Hey,
erstmal danke für die schnelle hilfe. :)
Hier die Logfiles
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by sandro (administrator) on 05-07-2013 14:35:40
Running from D:\sandro\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Akamai Technologies, Inc.) C:\Users\sandro\AppData\Local\Akamai\netsession_win.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE
(Akamai Technologies, Inc.) C:\Users\sandro\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
() C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4366704 2009-09-29] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [5825536 2009-08-19] (Lenovo (Beijing) Limited)
HKCU\...\Run: [Akamai NetSession Interface] "C:\Users\sandro\AppData\Local\Akamai\netsession_win.exe" [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-11-27] (Google Inc.)
HKCU\...\Run: [Facebook Update] "C:\Users\sandro\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-12] (Facebook Inc.)
HKCU\...\Run: [Epson Stylus SX430(Netzwerk)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE /FU "C:\Users\sandro\AppData\Local\Temp\E_SE245.tmp" /EF "HKCU" [190 2012-09-19] () <===== ATTENTION
HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-12-15] ()
HKCU\...\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [438272 2013-05-24] (NEXON Inc.)
MountPoints2: {35d35095-474a-11e0-aa06-806e6f6e6963} - E:\Install.exe
HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [1564872 2012-06-06] (Ask)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [2255184 2013-06-28] (LogMeIn Inc.)
Startup: C:\Users\sandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: BFlix Class - {0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - C:\Program Files (x86)\BFlix\BFlix.dll (BFlix)
BHO-x32: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\sandro\AppData\Roaming\Mozilla\Firefox\Profiles\cbvbaj65.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\sandro\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\sandro\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Extension: (Google Docs) - C:\Users\sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Bflix) - C:\Users\sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpojpihgafjhbgkgaglhighomjceieff\1.4_0
CHR Extension: (Gmail) - C:\Users\sandro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] ()
S3 athrusb; C:\Windows\System32\DRIVERS\athrxusb.sys [1075712 2008-07-29] (Atheros Communications, Inc.)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
S3 X6va005; \??\C:\Users\sandro\AppData\Local\Temp\0055418.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-05 14:35 - 2013-07-05 14:35 - 00000000 ____D C:\FRST
2013-07-04 14:55 - 2013-07-04 21:21 - 00000000 ____D C:\Users\sandro\Desktop\newmc
2013-07-02 16:35 - 2013-07-02 16:35 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-06-28 16:02 - 2013-06-28 16:02 - 00000175 ____A C:\Windows\System32\Drivers\aswVmm.sys.sum
2013-06-26 20:40 - 2013-06-28 16:02 - 00000175 ____A C:\Windows\System32\Drivers\aswSP.sys.sum
2013-06-26 20:40 - 2013-06-28 16:02 - 00000175 ____A C:\Windows\System32\Drivers\aswSnx.sys.sum
2013-06-20 18:44 - 2013-06-20 18:53 - 00000000 ____D C:\Users\sandro\AppData\Roaming\Audacity
2013-06-20 18:43 - 2013-06-20 18:43 - 00001007 ____A C:\Users\sandro\Desktop\Audacity.lnk
2013-06-20 18:42 - 2013-06-20 18:43 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-06-18 20:10 - 2013-06-18 20:10 - 00000000 ____A C:\Users\sandro\Desktop\Neues Textdokument.txt
2013-06-15 23:12 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-15 23:12 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-15 23:12 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-15 23:12 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-15 23:12 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-15 23:12 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-15 23:12 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-15 23:12 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-15 23:12 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-15 23:12 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-15 23:12 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-15 