E7A82FC58}
Error: (11/17/2013 02:19:00 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (11/17/2013 02:18:24 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (11/17/2013 02:18:24 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Player-Netzwerkfreigabedienst erreicht.
Error: (11/16/2013 00:48:38 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (11/16/2013 00:48:38 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005
Error: (11/11/2013 05:53:22 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (11/07/2013 04:26:40 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (11/18/2013 01:34:44 AM) (Source: Application Error)(User: )
Description: conhost.exe6.1.7601.1822951fb02e5conhost.exe6.1.7601.1822951fb02e5c000000500001977118801cee3f5e2db9b3cC:\Windows\system32\conhost.exeC:\Windows\system32\conhost.exe38159b8e-4fe9-11e3-a150-50e549c80acc
Error: (11/18/2013 01:31:20 AM) (Source: Application Error)(User: )
Description: conhost.exe6.1.7601.1822951fb02e5conhost.exe6.1.7601.1822951fb02e5c00000050000199013fc01cee3f56add9a13C:\Windows\system32\conhost.exeC:\Windows\system32\conhost.exebe90f4ad-4fe8-11e3-a150-50e549c80acc
Error: (11/18/2013 01:30:25 AM) (Source: Application Error)(User: )
Description: conhost.exe6.1.7601.1822951fb02e5conhost.exe6.1.7601.1822951fb02e5c0000005000019901ba001cee3f554d7c466C:\Windows\system32\conhost.exeC:\Windows\system32\conhost.exe9d6a999b-4fe8-11e3-a150-50e549c80acc
Error: (11/18/2013 00:31:48 AM) (Source: Application Error)(User: )
Description: ICQ7.exe14.0.0.1624626b2f4MoveIt.dll_unloaded0.0.0.04f9d5cebc00000050f67cf7e108c01cee3ed1d61eb82C:\Users\Benny\AppData\Local\Temp\{27EA1B38-BCC6-40DD-B368-0234837E76A7}\ICQ7.exeMoveIt.dll6d617f0b-4fe0-11e3-a150-50e549c80acc
Error: (11/18/2013 00:24:06 AM) (Source: Application Error)(User: )
Description: helloworld.exe0.0.0.052895016libstdc++-6.dll0.0.0.04bc96caec0000005000442f426401cee3ec1c5dc489C:\Users\Benny\Downloads\helloworld.exeC:\Users\Benny\Downloads\libstdc++-6.dll5a10c7ca-4fdf-11e3-a150-50e549c80acc
Error: (11/18/2013 00:23:02 AM) (Source: Application Error)(User: )
Description: helloworld.exe0.0.0.052894fd5libstdc++-6.dll0.0.0.04bc96caec0000005000442f414f401cee3ebf565c386C:\Users\Benny\Downloads\helloworld.exeC:\Users\Benny\Downloads\libstdc++-6.dll33e0ad95-4fdf-11e3-a150-50e549c80acc
Error: (11/18/2013 00:20:59 AM) (Source: Application Error)(User: )
Description: helloworld.exe0.0.0.052894dc6libstdc++-6.dll0.0.0.04bc96caec0000005000442f473401cee3ebacb20311C:\Users\Benny\Downloads\helloworld.exeC:\Users\Benny\Downloads\libstdc++-6.dllea697333-4fde-11e3-a150-50e549c80acc
Error: (11/18/2013 00:20:35 AM) (Source: Application Error)(User: )
Description: helloworld.exe0.0.0.052894dc6libstdc++-6.dll0.0.0.04bc96caec0000005000442f486001cee3eb9e2bfed0C:\Users\Benny\Downloads\helloworld.exeC:\Users\Benny\Downloads\libstdc++-6.dlldbde3ebf-4fde-11e3-a150-50e549c80acc
Error: (11/18/2013 00:20:30 AM) (Source: Application Error)(User: )
Description: helloworld.exe0.0.0.052894dc6libstdc++-6.dll0.0.0.04bc96caec0000005000442f4a2801cee3eb9a6a06baC:\Users\Benny\Downloads\helloworld.exeC:\Users\Benny\Downloads\libstdc++-6.dlld948e430-4fde-11e3-a150-50e549c80acc
Error: (11/18/2013 00:14:14 AM) (Source: Application Error)(User: )
Description: helloworld.exe0.0.0.052894dc6libstdc++-6.dll0.0.0.04bc96caec0000005000442f4157c01cee3eabb1e91e8C:\Users\Benny\Downloads\helloworld.exeC:\Users\Benny\Downloads\libstdc++-6.dllf927f3cd-4fdd-11e3-a150-50e549c80acc
CodeIntegrity Errors:
===================================
Date: 2013-06-02 15:54:26.432
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-06-01 22:49:01.506
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-05-31 14:07:20.939
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-05-31 14:07:04.347
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-05-23 20:53:52.285
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 46%
Total physical RAM: 3325.24 MB
Available physical RAM: 1764.14 MB
Total Pagefile: 6648.77 MB
Available Pagefile: 4470.96 MB
Total Virtual: 2047.88 MB
Available Virtual: 1906.53 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.79 GB) (Free:46.61 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 66E1A10A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |