FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-12-2013 02
Ran by Jan (administrator) on JAN-PC on 16-12-2013 22:36:04
Running from C:\Users\Jan.jan-PC\Downloads
Microsoft Windows 7 Home Premium (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMutilps32.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe
(Dropbox, Inc.) C:\Users\Jan.jan-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\tv_w32.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-06-09] (Realtek Semiconductor)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1934632 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [YouCam Service] - "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2254768 2012-12-10] (LogMeIn Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
HKLM\...\Run: [IndexSearch] - C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] - C:\Program Files\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-08] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort12reminder] - C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM\...\Run: [ControlCenter4] - C:\Program Files\ControlCenter4\BrCcBoot.exe [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM\...\Run: [BrStsMon00] - C:\Program Files\Browny02\Brother\BrStMonW.exe [2629632 2011-05-19] (Brother Industries, Ltd.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
MountPoints2: {dd118929-a143-11e1-aaa0-806e6f6e6963} - D:\cdstart.exe
HKU\Gast\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [ 2013-12-11] (Valve Corporation)
HKU\Gast\...\Run: [Okpkpy] - C:\Users\Gast\AppData\Roaming\Okpkpy.exe
HKU\Gast\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [ 2009-05-05] (Acresso Corporation)
Startup: C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Jan.jan-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x25BAB51F27EDCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Jan.jan-PC\AppData\Roaming\Mozilla\Firefox\Profiles\rpwm3g8z.default
FF NewTab: hxxp://www.nationzoom.com/newtab/?type=nt&ts=1387219099&from=adks&uid=TOSHIBAXMK3259GSXP_22JXT4NBTXX22JXT4NBT
FF Homepage: about:home|https://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll No File
FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
========================== Services (Whitelisted) =================
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1435568 2012-12-10] (LogMeIn Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
==================== Drivers (Whitelisted) ====================
S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [46680 2011-01-14] (Alcor Micro, Corp.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2012-06-01] ()
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2012-06-01] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2012-07-31] (Screaming Bee LLC)
S3 clwvd; system32\DRIVERS\clwvd.sys [x]
S1 jbvldfuk; \??\C:\Windows\system32\drivers\jbvldfuk.sys [x]
S3 nsysaudm; \??\C:\Users\jan\AppData\Local\Temp\nsysaudm.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-16 22:36 - 2013-12-16 22:36 - 00010628 _____ C:\Users\Jan.jan-PC\Downloads\FRST.txt
2013-12-16 22:35 - 2013-12-16 22:35 - 01060997 _____ (Farbar) C:\Users\Jan.jan-PC\Downloads\FRST.exe
2013-12-16 22:35 - 2013-12-16 22:35 - 00000000 ____D C:\FRST
2013-12-16 21:24 - 2013-12-16 21:25 - 00000149 _____ C:\Users\Jan.jan-PC\Desktop\Neues Textdokument.txt
2013-12-16 21:09 - 2013-12-16 21:09 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Malwarebytes
2013-12-16 21:08 - 2013-12-16 21:08 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-16 21:08 - 2013-12-16 21:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-16 21:08 - 2013-12-16 21:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-16 21:08 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-16 21:07 - 2013-12-16 21:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jan.jan-PC\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-12-16 20:35 - 2013-12-16 20:35 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-12-16 20:25 - 2013-12-16 20:25 - 01226802 _____ C:\Users\Jan.jan-PC\Desktop\adwcleaner.exe
2013-12-16 19:48 - 2013-12-16 19:48 - 00131072 _____ C:\Windows\Minidump\121613-22557-01.dmp
2013-12-16 19:41 - 2013-12-16 21:24 - 00000000 ____D C:\ProgramData\WPM
2013-12-16 18:24 - 2013-12-16 18:24 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Screaming Bee
2013-12-16 18:22 - 2013-12-16 18:22 - 00000000 ____D C:\Program Files\Screaming Bee
2013-12-15 18:38 - 2013-12-15 18:38 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Adobe
2013-12-15 18:09 - 2013-12-15 18:09 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Neuer Ordner
2013-12-14 01:42 - 2013-12-14 01:42 - 00131072 _____ C:\Windows\Minidump\121413-18252-01.dmp
2013-12-12 14:56 - 2013-12-12 14:56 - 00000000 ____H C:\Users\Jan.jan-PC\Documents\Default.rdp
2013-12-10 10:35 - 2013-12-10 10:35 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\DVDVideoSoft
2013-12-07 17:54 - 2013-12-07 17:54 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\SplitMediaLabs
2013-12-07 17:51 - 2013-12-07 17:51 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\SplitMediaLabs
2013-12-07 17:50 - 2013-12-07 17:51 - 39006216 _____ (SplitMediaLabs) C:\Users\Jan.jan-PC\Downloads\xsplit_installer_v1.3.1311.1201.exe
2013-12-07 16:17 - 2013-12-07 16:17 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Warframe
2013-12-07 16:00 - 2013-12-07 16:00 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Apps\2.0
2013-12-06 22:00 - 2013-12-12 17:36 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\openvr
2013-12-05 17:09 - 2013-12-16 15:56 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Text
2013-12-03 17:42 - 2013-12-03 17:42 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\TechSmith
2013-12-03 17:31 - 2013-12-11 08:39 - 00005632 _____ C:\Users\Jan.jan-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-03 17:26 - 2013-12-03 17:27 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\vlc
2013-12-03 17:26 - 2013-12-03 17:26 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\dvdcss
2013-12-03 17:17 - 2013-12-03 18:21 - 00000000 ____D C:\Users\Jan.jan-PC\Documents\Camtasia Studio
2013-11-30 22:16 - 2013-12-12 15:31 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\.minecraft
2013-11-29 23:58 - 2013-11-29 23:58 - 00000925 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-29 23:57 - 2013-11-29 23:57 - 01142864 _____ C:\Users\Jan.jan-PC\Downloads\SteamSetup.exe
2013-11-29 20:25 - 2013-12-16 14:31 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\CrashDumps
2013-11-29 19:26 - 2013-11-29 19:26 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\LolClient
2013-11-29 18:48 - 2013-11-29 18:48 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Vitalwerks
2013-11-29 15:23 - 2013-11-29 15:23 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\WinRAR
2013-11-29 14:33 - 2013-12-16 21:27 - 00000000 ___RD C:\Users\Jan.jan-PC\Dropbox
2013-11-29 14:33 - 2013-11-29 14:33 - 00001042 _____ C:\Users\Jan.jan-PC\Desktop\Dropbox.lnk
2013-11-29 14:29 - 2013-11-29 14:29 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-11-29 14:28 - 2013-11-29 14:44 - 00000000 ____D C:\Users\Jan.jan-PC\.gimp-2.8
2013-11-29 14:28 - 2013-11-29 14:28 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\gegl-0.2
2013-11-29 14:27 - 2013-12-16 21:27 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Dropbox
2013-11-29 14:26 - 2013-11-29 14:26 - 35334016 _____ (Dropbox, Inc.) C:\Users\Jan.jan-PC\Downloads\Dropbox 2.4.7.exe
2013-11-29 14:17 - 2013-11-29 14:07 - 00001779 _____ C:\Users\Jan.jan-PC\Desktop\DUC.lnk
2013-11-29 14:17 - 2013-01-27 19:28 - 00001219 _____ C:\Users\Jan.jan-PC\Desktop\Free Studio Manager.lnk
2013-11-29 14:17 - 2012-12-12 19:32 - 00000914 _____ C:\Users\Jan.jan-PC\Desktop\LogMeIn Hamachi.lnk
2013-11-29 14:17 - 2012-05-19 08:31 - 00001351 _____ C:\Users\Jan.jan-PC\Desktop\Sticky Notes.lnk
2013-11-29 14:17 - 2009-07-14 05:41 - 00001266 _____ C:\Users\Jan.jan-PC\Desktop\displayswitch.lnk
2013-11-29 14:14 - 2013-11-29 14:14 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Macromedia
2013-11-29 14:14 - 2013-11-29 14:14 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Macromedia
2013-11-29 14:12 - 2013-11-29 15:14 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Mozilla
2013-11-29 14:12 - 2013-11-29 14:12 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Mozilla
2013-11-29 13:54 - 2013-12-16 22:27 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Skype
2013-11-29 13:53 - 2013-12-16 21:47 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\LogMeIn Hamachi
2013-11-29 13:53 - 2013-12-15 18:38 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Adobe
2013-11-29 13:53 - 2013-11-29 13:53 - 00110504 _____ C:\Users\Jan.jan-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-29 13:53 - 2013-11-29 13:53 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\ControlCenter4
2013-11-29 13:52 - 2013-12-16 20:27 - 00001150 _____ C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-29 13:52 - 2013-12-03 17:37 - 00000000 ____D C:\Users\Jan.jan-PC
2013-11-29 13:52 - 2013-11-29 13:52 - 00000020 ___SH C:\Users\Jan.jan-PC\ntuser.ini
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Startmenü
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Netzwerkumgebung
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Druckumgebung
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Documents\Eigene Musik
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Documents\Eigene Bilder
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\AppData\Local\Verlauf
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\VirtualStore
2013-11-29 13:52 - 2013-11-18 19:57 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Microsoft Help
2013-11-29 13:52 - 2009-07-14 05:42 - 00000000 ___RD C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-29 13:52 - 2009-07-14 05:37 - 00000000 ___RD C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-28 18:00 - 2013-12-06 16:48 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Kanal
2013-11-18 19:57 - 2013-11-18 19:57 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-11-18 19:57 - 2013-11-18 19:57 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-11-18 19:04 - 2013-11-20 15:40 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-16 02:18 - 2013-11-16 02:19 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2013-12-16 22:36 - 2013-12-16 22:36 - 00010628 _____ C:\Users\Jan.jan-PC\Downloads\FRST.txt
2013-12-16 22:35 - 2013-12-16 22:35 - 01060997 _____ (Farbar) C:\Users\Jan.jan-PC\Downloads\FRST.exe
2013-12-16 22:35 - 2013-12-16 22:35 - 00000000 ____D C:\FRST
2013-12-16 22:27 - 2013-11-29 13:54 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Skype
2013-12-16 21:51 - 2012-09-07 07:58 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-16 21:47 - 2013-11-29 13:53 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\LogMeIn Hamachi
2013-12-16 21:33 - 2009-07-14 05:34 - 00015008 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-16 21:33 - 2009-07-14 05:34 - 00015008 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-16 21:32 - 2013-10-25 19:17 - 00000000 ____D C:\AdwCleaner
2013-12-16 21:30 - 2012-05-19 00:50 - 01600692 _____ C:\Windows\WindowsUpdate.log
2013-12-16 21:27 - 2013-11-29 14:33 - 00000000 ___RD C:\Users\Jan.jan-PC\Dropbox
2013-12-16 21:27 - 2013-11-29 14:27 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Dropbox
2013-12-16 21:26 - 2013-01-21 19:57 - 00000342 _____ C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job
2013-12-16 21:26 - 2012-05-19 14:38 - 00191334 _____ C:\Windows\PFRO.log
2013-12-16 21:26 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-16 21:26 - 2009-07-14 05:39 - 00102595 _____ C:\Windows\setupact.log
2013-12-16 21:25 - 2013-12-16 21:24 - 00000149 _____ C:\Users\Jan.jan-PC\Desktop\Neues Textdokument.txt
2013-12-16 21:24 - 2013-12-16 19:41 - 00000000 ____D C:\ProgramData\WPM
2013-12-16 21:09 - 2013-12-16 21:09 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Malwarebytes
2013-12-16 21:08 - 2013-12-16 21:08 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-16 21:08 - 2013-12-16 21:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-16 21:08 - 2013-12-16 21:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-16 21:07 - 2013-12-16 21:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jan.jan-PC\Downloads\mbam-setup-1.75.0.1300(1).exe
2013-12-16 20:35 - 2013-12-16 20:35 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-12-16 20:27 - 2013-11-29 13:52 - 00001150 _____ C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-16 20:25 - 2013-12-16 20:25 - 01226802 _____ C:\Users\Jan.jan-PC\Desktop\adwcleaner.exe
2013-12-16 19:48 - 2013-12-16 19:48 - 00131072 _____ C:\Windows\Minidump\121613-22557-01.dmp
2013-12-16 19:48 - 2013-09-01 01:01 - 253559740 _____ C:\Windows\MEMORY.DMP
2013-12-16 19:48 - 2013-09-01 01:01 - 00000000 ____D C:\Windows\Minidump
2013-12-16 19:41 - 2012-08-31 18:05 - 00420944 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll
2013-12-16 19:18 - 2012-05-19 01:02 - 01507104 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-16 19:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2013-12-16 18:24 - 2013-12-16 18:24 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Screaming Bee
2013-12-16 18:22 - 2013-12-16 18:22 - 00000000 ____D C:\Program Files\Screaming Bee
2013-12-16 15:57 - 2013-04-04 17:54 - 00000000 ____D C:\Program Files\Steam
2013-12-16 15:56 - 2013-12-05 17:09 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Text
2013-12-16 15:16 - 2013-02-10 18:16 - 00000000 ____D C:\Program Files\Google
2013-12-16 14:31 - 2013-11-29 20:25 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\CrashDumps
2013-12-16 14:31 - 2013-06-20 16:25 - 00000000 ____D C:\Program Files\Sony
2013-12-16 14:31 - 2012-05-19 13:13 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-12-15 18:38 - 2013-12-15 18:38 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Adobe
2013-12-15 18:38 - 2013-11-29 13:53 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Adobe
2013-12-15 18:09 - 2013-12-15 18:09 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Neuer Ordner
2013-12-14 01:42 - 2013-12-14 01:42 - 00131072 _____ C:\Windows\Minidump\121413-18252-01.dmp
2013-12-13 17:04 - 2013-03-25 17:38 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-12-12 17:36 - 2013-12-06 22:00 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\openvr
2013-12-12 15:31 - 2013-11-30 22:16 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\.minecraft
2013-12-12 14:56 - 2013-12-12 14:56 - 00000000 ____H C:\Users\Jan.jan-PC\Documents\Default.rdp
2013-12-11 16:36 - 2013-07-16 18:18 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 16:33 - 2012-08-23 18:48 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 15:44 - 2012-05-23 18:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-11 15:44 - 2012-05-23 18:37 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-11 08:39 - 2013-12-03 17:31 - 00005632 _____ C:\Users\Jan.jan-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-10 10:35 - 2013-12-10 10:35 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\DVDVideoSoft
2013-12-10 10:35 - 2013-08-08 16:46 - 00000000 ____D C:\Users\Jan.jan-PC\Documents\DVDVideoSoft
2013-12-07 18:01 - 2013-09-15 16:41 - 00000000 __SHD C:\Windows\system32\AI_RecycleBin
2013-12-07 17:54 - 2013-12-07 17:54 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\SplitMediaLabs
2013-12-07 17:51 - 2013-12-07 17:51 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\SplitMediaLabs
2013-12-07 17:51 - 2013-12-07 17:50 - 39006216 _____ (SplitMediaLabs) C:\Users\Jan.jan-PC\Downloads\xsplit_installer_v1.3.1311.1201.exe
2013-12-07 16:17 - 2013-12-07 16:17 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Warframe
2013-12-07 16:00 - 2013-12-07 16:00 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Apps\2.0
2013-12-06 16:48 - 2013-11-28 18:00 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Kanal
2013-12-04 18:34 - 2013-01-24 19:01 - 00000000 ___RD C:\Program Files\Skype
2013-12-04 18:34 - 2012-06-16 19:31 - 00000000 ____D C:\ProgramData\Skype
2013-12-03 21:16 - 2013-08-08 20:20 - 00000000 ____D C:\Users\Jan.jan-PC\Documents\Stronghold 2
2013-12-03 18:21 - 2013-12-03 17:17 - 00000000 ____D C:\Users\Jan.jan-PC\Documents\Camtasia Studio
2013-12-03 17:42 - 2013-12-03 17:42 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\TechSmith
2013-12-03 17:37 - 2013-11-29 13:52 - 00000000 ____D C:\Users\Jan.jan-PC
2013-12-03 17:37 - 2013-11-09 22:45 - 00001126 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk
2013-12-03 17:27 - 2013-12-03 17:26 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\vlc
2013-12-03 17:26 - 2013-12-03 17:26 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\dvdcss
2013-11-29 23:58 - 2013-11-29 23:58 - 00000925 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-29 23:57 - 2013-11-29 23:57 - 01142864 _____ C:\Users\Jan.jan-PC\Downloads\SteamSetup.exe
2013-11-29 19:26 - 2013-11-29 19:26 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\LolClient
2013-11-29 18:48 - 2013-11-29 18:48 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Vitalwerks
2013-11-29 15:23 - 2013-11-29 15:23 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\WinRAR
2013-11-29 15:14 - 2013-11-29 14:12 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Mozilla
2013-11-29 14:44 - 2013-11-29 14:28 - 00000000 ____D C:\Users\Jan.jan-PC\.gimp-2.8
2013-11-29 14:33 - 2013-11-29 14:33 - 00001042 _____ C:\Users\Jan.jan-PC\Desktop\Dropbox.lnk
2013-11-29 14:29 - 2013-11-29 14:29 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-11-29 14:28 - 2013-11-29 14:28 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\gegl-0.2
2013-11-29 14:26 - 2013-11-29 14:26 - 35334016 _____ (Dropbox, Inc.) C:\Users\Jan.jan-PC\Downloads\Dropbox 2.4.7.exe
2013-11-29 14:14 - 2013-11-29 14:14 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Macromedia
2013-11-29 14:14 - 2013-11-29 14:14 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Macromedia
2013-11-29 14:12 - 2013-11-29 14:12 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\Mozilla
2013-11-29 14:07 - 2013-11-29 14:17 - 00001779 _____ C:\Users\Jan.jan-PC\Desktop\DUC.lnk
2013-11-29 13:53 - 2013-11-29 13:53 - 00110504 _____ C:\Users\Jan.jan-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-29 13:53 - 2013-11-29 13:53 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Roaming\ControlCenter4
2013-11-29 13:52 - 2013-11-29 13:52 - 00000020 ___SH C:\Users\Jan.jan-PC\ntuser.ini
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Startmenü
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Netzwerkumgebung
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Druckumgebung
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Documents\Eigene Musik
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\Documents\Eigene Bilder
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 _SHDL C:\Users\Jan.jan-PC\AppData\Local\Verlauf
2013-11-29 13:52 - 2013-11-29 13:52 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\VirtualStore
2013-11-27 14:13 - 2013-11-09 23:16 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Spiele
2013-11-23 20:24 - 2013-03-31 14:29 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\Server - Scheis
2013-11-21 17:02 - 2013-10-05 15:36 - 00000000 ____D C:\Users\Jan.jan-PC\Desktop\BPM
2013-11-21 13:33 - 2009-07-14 05:33 - 00420504 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-20 15:40 - 2013-11-18 19:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-20 15:39 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-20 15:38 - 2012-05-19 14:27 - 00000000 ____D C:\Program Files\Microsoft Office
2013-11-20 15:38 - 2009-07-14 09:57 - 00000000 ____D C:\Windows\ShellNew
2013-11-20 15:34 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-20 15:34 - 2009-07-14 03:04 - 00000416 _____ C:\Windows\win.ini
2013-11-19 13:52 - 2013-07-16 18:16 - 00002117 _____ C:\Users\Jan.jan-PC\Desktop\Microsoft Security Essentials.lnk
2013-11-19 13:52 - 2013-05-17 18:02 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-11-19 13:52 - 2013-04-12 14:02 - 00001912 _____ C:\Windows\epplauncher.mif
2013-11-19 11:21 - 2012-05-19 14:01 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-18 19:57 - 2013-11-29 13:52 - 00000000 ____D C:\Users\Jan.jan-PC\AppData\Local\Microsoft Help
2013-11-18 19:57 - 2013-11-18 19:57 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-11-18 19:57 - 2013-11-18 19:57 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-11-17 14:13 - 2013-02-19 13:43 - 00000000 ____D C:\Program Files\Origin
2013-11-17 13:45 - 2012-09-30 14:01 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-16 02:19 - 2013-11-16 02:18 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-16 00:32 - 2013-10-12 11:53 - 00000000 ____D C:\Program Files\MSECache
Some content of TEMP:
====================
C:\Users\Jan.jan-PC\AppData\Local\Temp\adks_NationZoom.exe
C:\Users\Jan.jan-PC\AppData\Local\Temp\DownLite_Setup.exe
C:\Users\Jan.jan-PC\AppData\Local\Temp\jansi-32-git-Bukkit-1.6.4-R2.0-b2918jnks.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-10 17:49
==================== End Of Log ============================
--- --- ---
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-12-2013 02
Ran by Jan at 2013-12-16 22:37:05
Running from C:\Users\Jan.jan-PC\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
==================== Installed Programs ======================
Adobe Flash Player 11 ActiveX (Version: 11.9.900.170)
Adobe Flash Player 11 Plugin (Version: 11.9.900.170)
Adobe Reader X (10.1.8) MUI (Version: 10.1.8)
Adobe Shockwave Player 12.0 (Version: 12.0.4.144)
Alcor Micro USB Card Reader (Version: 1.2.42.68439)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.2.43)
Audacity 2.0.3 (Version: 2.0.3)
Battlefield 1942™ (Version: 1.6.20.0)
Brother BRAdmin Light 1.24.0000 (Version: 1.24.0000)
Brother MFL-Pro Suite MFC-J430W (Version: 1.0.19.0)
Camtasia Studio 8 (Version: 8.1.2.1344)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
D3DX10 (Version: 15.4.2368.0902)
DC-Bass Source 1.3.0
DivX-Setup (Version: 2.6.1.8)
Dropbox (HKCU Version: 2.4.7)
Empire Earth
Feuerwehr-Simulator 2010
FL Studio 11
FlatOut2 (Version: 1.00.0000)
FlowStone FL 3.0
Fotogalerie (Version: 16.4.3508.0205)
Free YouTube Download version 3.1.42.1212 (Version: 3.1.42.1212)
Free YouTube to MP3 Converter version 3.12.13.925 (Version: 3.12.13.925)
Gear Up
GIMP 2.8.6 (Version: 2.8.6)
Haali Media Splitter
IL Download Manager
IL Shared Libraries
Intel(R) Processor Graphics (Version: 8.15.10.2342)
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
JavaFX 2.1.0 (Version: 2.1.0)
Lagarith Lossless Codec (1.3.27)
LAME v3.99.3 (for Windows)
Landwirtschafts Simulator 2011 (Version: 1.0)
Launch Manager (Version: 5.1.4)
League of Legends (Version: 3.0.1)
LogMeIn Hamachi (Version: 2.1.0.294)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Medal of Honor (TM) (Version: 1.0.0.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0)
Microsoft Security Client (Version: 4.4.0304.0)
Microsoft Security Essentials (Version: 4.4.304.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3508.0205)
Mozilla Firefox 25.0.1 (x86 de) (Version: 25.0.1)
Mozilla Maintenance Service (Version: 25.0.1)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
Need for Speed™ Most Wanted (Version: 1.5.0.0)
No-IP DUC (Version: 4.0.1)
Notepad++ (Version: 6.4.5)
Nuance PaperPort 12 (Version: 12.1.0000)
Nuance PDF Viewer Plus (Version: 5.30.3290)
NVIDIA PhysX (Version: 9.10.0513)
OpenSource Flash Video Splitter 1.0.0.5 (Version: 1.0.0.5)
Origin (Version: 9.0.13.2141)
Pando Media Booster (Version: 2.6.0.7)
PaperPort Image Printer (Version: 1.00.0001)
Photo Common (Version: 16.4.3508.0205)
Photo Gallery (Version: 16.4.3508.0205)
PlayStation(R)Store (Version: 4.16.2.15545)
Realtek High Definition Audio Driver (Version: 6.0.1.6392)
Scansoft PDF Professional
Skype™ 6.11 (Version: 6.11.102)
Steam
Stronghold 2 (Version: 1.40.1000)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.1.18.0)
Team Fortress 2
TeamSpeak 3 Client (Version: 3.0.13)
TeamViewer 8 (Version: 8.0.22298)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0)
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
VLC media player 2.0.2 (Version: 2.0.2)
Warframe
Windows Live Communications Platform (Version: 16.4.3508.0205)
Windows Live Essentials (Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (Version: 16.4.3508.0205)
Windows Live Photo Common (Version: 16.4.3508.0205)
Windows Live PIMT Platform (Version: 16.4.3508.0205)
Windows Live SOXE (Version: 16.4.3508.0205)
Windows Live SOXE Definitions (Version: 16.4.3508.0205)
Windows Live UX Platform (Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (Version: 16.4.3508.0205)
WinRAR 4.20 (32-Bit) (Version: 4.20.0)
==================== Restore Points =========================
15-12-2013 10:11:18 Windows Update
16-12-2013 13:27:34 Removed Google Earth.
16-12-2013 17:22:04 Installed MorphVOX Junior
16-12-2013 19:02:38 Removed MorphVOX Junior
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {05EE699F-AB25-42D8-8781-558C5D1D2FAD} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
Task: {0E12083C-0335-49DB-9542-BA1EC6D83ECC} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
Task: {18E6D428-D26C-4169-BEDF-3B5BDDC952F6} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe aepdu.dll,AePduRunUpdate
Task: {1C292AB1-663F-4348-B364-592B7D2757CC} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {1E6C0419-8AE6-42B4-8AAF-D6267F6FF8ED} - System32\Tasks\{2370983E-D305-411F-B19E-92AAD93C9A70} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.10.0.114&LastError=12002
Task: {1EC9510D-A439-4950-9399-B6399EDF9EA7} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => Rundll32.exe /d acproxy.dll,PerformAutochkOperations
Task: {242B3494-6B6D-4C53-853B-25B1D8DE1F0E} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files\AVG Secure Search\PostInstall\ROC.exe
Task: {30E74A92-A8B3-4861-86F3-9C7AB09D884D} - System32\Tasks\{6CA89A99-2B14-4F3F-95CE-60E3DD5F549A} => C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
Task: {373090B8-8D24-4CCA-8C7B-826D384DC1B3} - System32\Tasks\{82ABEF68-FEBF-4083-A6FD-D78906D1C00D} => C:\Program Files\Steam\Steam.exe [2013-12-11] (Valve Corporation)
Task: {3B752245-2F0F-427B-8B8B-35B2284D8FD9} - System32\Tasks\{D4F84686-D404-41C3-BABF-857F826CEB08} => C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
Task: {46D560F1-CEE4-49E3-8B8F-0B14859C06BB} - System32\Tasks\{3DB505D6-F76E-4819-BB88-B46EA0F5057A} => C:\Program Files\Microsoft Office\Office12\Wordconv.exe [2009-02-26] ()
Task: {5C2C622F-70E9-4194-A7DA-033E827365AD} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => Rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
Task: {61B58F35-AF8A-48EF-9913-6A6164977651} - System32\Tasks\{23D047C3-3DC4-43DF-B0EC-4D14B82AA3CA} => C:\Program Files\Steam\Steam.exe [2013-12-11] (Valve Corporation)
Task: {847F60EE-2E22-403D-B3F6-D6845AE22330} - System32\Tasks\{701BAA23-946F-4FA6-840D-61AED8C5051D} => C:\Users\jan\Desktop\Xpadder.exe
Task: {9334C323-F100-4656-9BA0-E4AA69C0F9C2} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => Rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
Task: {9DDE9792-189F-4923-8A0E-D04DB5CF0AC8} - System32\Tasks\{9B7CDBF1-35DE-483F-B714-C01FF9DABA01} => C:\Program Files\Microsoft Office\Office12\Wordconv.exe [2009-02-26] ()
Task: {9F68B014-BB1D-4465-81AE-042E9432F097} - System32\Tasks\{EC705C06-F4C5-4F9C-8162-662FA90C4740} => C:\Program Files\Steam\Steam.exe [2013-12-11] (Valve Corporation)
Task: {A343CA7E-6803-4DB0-BD7C-14DA5760D28E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {BDE35736-4695-4B5F-9324-ED0564F05672} - System32\Tasks\{82F375D2-3D6E-4CDB-836B-4FF1C7135B7D} => C:\Program Files\Steam\Steam.exe [2013-12-11] (Valve Corporation)
Task: {BF4C5755-69CB-4C25-88C4-2DFADA12A93E} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => Rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
Task: {CA8F7555-24B1-49DF-AC32-447F51BFCFCC} - System32\Tasks\WPD\SqmUpload_S-1-5-21-3436101307-2244394405-2195471117-1000 => Rundll32.exe portabledeviceapi.dll,#1
Task: {CE657B91-539D-44FA-9249-DD599C547067} - System32\Tasks\WPD\SqmUpload_S-1-5-21-3436101307-2244394405-2195471117-1003 => Rundll32.exe portabledeviceapi.dll,#1
Task: {DA242672-FB72-484A-8F8E-B1B9D9099C34} - System32\Tasks\Google Updater and Installer => C:\Users\jan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {DB9D7B30-1FD8-4A10-A190-8515FB830B18} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {E63AA883-4352-4A11-8C35-7B659096BD22} - System32\Tasks\{F9B8A97F-3236-4038-83D8-CCD79A490A8C} => C:\Program Files\Microsoft Office\Office12\Wordconv.exe [2009-02-26] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job => C:\Program Files\AVG Secure Search\PostInstall\ROC.exe
==================== Loaded Modules (whitelisted) =============
2012-05-19 13:33 - 2011-03-25 10:28 - 00094208 _____ () C:\Windows\System32\IccLibDll.dll
2013-06-30 13:57 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Jan.jan-PC\AppData\Roaming\Dropbox\bin\libcef.dll