23:12 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-15 20:17 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-15 20:17 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-15 20:17 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-15 20:17 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-15 20:17 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-15 20:17 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-15 20:17 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-15 20:17 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-15 20:17 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-15 20:17 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-15 20:17 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-15 20:17 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-15 20:17 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-14 19:05 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-14 19:05 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-14 19:05 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-14 19:04 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-14 19:04 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-14 19:02 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-14 19:02 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-14 19:02 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-14 19:02 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-14 19:02 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-14 19:02 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-14 19:02 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-14 19:02 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-14 19:02 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-14 19:02 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-14 19:02 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-14 19:02 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-14 19:00 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-14 19:00 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-12 15:32 - 2013-06-12 15:32 - 00002183 ____A C:\Users\sandro\.recently-used.xbel
2013-06-12 15:29 - 2013-06-12 15:30 - 04045840 ____A C:\Users\sandro\Desktop\MDC New YouTube Template.xcf
==================== One Month Modified Files and Folders =======
2013-07-05 14:36 - 2012-12-15 17:59 - 00000000 ____D C:\Users\sandro\AppData\Local\PMB Files
2013-07-05 14:35 - 2013-07-05 14:35 - 00000000 ____D C:\FRST
2013-07-05 14:29 - 2011-08-29 14:40 - 00000000 ____D C:\Users\sandro\AppData\Local\LogMeIn Hamachi
2013-07-05 14:28 - 2011-11-27 17:56 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-05 14:28 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-05 14:28 - 2009-07-14 06:51 - 00194381 ____A C:\Windows\setupact.log
2013-07-05 14:24 - 2011-03-04 22:52 - 01819810 ____A C:\Windows\WindowsUpdate.log
2013-07-05 14:04 - 2012-11-10 22:04 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-05 13:41 - 2012-01-17 17:08 - 00001120 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3034911989-112592130-3386621625-1001Core.job
2013-07-05 13:41 - 2011-11-27 17:56 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-05 13:30 - 2012-01-17 17:08 - 00001142 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3034911989-112592130-3386621625-1001UA.job
2013-07-04 21:31 - 2009-07-14 06:45 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-04 21:31 - 2009-07-14 06:45 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-04 21:26 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2013-07-04 21:23 - 2011-03-05 18:37 - 00001922 ____A C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-07-04 21:23 - 2011-03-05 18:37 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2013-07-04 21:23 - 2011-03-05 15:59 - 00000000 ____D C:\users\sandro
2013-07-04 21:22 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-04 21:21 - 2013-07-04 14:55 - 00000000 ____D C:\Users\sandro\Desktop\newmc
2013-07-04 21:21 - 2012-12-15 17:59 - 00000000 ____D C:\ProgramData\PMB Files
2013-07-04 21:21 - 2011-11-10 14:54 - 00000000 ____D C:\Users\sandro\AppData\Local\Akamai
2013-07-04 21:21 - 2011-07-10 20:07 - 00000000 ____D C:\Users\sandro\AppData\Roaming\.minecraft
2013-07-04 21:21 - 2011-06-19 17:32 - 00000000 ____D C:\Users\sandro\AppData\Roaming\Skype
2013-07-04 21:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-03 20:36 - 2012-12-26 21:25 - 00000000 ____D C:\Users\sandro\AppData\Roaming\Minecraft Version Changer
2013-07-02 16:35 - 2013-07-02 16:35 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-06-28 17:43 - 2011-11-18 18:52 - 00000000 ____D C:\Users\sandro\Desktop\Dokumente
2013-06-28 16:02 - 2013-06-28 16:02 - 00000175 ____A C:\Windows\System32\Drivers\aswVmm.sys.sum
2013-06-28 16:02 - 2013-06-26 20:40 - 00000175 ____A C:\Windows\System32\Drivers\aswSP.sys.sum
2013-06-28 16:02 - 2013-06-26 20:40 - 00000175 ____A C:\Windows\System32\Drivers\aswSnx.sys.sum
2013-06-28 16:02 - 2013-05-18 20:40 - 00189936 ____A C:\Windows\System32\Drivers\aswVmm.sys
2013-06-28 16:02 - 2011-03-05 18:37 - 01030952 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-06-28 16:02 - 2011-03-05 18:37 - 00378944 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-06-25 17:12 - 2013-02-03 19:45 - 00000000 ____D C:\Users\sandro\AppData\Roaming\Football Superstars
2013-06-22 20:53 - 2013-04-05 14:32 - 00002183 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-20 18:53 - 2013-06-20 18:44 - 00000000 ____D C:\Users\sandro\AppData\Roaming\Audacity
2013-06-20 18:43 - 2013-06-20 18:43 - 00001007 ____A C:\Users\sandro\Desktop\Audacity.lnk
2013-06-20 18:43 - 2013-06-20 18:42 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-06-20 17:47 - 2013-04-25 16:50 - 00000000 ____D C:\Users\sandro\AppData\Roaming\TS3Client
2013-06-19 18:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-18 20:10 - 2013-06-18 20:10 - 00000000 ____A C:\Users\sandro\Desktop\Neues Textdokument.txt
2013-06-15 20:18 - 2011-03-05 22:42 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 18:06 - 2012-08-22 20:50 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 18:06 - 2012-08-22 20:50 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 15:33 - 2012-01-21 19:06 - 00000000 ____D C:\Users\sandro\.gimp-2.6
2013-06-12 15:32 - 2013-06-12 15:32 - 00002183 ____A C:\Users\sandro\.recently-used.xbel
2013-06-12 15:30 - 2013-06-12 15:29 - 04045840 ____A C:\Users\sandro\Desktop\MDC New YouTube Template.xcf
2013-06-08 16:08 - 2013-06-15 23:12 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-15 23:12 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-15 23:12 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-15 23:12 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-15 23:12 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-15 23:12 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-15 23:12 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-15 23:12 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-15 23:12 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-15 23:12 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-15 23:12 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-15 23:12 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-08 11:45 - 2013-05-11 17:43 - 00000000 ____D C:\Users\sandro\Desktop\+++ GSN +++
Files to move or delete:
====================
C:\Users\sandro\AppData\Roaming\skype.dat
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-04 23:58
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013
Ran by sandro at 2013-07-05 14:37:36
Running from D:\sandro\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Shockwave Player 11.6 (x32 Version: 11.6.3.633)
Akamai NetSession Interface (HKCU)
Akamai NetSession Interface Service (x32)
ALPS Touch Pad Driver
Ask Toolbar (x32 Version: 1.15.4.0)
Ask Toolbar Updater (HKCU Version: 1.2.2.23821)
Audacity 2.0.3 (x32 Version: 2.0.3)
avast! Free Antivirus (x32 Version: 8.0.1489.0)
Babylon toolbar on IE (x32)
Bandisoft MPEG-1 Decoder (x32)
BFlix (x32 Version: 0.0.0.1)
CamStudio OSS Desktop Recorder (x32 Version: 2.6 Beta r294)
Command & Conquer Alarmstufe Rot 2 (x32)
EA Installer (x32 Version: 2.3.0.74)
Energy Management (x32 Version: 4.4.1.3)
Epson Easy Photo Print 2 (x32 Version: 2.2.4.0)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (x32 Version: 1.00.0000)