2013-11-16 02:18 - 2013-11-16 02:18 - 03363952 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/16/2013 10:37:11 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:37:11.771]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:36:37 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:36:37.265]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:36:02 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:36:02.763]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:35:28 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:35:28.258]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:34:53 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:34:53.754]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:34:19 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:34:19.246]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:33:44 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:33:44.744]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:33:10 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:33:10.240]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:32:35 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:32:35.709]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:32:01 PM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2013/12/16 22:32:01.205]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
System errors:
=============
Error: (12/16/2013 10:36:14 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error: (12/16/2013 09:27:44 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC)
Error: (12/16/2013 09:27:44 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (12/16/2013 09:14:53 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error: (12/16/2013 08:29:10 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC)
Error: (12/16/2013 08:29:10 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (12/16/2013 07:49:17 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (12/16/2013 07:49:15 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC)
Error: (12/16/2013 07:48:40 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.
Error: (12/16/2013 07:48:13 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Desk 365 service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (12/16/2013 10:37:11 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:37:11.771]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:36:37 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:36:37.265]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:36:02 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:36:02.763]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:35:28 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:35:28.258]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:34:53 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:34:53.754]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:34:19 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:34:19.246]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:33:44 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:33:44.744]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:33:10 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:33:10.240]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:32:35 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:32:35.709]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
Error: (12/16/2013 10:32:01 PM) (Source: Brother BrLog)(User: )
Description: STIBrtSTI: [2013/12/16 22:32:01.205]: [00000152]: GetDeviceIpAddress: GetAddressByName [Fritzbofon7390] Error
==================== Memory info ===========================
Percentage of memory in use: 46%
Total physical RAM: 2669.86 MB
Available physical RAM: 1441.62 MB
Total Pagefile: 5338 MB
Available Pagefile: 3909.28 MB
Total Virtual: 2047.88 MB
Available Virtual: 1892.97 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:297.99 GB) (Free:155.99 GB) NTFS
Drive d: (LS11) (CDROM) (Total:0.74 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 4862B406)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================[/CODE]