Epson Event Manager (x32 Version: 2.50.0000)
EPSON Scan (x32)
EPSON SX430 Series Printer Uninstall
EpsonNet Print (x32 Version: 2.5.00)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287)
Football Superstars (x32)
Foxit Reader (x32 Version: 4.3.1.218)
FUSSBALL MANAGER 11 (x32)
FUSSBALL MANAGER 13 (x32 Version: 1.0.0.0)
GIMP 2.6.11 (x32 Version: 2.6.11)
Google Chrome (x32 Version: 27.0.1453.116)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358)
Google Update Helper (x32 Version: 1.3.21.145)
Grand Theft Auto San Andreas (x32 Version: 1.00.00001)
Intel® Matrix Storage Manager
Java Auto Updater (x32 Version: 2.0.7.1)
Java(TM) 6 Update 31 (x32 Version: 6.0.310)
Lenovo EasyCamera (x32 Version: 6.96.2018.19)
Lenovo OneKey Recovery (Version: 7.0.0723)
Lenovo OneKey Recovery (x32 Version: 7.0.0723)
LogMeIn Hamachi (x32 Version: 2.1.0.374)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 14.0.1 (x86 de) (x32 Version: 14.0.1)
Nokia Connectivity Cable Driver (Version: 7.1.32.64)
OpenOffice.org 3.2 (x32 Version: 3.2.9502)
Opera 12.14 (x32 Version: 12.14.1738)
Origin (x32 Version: 9.0.11.77)
Pando Media Booster (x32 Version: 2.6.0.8)
Project 64 version 2.1.0.1 (x32 Version: 2.1.0.1)
Project Blackout (x32 Version: )
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30101)
Skype Click to Call (x32 Version: 6.9.12585)
Skype™ 5.10 (x32 Version: 5.10.116)
swMSM (x32 Version: 12.0.0.1)
TeamSpeak 3 Client (HKCU Version: 3.0.10)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Warcraft III (x32)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (05/19/2009 4.4.0.1) (Version: 05/19/2009 4.4.0.1)
WinRAR 4.01 (64-Bit) (Version: 4.01.0)
Zattoo4 4.0.5 (x32 Version: 4.0.5)
==================== Restore Points =========================
22-06-2013 18:47:32 Windows Update
28-06-2013 14:07:09 Windows Update
02-07-2013 14:40:32 Windows Update
04-07-2013 19:28:13 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {048D5216-36DA-4457-A35E-E00337E398F6} - System32\Tasks\{3914F047-8A3C-42C2-A7F5-23DFE1452232} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {093992E8-F3C0-4F8B-B9B2-BF5B03DEBF3A} - System32\Tasks\{C36844BF-1B88-482E-B664-317088A2DBF9} => C:\Westwood\AR2\Ra2.exe [2000-09-26] ()
Task: {25482094-A5AE-43A5-B2E8-72464527C744} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-06-06] ()
Task: {36D5F236-EC69-4C04-A052-1BBFF82354DC} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3034911989-112592130-3386621625-1001UA => C:\Users\sandro\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {4E6FDA33-63FE-4398-B092-B1C1F3635ABF} - System32\Tasks\{C5FF24DB-767B-4190-86A3-3009EF507C49} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {522F0EEC-3479-4622-9930-3567E1CF9E88} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3034911989-112592130-3386621625-1001Core => C:\Users\sandro\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {5A7B0631-CEA1-44F5-9764-DAC7E261A0AC} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {5BBDD473-F007-4667-A541-5D3B6924D18B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software)
Task: {5CD085F7-FD7D-4158-9FFA-C7DDBC073D1E} - System32\Tasks\{F08C5F5F-1C85-4B40-9731-CA161CA8390A} => C:\Program Files (x86)\Internet Explorer\iexplore.exe [2013-05-17] (Microsoft Corporation)
Task: {6936595E-3F7F-464C-B7A5-42A8EE75CC11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-27] (Google Inc.)
Task: {7C777167-5A6B-4F2E-BF45-CC8032EEC71B} - System32\Tasks\{C64A5FFA-E7F6-4076-B3F9-BC74AFD179DD} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {809FD736-B83D-4294-822D-9F0DF2223D92} - System32\Tasks\{915C6DC5-C0BB-490C-968E-901D5E8A2FCB} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.)
Task: {896AA68E-DA3E-45B3-8D3B-39AEF56914EE} - System32\Tasks\{F586CC48-9D19-4E72-B120-041CBEEE72D1} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {8B07FA57-92EB-4881-8970-018F2D78D386} - System32\Tasks\{5FBB55DB-2206-48F7-85B1-6CD3B3D783A0} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {9296B8E8-5D6B-4CC7-A2CD-10222BDA844D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated)
Task: {97DE3D6E-E886-4958-B62A-C5FD2B434864} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-27] (Google Inc.)
Task: {B4CACC1A-CA3E-4FD6-9BB9-D3B83C77938E} - System32\Tasks\{A3473245-71FE-488B-9F14-A3965AF51302} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {D017A432-05AB-4B85-AFBE-96CF59E4730F} - System32\Tasks\{5560F507-3EE8-47BC-8CB9-824F07C19401} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {DD73687C-AFD7-464D-928B-ADA0D6401B79} - System32\Tasks\{912D22B4-E3C7-4A73-B38E-C7D1CCAA0863} => C:\Westwood\AR2\Ra2.exe [2000-09-26] ()
Task: {E9108E9F-19B5-4418-92C8-938AEEDF18E4} - System32\Tasks\User_Feed_Synchronization-{EE430275-9846-41B8-8D93-4187B249ADDB} => C:\Windows\system32\msfeedssync.exe [2013-05-29] (Microsoft Corporation)
Task: {EED86218-6749-405B-834B-5C8F7A25BE5B} - System32\Tasks\{77685FF6-995C-4B72-A184-61E9AD9AE0CA} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {F79EA3A4-C859-4537-AC0B-52F48809BE28} - System32\Tasks\{2A32CB64-F38E-45DB-B53B-763D4844055C} => C:\program files (x86)\mozilla firefox\firefox.exe [2012-07-14] (Mozilla Corporation)
Task: {FA4E86A9-8F60-41FA-ACDB-2A4A3EFB23C5} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3034911989-112592130-3386621625-1001Core.job => C:\Users\sandro\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3034911989-112592130-3386621625-1001UA.job => C:\Users\sandro\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/04/2013 08:53:16 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000a7087
ID des fehlerhaften Prozesses: 0x424
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (07/02/2013 09:58:35 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (07/01/2013 06:20:15 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/27/2013 07:24:16 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe, Version: 11.7.700.224, Zeitstempel: 0x51a67447
Name des fehlerhaften Moduls: MMDevApi.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b892
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00023b0c
ID des fehlerhaften Prozesses: 0x12d8
Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_7_700_224.exe0
Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe1
Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_7_700_224.exe2
Berichtskennung: FlashPlayerPlugin_11_7_700_224.exe3
Error: (06/25/2013 05:12:02 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/19/2013 06:20:20 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/19/2013 05:05:17 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/14/2013 06:51:30 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 14.0.1.4577 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 12c0
Startzeit: 01ce691e57af2443
Endzeit: 185
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: a326df96-d512-11e2-92cf-1c7508516d4a
Error: (06/12/2013 06:37:48 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/10/2013 07:07:28 PM) (Source: Application Hang) (User: )
Description: Programm gta_sa.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: ccc
Startzeit: 01ce65fcc72854d4
Endzeit: 19
Anwendungspfad: C:\Program Files (x86)\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe
Berichts-ID:
System errors:
=============
Error: (07/05/2013 01:29:56 PM) (Source: Server) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{ED0AFD4C-B987-4ED9-A30B-EAD19F53418F} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.
Error: (07/04/2013 09:17:57 PM) (Source: DCOM) (User: )
Description: 1084wuauserv{E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error: (07/04/2013 09:16:41 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
AFD
aswRdr
aswRvrt
aswSnx
aswSP
aswTdi
aswVmm
CSC
DfsC
discache
NetBIOS
NetBT
nsiproxy
Psched
rdbss
spldr
tdx
vwififlt
Wanarpv6
WfpLwf
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Network Location Awareness" ist vom Dienst "Network Store Interface Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SMB 2.0 MiniRedirector" ist vom Dienst "SMB MiniRedirector Wrapper and Engine" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SMB 1.x MiniRedirector" ist vom Dienst "SMB MiniRedirector Wrapper and Engine" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SMB MiniRedirector Wrapper and Engine" ist vom Dienst "Redirected Buffering Sub Sysytem" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%31
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IP Helper" ist vom Dienst "Network Store Interface Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Workstation" ist vom Dienst "Network Store Interface Service" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (07/04/2013 09:16:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Network Store Interface Service" ist vom Dienst "NSI proxy service driver." abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%31
Microsoft Office Sessions:
=========================
Error: (07/04/2013 08:53:16 PM) (Source: Application Error)(User: )
Description: Explorer.EXE6.1.7601.175674d672ee4Explorer.EXE6.1.7601.175674d672ee4c000000500000000000a708742401ce78b176e7451bC:\Windows\Explorer.EXEC:\Windows\Explorer.EXEfc0e8607-e4da-11e2-bf53-1c7508516d4a
Error: (07/02/2013 09:58:35 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\Users\sandro\AppData\Roaming\football superstars\DevWidgetsR_msvcrt.dllc:\Users\sandro\AppData\Roaming\football superstars\Microsoft.VC90.CRT.MANIFEST4
Error: (07/01/2013 06:20:15 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\Users\sandro\AppData\Roaming\football superstars\DevWidgetsR_msvcrt.dllc:\Users\sandro\AppData\Roaming\football superstars\Microsoft.VC90.CRT.MANIFEST4
Error: (06/27/2013 07:24:16 PM) (Source: Application Error)(User: )
Description: FlashPlayerPlugin_11_7_700_224.exe11.7.700.22451a67447MMDevApi.dll6.1.7601.175144ce7b892c000000500023b0c12d801ce735aa6b0f0abC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exeC:\Windows\System32\MMDevApi.dll644f2feb-df4e-11e2-a84a-1c7508516d4a
Error: (06/25/2013 05:12:02 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"C:\Users\sandro\AppData\Roaming\Football Superstars\DevWidgetsR_msvcrt.dllC:\Users\sandro\AppData\Roaming\Football Superstars\Microsoft.VC90.CRT.MANIFEST4
Error: (06/19/2013 06:20:20 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\Users\sandro\AppData\Roaming\football superstars\DevWidgetsR_msvcrt.dllc:\Users\sandro\AppData\Roaming\football superstars\Microsoft.VC90.CRT.MANIFEST4
Error: (06/19/2013 05:05:17 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\Users\sandro\AppData\Roaming\football superstars\DevWidgetsR_msvcrt.dllc:\Users\sandro\AppData\Roaming\football superstars\Microsoft.VC90.CRT.MANIFEST4
Error: (06/14/2013 06:51:30 PM) (Source: Application Hang)(User: )
Description: firefox.exe14.0.1.457712c001ce691e57af2443185C:\Program Files (x86)\Mozilla Firefox\firefox.exea326df96-d512-11e2-92cf-1c7508516d4a
Error: (06/12/2013 06:37:48 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.4148"Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\Users\sandro\AppData\Roaming\football superstars\DevWidgetsR_msvcrt.dllc:\Users\sandro\AppData\Roaming\football superstars\Microsoft.VC90.CRT.MANIFEST4
Error: (06/10/2013 07:07:28 PM) (Source: Application Hang)(User: )
Description: gta_sa.exe0.0.0.0ccc01ce65fcc72854d419C:\Program Files (x86)\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe
==================== Memory info ===========================
Percentage of memory in use: 61%
Total physical RAM: 2008.6 MB
Available physical RAM: 763.32 MB
Total Pagefile: 4017.2 MB
Available Pagefile: 2583.37 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:135.13 GB) (Free:62.95 GB) NTFS (Disk=0 Partition=2)
Drive d: () (Fixed) (Total:97.66 GB) (Free:80.58 GB) NTFS (Disk=0 Partition=3)
Drive e: (GTA_SAN_ANDREAS) (CDROM) (Total:3.93 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: C3FFC3FF)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=135 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |