Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-07-2013
Ran by Thomas at 2013-07-19 16:02:06
Running from C:\Users\Thomas\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3)
Adobe After Effects CS4 (x32 Version: 9)
Adobe After Effects CS4 Presets (x32 Version: 9)
Adobe After Effects CS4 Third Party Content (x32 Version: 9)
Adobe Anchor Service CS4 (x32 Version: 2.0)
Adobe CMaps CS4 (x32 Version: 2.0)
Adobe Color Video Profiles AE CS4 (x32 Version: 2.0)
Adobe Default Language CS4 (x32 Version: 2.0)
Adobe Dynamiclink Support (x32 Version: 1)
Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.5.502.135)
Adobe Fonts All (x32 Version: 2.0)
Adobe Media Encoder CS4 Exporter (x32 Version: 1.0)
Adobe Media Encoder CS4 Importer (x32 Version: 1.0)
Adobe MotionPicture Color Files CS4 (x32 Version: 2.0)
Adobe Output Module (x32 Version: 2.0)
Adobe PDF Library Files CS4 (x32 Version: 9.0)
Adobe Setup (x32 Version: 2.0)
Adobe Type Support CS4 (x32 Version: 9.0)
Adobe Update Manager CS4 (x32 Version: 6.0.0)
Adobe XMP Panels CS4 (x32 Version: 2.0)
AdobeColorCommonSetRGB (x32 Version: 2.0)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.95)
AMD Accelerated Video Transcoding (Version: 2.00.0002)
AMD APP SDK Runtime (Version: 10.0.923.1)
AMD Catalyst Install Manager (Version: 8.0.873.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2012.0405.2205.37728)
AMD Media Foundation Decoders (Version: 1.0.70405.2224)
AMD VISION Engine Control Center (x32 Version: 2012.0405.2205.37728)
Amnesia - The Dark Descent (x32 Version: 1.2)
Apple Application Support (x32 Version: 2.1.7)
Apple Software Update (x32 Version: 2.1.3.127)
aTube Catcher (x32 Version: 2.9.1328)
aTube Toolbar (x32 Version: 1.0.0.12)
Audiosurf (x32)
Battlefield: Bad Company 2 (x32)
be Flash Player 11 Plugin 64-bit (Version: 11.2.202.233)
Beat Hazard (x32)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95)
BioShock (x32 Version: 2.5.0000)
BioShock 2 (x32 Version: 1.00.0000)
BitTorrent (x32 Version: 7.6.1)
Call of Duty 4: Modern Warfare (x32)
Call of Duty: Black Ops II - Multiplayer (x32)
Call of Duty: Black Ops II - Zombies (x32)
Call of Duty: Black Ops II (x32)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0405.2205.37728)
Catalyst Control Center InstallProxy (x32 Version: 2012.0405.2205.37728)
Catalyst Control Center Localization All (x32 Version: 2012.0405.2205.37728)
CCC Help Chinese Standard (x32 Version: 2012.0405.2204.37728)
CCC Help Chinese Traditional (x32 Version: 2012.0405.2204.37728)
CCC Help Czech (x32 Version: 2012.0405.2204.37728)
CCC Help Danish (x32 Version: 2012.0405.2204.37728)
CCC Help Dutch (x32 Version: 2012.0405.2204.37728)
CCC Help English (x32 Version: 2012.0405.2204.37728)
CCC Help Finnish (x32 Version: 2012.0405.2204.37728)
CCC Help French (x32 Version: 2012.0405.2204.37728)
CCC Help German (x32 Version: 2012.0405.2204.37728)
CCC Help Greek (x32 Version: 2012.0405.2204.37728)
CCC Help Hungarian (x32 Version: 2012.0405.2204.37728)
CCC Help Italian (x32 Version: 2012.0405.2204.37728)
CCC Help Japanese (x32 Version: 2012.0405.2204.37728)
CCC Help Korean (x32 Version: 2012.0405.2204.37728)
CCC Help Norwegian (x32 Version: 2012.0405.2204.37728)
CCC Help Polish (x32 Version: 2012.0405.2204.37728)
CCC Help Portuguese (x32 Version: 2012.0405.2204.37728)
CCC Help Russian (x32 Version: 2012.0405.2204.37728)
CCC Help Spanish (x32 Version: 2012.0405.2204.37728)
CCC Help Swedish (x32 Version: 2012.0405.2204.37728)
CCC Help Thai (x32 Version: 2012.0405.2204.37728)
CCC Help Turkish (x32 Version: 2012.0405.2204.37728)
ccc-utility64 (Version: 2012.0405.2205.37728)
CCleaner (Version: 3.27)
Chuzzle Deluxe (x32 Version: 2.2.0.95)
Counter-Strike Global Offensive Beta - Dedicated Server (x32)
Counter-Strike: Global Offensive Beta (x32)
Counter-Strike: Source (x32)
Darksiders (x32)
Dead Space™ 3 (x32 Version: 1.0.0.0)
Diablo III (x32 Version: 1.0.3.10057)
Die Sims™ 3 (x32 Version: 1.0.632)
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95)
Dota 2 (x32)
DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4030)
eReg (x32 Version: 1.20.138.34)
ESL Wire 1.14.1
Fallout: New Vegas (x32)
FATE (x32 Version: 2.2.0.95)
ffdshow v1.2.4422 [2012-04-09] (x32 Version: 1.2.4422.0)
FIFA 12 (c) EA version 1 (x32 Version: 1)
Fraps (remove only) (x32)
From Dust (x32 Version: 1.0.0)
Google Chrome (HKCU Version: 28.0.1500.72)
Guild Wars 2 (x32)
Gyazo 1.0 (x32)
HP Advisor (x32 Version: 3.4.10262.3295)
HP Customer Experience Enhancements (x32 Version: 6.0.1.4)
HP Game Console (x32)
HP Games (x32 Version: 1.0.1.3)
HP MediaSmart DVD (x32 Version: 4.1.4229)
HP MediaSmart Music (x32 Version: 4.1.4301)
HP MediaSmart Photo (x32 Version: 4.1.4211)
HP MediaSmart SmartMenu (Version: 3.1.1.12)
HP MediaSmart Video (x32 Version: 4.1.4214)
HP Odometer (x32 Version: 2.10.0000)
HP Setup (x32 Version: 8.1.4186.3400)
HP Support Assistant (x32 Version: 5.0.11.16)
HP Support Information (x32 Version: 10.1.0002)
HP Update (x32 Version: 5.002.003.003)
HP Vision Hardware Diagnostics (Version: 2.1.2.27173)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3)
HydraVision (x32 Version: 4.2.166.0)
ICQ7M (x32 Version: 7.8)
Insaniquarium Deluxe (x32 Version: 2.2.0.95)
Internet Explorer Toolbar 4.6 by SweetPacks (x32 Version: 4.6.0004)
Java Auto Updater (x32 Version: 2.1.6.0)
Java(TM) 7 Update 4 (64-bit) (Version: 7.0.40)
Java(TM) 7 Update 4 (x32 Version: 7.0.40)
JavaFX 2.1.0 (x32 Version: 2.1.0)
Jewel Quest II (x32 Version: 2.2.0.95)
Jewel Quest Solitaire (x32 Version: 2.2.0.95)
John Deere Drive Green (x32 Version: 2.2.0.95)
Junk Mail filter update (x32 Version: 14.0.8089.726)
LabelPrint (x32 Version: 2.5.2823)
Lagarith Lossless Codec (1.3.27) (x32)
League of Legends (x32 Version: 1.02.0000)
LightScribe System Software (x32 Version: 1.18.15.1)
Logitech Gaming Software (Version: 8.20.74)
Logitech Gaming Software 8.20 (Version: 8.20.74)
LOLReplay (x32 Version: 0.8.1.4)
Lucius 1.01.3173 (x32 Version: 1.01.3173)
Magic Bullet Suite 64-bit (Version: 11.4.1)
Magic Bullet Suite 64-bit (x32 Version: 11.4.1)
Magic Desktop (x32)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mass Effect™ 3 (x32 Version: 1.01.0.0)
MATLAB Component Runtime 7.7 (x32 Version: 7.7)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (x32 Version: 2.0.48.0)
Microsoft Games for Windows - LIVE (x32 Version: 3.1.186.0)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.1.99.0)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (x32 Version: 4.1.10329.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
mIRC (x32 Version: 7.22)
Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030)
Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7)
MSVCRT (x32 Version: 14.0.1468.721)
MSVCRT Redists (Version: 1.0)
MSVCRT Redists (x32 Version: 1.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MusicStation (x32 Version: 1.0.1.5)
My Game Long Name
Norton 360 (x32 Version: 20.4.0.40)
NVIDIA Drivers (Version: 1.10.61.39)
NVIDIA PhysX (x32 Version: 9.11.1107)
Open Broadcaster Software (x32)
OpenAL (x32)
osu! (x32 Version: 0.0.0.0)
Pando Media Booster (x32 Version: 2.6.0.7)
PC Wizard 2012.2.0 (x32)
PDF Complete Special Edition (x32 Version: 3.5.111)
Penguins! (x32 Version: 2.2.0.95)
PhotoNow! (x32 Version: 1.1.6904)
Photoshop Camera Raw (x32 Version: 5.0)
PictureMover (x32 Version: 3.5.0.28)
Plants vs. Zombies (x32 Version: 2.2.0.95)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Polar Bowler (x32 Version: 2.2.0.95)
Power2Go (x32 Version: 6.1.4022)
PowerDirector (x32 Version: 8.0.2906)
Prototype(TM) (x32 Version: 1.0)
QuickTime (x32 Version: 7.72.80.56)
RAGE (x32)
Rainmeter (x32 Version: 2.2 r1116)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6132)
Recovery Manager (x32 Version: 5.5.2926)
S.T.A.L.K.E.R. - Call Of Pripyat [v1.6.01] (x32 Version: 1.6.01)
Skype™ 5.10 (x32 Version: 5.10.116)
Slingo Deluxe (x32 Version: 2.2.0.95)
Spotify (HKCU Version: 0.9.1.57.ge7405149)
StarCraft II (x32 Version: 2.0.9.26147)
Steam (x32 Version: 1.0.0.0)
Suite Shared Configuration CS4 (x32 Version: 1.0)
TeamSpeak 3 Client (x32 Version: 3.0.10.1)
TeamViewer 8 (x32 Version: 8.0.16642)
TERA (x32 Version: 19.04.02.03.hf3)
The Walking Dead (c) 3 version 1 (x32 Version: 1)
The Walking Dead (x32)
TZAC ANTICHEAT 2 (x32 Version: 2)
Ubisoft Game Launcher (x32 Version: 1.0.0.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update Manager for SweetPacks 1.1 (x32 Version: 1.1.0008)
Vegas Pro 10.0 (64-bit) (Version: 10.0.738)
Virtual Villagers - The Secret City (x32 Version: 2.2.0.95)
Wedding Dash (x32 Version: 2.2.0.95)
Windows Live Call (x32 Version: 14.0.8064.0206)
Windows Live Communications Platform (x32 Version: 14.0.8064.206)
Windows Live Essentials (x32 Version: 14.0.8089.0726)
Windows Live Essentials (x32 Version: 14.0.8089.726)
Windows Live Fotogalerie (x32 Version: 14.0.8081.709)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)
Windows Live Mail (x32 Version: 14.0.8089.0726)
Windows Live Messenger (x32 Version: 14.0.8089.0726)
Windows Live Sync (x32 Version: 14.0.8089.726)
Windows Live Writer (x32 Version: 14.0.8089.0726)
Windows Live-Uploadtool (x32 Version: 14.0.8014.1029)
WinRAR 4.11 (32-Bit) (x32 Version: 4.11.0)
World of Warcraft (x32 Version: 5.3.0.17128)
Xfire (remove only) (x32)
XSplit (x32 Version: 1.1.1209.0601)
ZoomEx (Version: 1.0)
Zuma Deluxe (x32 Version: 2.2.0.95)
==================== Restore Points =========================
18-07-2013 19:23:40 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0506CAFF-B409-4CB7-9C39-55CE64F1FD60} - System32\Tasks\{4B058D46-4E13-42AA-A958-47C57A55EB2D} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {0E8042EE-45B0-4866-9016-71175193D4B4} - System32\Tasks\{AC27E048-A0D5-44A2-BCB5-2C6E240B1D39} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {10D6D9B7-E6B8-4A8B-B180-319FB42FAB7A} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] ()
Task: {19A7BC0E-E671-4C94-B92A-3AD32219D38B} - System32\Tasks\{BB21EA02-8F78-42FB-BDAB-D8F52AE12437} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {1E0AF271-83CB-4C42-95BD-A14E8F59FEBF} - System32\Tasks\{C2FB6E04-D7A2-4AB5-8F34-69601B1C3ECB} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {353749CA-12D1-4691-82F6-204DD655FA56} - System32\Tasks\{6195DA7A-9123-4002-B8D4-BE995932FC98} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {4877E900-016A-4FD2-9415-D6FDA891C975} - System32\Tasks\{DBBECB5E-92C1-4F69-A453-294BBE75BE4A} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {53266036-4171-40EF-A73A-170046BE3C2F} - System32\Tasks\{D98A728C-9280-4150-8140-246856147BF1} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {5A2CD3B8-203E-4FF2-90A9-5CBAB5E33EC3} - System32\Tasks\{332D1F18-3C9B-43ED-8CDB-1BB11E9CC084} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {5B7A5AFC-95E9-4AEC-89EF-3F65D526A255} - System32\Tasks\{7C0C073B-EF12-4E9E-AFDC-0230BBDAF335} => C:\Counter-Strike 1.6 Mini\hlupdate.exe No File
Task: {5C50A6BB-7F85-4751-825E-09CAE0AE2500} - System32\Tasks\{B6B47F50-62CD-4F5F-AD2A-B9AFD1D25F96} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {664A0DA9-AA9C-48A4-9EA0-CA629FEC1225} - System32\Tasks\{1AE1C097-21B6-4F7D-AACD-52E7D3F37C48} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlds.exe [2003-11-14] (Valve)
Task: {7023A11B-3C1C-42B8-8380-444B92AE111E} - System32\Tasks\{DE3201B3-5506-4309-8B7D-8C5D5C43AACC} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {757320D7-049D-4AC3-8058-D437B55AC852} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {7CC9AAFA-494A-44A0-985E-212607EDD13A} - System32\Tasks\{3541458F-6A3A-47DE-9A59-5B4D5FBED56B} => C:\program files (x86)\mozilla firefox\firefox.exe No File
Task: {7E47136D-06E5-4CBB-A4D0-B616EFFD5BC8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {7E76DBD0-DF74-4629-B4ED-7648F85365A0} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] ()
Task: {7FFEF84E-68C7-4B23-85CB-BF373785296C} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] ()
Task: {85928B67-E76B-4393-84BA-89A6083B3516} - System32\Tasks\{31E78281-B712-40C6-9CA9-34B259C9653C} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {8A54ED3B-2604-4108-B7BB-CD1D12518FE7} - System32\Tasks\{1B624F83-E6F3-4843-A760-F6380B4B214F} => C:\Program Files (x86)\Metro Last Light\MetroLL.exe No File
Task: {8CD92F97-2F1C-401F-B104-AD875D60C44D} - System32\Tasks\{31CF1282-D6DB-4D97-9037-4A00E1E676AF} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {94371FF7-BB38-4A2C-9B5C-AEEE893A1927} - System32\Tasks\{7A265765-3807-4542-A510-89E7F613B51B} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {9B5B95D8-C095-4929-A269-1324C7705EE2} - System32\Tasks\{3007051E-A6AD-4856-B51E-E5047D05BE25} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {A34EEE9B-660B-409A-9F2C-106405F0FFAE} - System32\Tasks\{9EFDB496-3F35-4201-94FC-0C21DBA3B8AD} => C:\Counter-Strike 1.6 Mini\hlupdate.exe No File
Task: {A3CF71F9-CBD3-4DCC-A66F-9F1D5AA6C48B} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {ADCB2EC0-A8D6-4DFF-8334-00F4BAF88946} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd)
Task: {B4342D9F-89B1-4174-900B-8458659A22A7} - System32\Tasks\{7A2D8C2C-3DBB-4BE5-B7DD-AAE8D5E03124} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {B443C4D4-2F2C-4620-B5D1-C6C8884764DE} - System32\Tasks\{D44CEBB5-5D6D-4A31-ABCB-D858F1068CF1} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {B4D3C018-C956-4833-9753-5831BF9F6897} - System32\Tasks\RunAsStdUser Task => C:\Users\Thomas\AppData\Local\RavenBleuSA\bin\1.0.11.0\RavenBleuSA.exe No File
Task: {B935756A-19FD-40D2-B861-7992CCD0EBFE} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe No File
Task: {B95D05AC-7D77-4191-8556-310794DF53A8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\First Boot => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2010-06-11] (Hewlett-Packard Company)
Task: {B9ACD865-1CB7-475B-B4ED-393EE2BDD1CD} - System32\Tasks\{00D7E840-C0EF-4BCB-AF65-9F0E0D638EFA} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {BCD4A7D1-1E8F-459D-B4DA-EBB425D04AC1} - System32\Tasks\Game_Booster_Startup => C:\Program Files (x86)\IObit\Game Booster 3\gbtray.exe No File
Task: {C1025E50-1FA6-479E-B0EC-A0827B107BCC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001UA => C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-09] (Google Inc.)
Task: {C31769DC-7D4C-4EE3-9E42-173936669B88} - System32\Tasks\{E764AAB2-291F-48CD-B5BD-C0F074FABA37} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {C3ED11FF-B035-4C06-AA12-E761E82C3CC8} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Common\Red Giant Link.exe [2012-06-25] ()
Task: {C45BEC25-938B-470E-A263-71EFA89A6586} - System32\Tasks\{919192AE-2B82-4672-84ED-4F0B300EC2A9} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {C8FC9037-E815-4AD1-8E30-EE510BE21661} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001Core => C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-09] (Google Inc.)
Task: {CDB18136-A53E-4E33-80C7-019561BCB908} - System32\Tasks\{D3A55335-6357-4820-8290-BEDFDCD19779} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {CEE6DC7A-B929-4C11-8F50-37E40C8124A8} - System32\Tasks\{6E78D882-B5AF-4FFD-8A61-470E12A4DB6C} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hl.exe [2003-12-12] (Valve)
Task: {D2493867-4F21-4A8F-81DD-04EF0AA0463D} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {D432A645-12DD-4F5D-8E6E-5C13950A4C09} - System32\Tasks\{D59F5E6C-E026-45CF-A6A5-EE285B4651E3} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {D587C4C9-2802-4461-98C5-F7E342324E3D} - System32\Tasks\{CD6A54F4-1D52-4014-AC68-9D317A05E377} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlds.exe [2003-11-14] (Valve)
Task: {DD02B20C-DCAF-4A08-90A0-2C5250E4CD35} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-31] (Adobe Systems Incorporated)
Task: {DEF3182D-F2E7-4D6F-A9F3-754FB140F5AB} - System32\Tasks\{8D938569-FD2F-47BE-963B-2C9E800CC5A8} => C:\Counter-Strike 1.6 Mini\hl.exe No File
Task: {E17173A3-FF46-46DC-BF6A-DFE3DF7805DF} - System32\Tasks\{8F52A8C5-B29D-42A9-B9EB-A0D204FA21D7} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {E5516DA9-59FB-4EE3-9528-3AB55B56E25B} - System32\Tasks\{6D8E6FC0-2DEA-4C3E-AA72-953C10BC3BBD} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {E66B2770-2F36-4C33-B732-DCC188B000E1} - System32\Tasks\{9D2E3F92-3C44-4C34-BCB7-B53FF4011EAC} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {E9DA47F3-A900-4C32-A976-0052ED2EDE14} - System32\Tasks\{63522A55-1FF7-407D-9424-93010766DB64} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {EEA01C15-293D-40B8-8A80-2DD1D785011D} - System32\Tasks\{655A8288-41C6-4CC3-A365-1FCF3A6243BE} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {F1F695C3-8F31-4F85-9A04-F7CCDCB66B66} - System32\Tasks\{16A6CAEA-2E76-406C-900F-064FCEE11455} => C:\Program Files (x86)\Metro Last Light\MetroLL.exe No File
Task: {F5B14410-26A3-4B68-9D45-0863540AB0FD} - System32\Tasks\{5B91C125-B450-4E29-9851-F70F76C130BD} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlds.exe [2003-11-14] (Valve)
Task: {FA490460-1196-4031-A312-F85D5F59834B} - System32\Tasks\{E9C8BB16-3278-45AF-B83B-10BDCFC219EE} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: {FC8B9057-7BA1-48A2-8EF7-B356680AB92A} - System32\Tasks\{4B7ADB9A-9409-4BC4-94DF-6364C4B3389D} => C:\Users\Thomas\Desktop\Desktop\Counter-Strike 1.6 Mini\hlupdate.exe [2003-09-26] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001Core.job => C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001UA.job => C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Faulty Device Manager Devices =============
Name: Audiocontroller für Multimedia
Description: Audiocontroller für Multimedia
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/19/2013 01:09:43 PM) (Source: Application Hang) (User: )
Description: Programm yct.exe, Version 2.9.0.1328 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 2a54
Startzeit: 01ce84703a702a20
Endzeit: 24
Anwendungspfad: C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\yct.exe
Berichts-ID: b2c9d341-f063-11e2-8145-7071bcb8416c
Error: (07/19/2013 10:00:22 AM) (Source: CVHSVC) (User: )
Description: Nur zur Information.
Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/18/2013 09:17:37 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (07/18/2013 02:17:34 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw3mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4859a219
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x702f7364
ID des fehlerhaften Prozesses: 0x1f8
Startzeit der fehlerhaften Anwendung: 0xiw3mp.exe0
Pfad der fehlerhaften Anwendung: iw3mp.exe1
Pfad des fehlerhaften Moduls: iw3mp.exe2
Berichtskennung: iw3mp.exe3
Error: (07/18/2013 09:26:13 AM) (Source: CVHSVC) (User: )
Description: Nur zur Information.
Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/17/2013 10:42:02 AM) (Source: CVHSVC) (User: )
Description: Nur zur Information.
Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/16/2013 03:40:05 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (07/16/2013 10:39:00 AM) (Source: CVHSVC) (User: )
Description: Nur zur Information.
Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/15/2013 09:22:20 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {36de849a-1069-403c-a207-f8aa283b1295}
Error: (07/15/2013 07:19:19 PM) (Source: CVHSVC) (User: )
Description: Nur zur Information.
Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
System errors:
=============
Error: (07/19/2013 09:53:16 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2147024891
Error: (07/19/2013 09:53:16 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147024891
Error: (07/19/2013 09:50:05 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet:
%%1060
Error: (07/19/2013 09:50:02 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147024891
Error: (07/19/2013 09:50:02 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert.
Error: (07/19/2013 09:50:02 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IKE- und AuthIP IPsec-Schlüsselerstellungsmodule" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert.
Error: (07/18/2013 09:16:45 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2147024891
Error: (07/18/2013 09:16:45 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147024891
Error: (07/18/2013 09:16:07 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet:
%%1060
Error: (07/18/2013 09:15:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert.
Microsoft Office Sessions:
=========================
Error: (07/19/2013 01:09:43 PM) (Source: Application Hang)(User: )
Description: yct.exe2.9.0.13282a5401ce84703a702a2024C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\yct.exeb2c9d341-f063-11e2-8145-7071bcb8416c
Error: (07/19/2013 10:00:22 AM) (Source: CVHSVC)(User: )
Description: Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/18/2013 09:17:37 PM) (Source: SideBySide)(User: )
Description: Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0"C:\Program Files (x86)\SplitMediaLabs\XSplit\XSplitBroadcasterSrc.exe
Error: (07/18/2013 02:17:34 PM) (Source: Application Error)(User: )
Description: iw3mp.exe0.0.0.04859a219unknown0.0.0.000000000c0000005702f73641f801ce83ae5ff65b60C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 4\iw3mp.exeunknown06619e40-efa4-11e2-9585-7071bcb8416c
Error: (07/18/2013 09:26:13 AM) (Source: CVHSVC)(User: )
Description: Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/17/2013 10:42:02 AM) (Source: CVHSVC)(User: )
Description: Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/16/2013 03:40:05 PM) (Source: SideBySide)(User: )
Description: Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0"C:\Program Files (x86)\SplitMediaLabs\XSplit\XSplitBroadcasterSrc.exe
Error: (07/16/2013 10:39:00 AM) (Source: CVHSVC)(User: )
Description: Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
Error: (07/15/2013 09:22:20 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {36de849a-1069-403c-a207-f8aa283b1295}
Error: (07/15/2013 07:19:19 PM) (Source: CVHSVC)(User: )
Description: Error: Initialization failed 0x80070424 Type: 88::UnexpectedError.
CodeIntegrity Errors:
===================================
Date: 2012-05-12 17:27:41.060
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Thomas\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 17:27:41.007
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Thomas\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 17:27:40.709
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 17:27:40.657
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 13:36:06.344
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 13:36:06.289
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 13:21:39.308
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 13:21:39.215
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 10:49:44.263
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-05-12 10:49:44.200
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 60%
Total physical RAM: 6143.3 MB
Available physical RAM: 2410 MB
Total Pagefile: 12284.8 MB
Available Pagefile: 8520.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:917.82 GB) (Free:419.52 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:13.6 GB) (Free:1.67 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 6D6010DD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=918 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=14 GB) - (Type=07 NTFS)
==================== End Of Log ============================ FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-07-2013
Ran by Thomas (administrator) on 19-07-2013 16:01:28
Running from C:\Users\Thomas\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(ICQ, LLC.) C:\Program Files (x86)\ICQ7M\ICQ.exe
(Spotify Ltd) C:\Users\Thomas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Xfire Inc.) C:\Program Files (x86)\Xfire\xfire.exe
() C:\Program Files (x86)\Xfire\xfire64.exe
() C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.175\deploy\LoLLauncher.exe
() C:\Program Files (x86)\Xfire\xfire64.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.33\deploy\LolClient.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Google Inc.) C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Thomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [5889816 2011-12-07] (Logitech Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [ICQ] - C:\Program Files (x86)\ICQ7M\ICQ.exe [127040 2012-05-21] (ICQ, LLC.)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Thomas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-09] (Spotify Ltd)
HKCU\...\Run: [Google Update] - C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-11-09] (Google Inc.)
HKCR\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Thomas\AppData\Local\{43052835-0e74-b0ab-3a54-c943fa54b21c}\n. ATTENTION! ====> ZeroAccess?
MountPoints2: {96bf5622-dad0-11e1-944c-7071bcb8416c} - G:\Install.exe
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [AMD AVT] - Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-10] ()
HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-10] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=1373230290
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=1373230290
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=1373230290
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=1373230290
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=1373230290
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=1373230290
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=4456516
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {1797871B-E061-4F91-8041-7DE27A1F01E0} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=4456516
SearchScopes: HKLM - {5A1E0467-75EB-4522-BD4B-A3E0F30AAA7D} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM - {AB6CF7E4-1670-4E1F-8F9F-5EAB1A6C08B9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=4456516
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {1797871B-E061-4F91-8041-7DE27A1F01E0} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=4456516
SearchScopes: HKLM-x32 - {5A1E0467-75EB-4522-BD4B-A3E0F30AAA7D} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM-x32 - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = ${SEARCH_URL}{searchTerms}
SearchScopes: HKLM-x32 - {AB6CF7E4-1670-4E1F-8F9F-5EAB1A6C08B9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKCU - DefaultScope {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://searchab.com/?aff=7&uid=b9651e40-5daf-11e2-bc63-7071bcb8416c&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&affID=119779&tt=gc_&babsrc=SP_ss&mntrId=C4117071BCB8416C
SearchScopes: HKCU - {1797871B-E061-4F91-8041-7DE27A1F01E0} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=395049983_1052499_C411A0EC&ts=4456516
SearchScopes: HKCU - {5A1E0467-75EB-4522-BD4B-A3E0F30AAA7D} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
SearchScopes: HKCU - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://searchab.com/?aff=7&uid=b9651e40-5daf-11e2-bc63-7071bcb8416c&q={searchTerms}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={52F3D8F5-E8BA-4376-9C00-CECA2D89F894}&mid=4a5c4610928b47d09ab4a138fa5ca89f-bfe6a4fdef67948ef53788d6361048fce49b0ffe&lang=en&ds=yu011&pr=sa&d=2012-05-12 23:26:50&v=11.0.0.9&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {AB6CF7E4-1670-4E1F-8F9F-5EAB1A6C08B9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKCU - {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=2975613227834282&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
SearchScopes: HKCU - {DB6A597B-B576-4AAD-A5F8-8ED658837C60} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Zoomex - {12EE5012-C58D-703B-D69A-5A5E7467BBB3} - C:\ProgramData\Zoomex\50fed4919db46.dll ()
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: aTube Toolbar - {bfc39e47-d643-4dc2-aa1d-61377501c844} - C:\Program Files (x86)\atube\atubeX.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM-x32 - aTube Toolbar - {bfc39e47-d643-4dc2-aa1d-61377501c844} - C:\Program Files (x86)\atube\atubeX.dll ()
Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL [52920 2010-12-02] (EasyBits Software Corp.)
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 07 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 07 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_233.dll ()
FF Plugin: @java.com/DTPlugin,version=10.4.0 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.4.0 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.4.1 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.4.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Thomas\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Thomas\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\ergative.xml
FF Extension: hdvc - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\profiles\extensions\hdvc@hdvc.com.xpi
FF Extension: trtv3 - C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\profiles\extensions\trtv3@trtv.com.xpi
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Google Drive) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.2_0
CHR Extension: (ProxMate - Improve your Internet!) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\2.3.8_0
CHR Extension: (Gmail) - C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-04-05] (Advanced Micro Devices, Inc.)
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [678416 2012-09-04] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [4135800 2011-05-15] (INCA Internet Co., Ltd.)
S4 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2009-10-15] (PDF Complete Inc)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-05-16] ()
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-06-20] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-06-20] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
S3 cpuz135; C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [23816 2012-02-07] (CPUID)
S3 cpuz135; C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [23816 2012-02-07] (CPUID)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-06-30] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-06-30] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-06-30] (Symantec Corporation)
R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [147472 2012-09-04] (<Turtle Entertainment>)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130718.001\IDSvia64.sys [513184 2013-06-28] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130718.001\IDSvia64.sys [513184 2013-06-28] (Symantec Corporation)
S3 LADF_DHP2; C:\Windows\System32\DRIVERS\ladfDHP2amd64.sys [62168 2010-09-29] (Logitech)
S3 LADF_SBVM; C:\Windows\System32\DRIVERS\ladfSBVMamd64.sys [377176 2010-09-29] (Logitech)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66328 2011-10-24] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130718.033\ENG64.SYS [126040 2013-06-30] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130718.033\ENG64.SYS [126040 2013-06-30] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130718.033\EX64.SYS [2098776 2013-06-30] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130718.033\EX64.SYS [2098776 2013-06-30] (Symantec Corporation)
S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-03] (INCA Internet Co., Ltd.)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-30] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
S3 tizekdrv; C:\Users\Thomas\AppData\Roaming\TZAC\tizek64.sys [241848 2012-05-01] ()
S3 tizekdrv; C:\Users\Thomas\AppData\Roaming\TZAC\tizek64.sys [241848 2012-05-01] ()
S3 tizeqdrv; C:\Users\Thomas\AppData\Roaming\TZAC2\tizeq64.sys [171704 2012-06-19] ()
S3 tizeqdrv; C:\Users\Thomas\AppData\Roaming\TZAC2\tizeq64.sys [171704 2012-06-19] ()
S3 dump_wmimmc; \??\C:\Program Files (x86)\EA Sports\Fifa Online 2\GameGuard\dump_wmimmc.sys [x]
S3 NPPTNT2; \??\C:\Windows\system32\npptNT2.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-19 16:01 - 2013-07-19 16:01 - 00000000 ____D C:\FRST
2013-07-19 16:00 - 2013-07-19 16:00 - 01778207 _____ (Farbar) C:\Users\Thomas\Downloads\frst64.exe
2013-07-19 15:57 - 2013-07-19 15:57 - 01218862 _____ (Farbar) C:\Users\Thomas\Downloads\FRST.exe
2013-07-19 15:05 - 2013-07-19 15:05 - 00001297 _____ C:\Users\Thomas\Desktop\asda.txt
2013-07-19 12:12 - 2013-07-19 12:12 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2013-07-19 12:12 - 2013-07-19 12:12 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-19 12:12 - 2013-07-19 12:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-19 12:12 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-19 12:11 - 2013-07-19 12:12 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-18 19:04 - 2013-07-18 19:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-07-18 16:27 - 2013-07-18 16:27 - 00127843 _____ C:\Users\Thomas\Downloads\1311201730_special_gamefonts_pc.rar
2013-07-16 21:49 - 2013-07-13 00:03 - 00000000 ____D C:\Users\Thomas\Desktop\Demos
2013-07-16 21:40 - 2013-07-16 21:44 - 154954737 _____ C:\Users\Thomas\Downloads\Demos(4).rar
2013-07-16 19:12 - 2013-07-16 19:13 - 05487912 _____ (TeamViewer GmbH) C:\Users\Thomas\Downloads\TeamViewer_Setup_de_8.0.19617.exe
2013-07-16 19:07 - 2013-07-16 19:07 - 04179944 _____ (TeamViewer) C:\Users\Thomas\Downloads\TeamViewerQS_de.exe
2013-07-10 23:10 - 2013-07-10 23:49 - 119972102 _____ C:\Users\Thomas\Downloads\gntdn.rar
2013-07-10 12:45 - 2013-07-18 13:30 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-07-10 12:43 - 2013-07-10 12:45 - 83293072 _____ (Blizzard Entertainment) C:\Users\Thomas\Downloads\World-of-Warcraft-Setup-deDE.exe
2013-07-10 12:26 - 2013-07-10 12:26 - 22125133 _____ C:\Users\Thomas\Downloads\Cataclysm_434.rar
2013-07-07 22:57 - 2013-07-07 23:25 - 84751212 _____ C:\Users\Thomas\Downloads\Prinz Pi - Hallo Musik.rar
2013-07-07 22:53 - 2013-07-07 22:54 - 00000000 ____D C:\ProgramData\eSafe
2013-07-07 22:51 - 2013-07-07 22:51 - 00021610 _____ C:\Users\Thomas\Downloads\-Prinz Pi - Hallo Musik Akustik Live-MAG-DVD-DE-2012-YSP.found.on.www.byte.to (1).torrent
2013-07-07 22:51 - 2013-07-07 22:51 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\eIntaller
2013-07-07 22:50 - 2013-07-07 22:50 - 00021610 _____ C:\Users\Thomas\Downloads\-Prinz Pi - Hallo Musik Akustik Live-MAG-DVD-DE-2012-YSP.found.on.www.byte.to.torrent
2013-07-07 22:49 - 2013-07-07 22:49 - 00297968 _____ (StarApp) C:\Users\Thomas\Downloads\TorrentDownload.exe
2013-07-07 22:49 - 2013-07-07 22:49 - 00021676 _____ C:\Users\Thomas\Downloads\[torrent.cd].Prinz_Pi_-_Hallo_Musik_Akustik_Live-MAG-DVD-DE-2012-YSP (2).torrent
2013-07-07 22:49 - 2013-07-07 22:49 - 00021676 _____ C:\Users\Thomas\Downloads\[torrent.cd].Prinz_Pi_-_Hallo_Musik_Akustik_Live-MAG-DVD-DE-2012-YSP (1).torrent
2013-07-07 22:48 - 2013-07-07 22:48 - 00021676 _____ C:\Users\Thomas\Downloads\[torrent.cd].Prinz_Pi_-_Hallo_Musik_Akustik_Live-MAG-DVD-DE-2012-YSP.torrent
2013-07-07 22:47 - 2013-07-07 22:49 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-07-07 22:47 - 2013-07-07 22:47 - 00014650 _____ C:\Users\Thomas\Downloads\CFCF1B99B5C95F9C359A3739FE908A3F1A70FB08.torrent
2013-07-07 22:47 - 2013-07-07 22:47 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-07-07 22:46 - 2013-07-07 22:46 - 00644152 _____ C:\Users\Thomas\Downloads\BitLordInstaller - Prinz Pi Hallo Musik 2011.exe
2013-07-07 22:46 - 2013-07-07 22:46 - 00261456 _____ C:\Users\Thomas\Downloads\Prinz_Pi_Hallo_Musik_2011.exe
2013-07-07 22:46 - 2013-07-07 22:46 - 00261456 _____ C:\Users\Thomas\Downloads\Prinz_Pi_Hallo_Musik_2011 (1).exe
2013-07-07 22:40 - 2013-07-07 22:40 - 00014620 _____ C:\Users\Thomas\Downloads\[isoHunt] Prinz Pi Hallo Musik 2011.torrent
2013-07-07 20:02 - 2013-07-18 14:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\CrashDumps
2013-07-03 22:08 - 2013-07-03 22:08 - 00436249 _____ C:\Users\Thomas\Downloads\UPRandomizer-120a.zip
2013-07-03 22:07 - 2013-07-03 22:07 - 01000193 _____ C:\Users\Thomas\Downloads\VisualBoyAdvanceM1097.7z
2013-07-01 19:34 - 2013-07-01 19:34 - 00010704 _____ C:\Users\Thomas\Downloads\01_01.wma
2013-07-01 12:30 - 2013-07-01 12:30 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360
2013-06-30 08:41 - 2013-06-30 08:41 - 00000000 ____D C:\N360_BACKUP
2013-06-30 08:37 - 2013-07-01 12:25 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-06-30 08:37 - 2013-06-30 19:03 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-06-30 08:37 - 2013-06-30 19:03 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-06-30 08:37 - 2013-06-30 08:37 - 00000000 ____D C:\Program Files\Symantec
2013-06-30 08:37 - 2013-06-30 08:37 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-06-30 08:36 - 2013-07-01 12:25 - 00000000 ____D C:\Windows\system32\Drivers\N360x64
2013-06-30 08:36 - 2013-06-30 08:36 - 00000000 ____D C:\Program Files (x86)\Norton 360
2013-06-29 19:02 - 2013-06-29 19:02 - 00000000 ____D C:\Users\Thomas\Documents\4A Games
2013-06-29 18:57 - 2013-06-29 18:57 - 00000000 ____D C:\Users\Thomas\AppData\Local\4A Games
2013-06-29 18:48 - 2013-06-29 18:48 - 00002972 _____ C:\Windows\System32\Tasks\{1B624F83-E6F3-4843-A760-F6380B4B214F}
2013-06-29 18:48 - 2013-06-29 18:48 - 00002972 _____ C:\Windows\System32\Tasks\{16A6CAEA-2E76-406C-900F-064FCEE11455}
2013-06-29 18:17 - 2013-06-30 08:38 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
2013-06-29 18:17 - 2013-06-29 18:17 - 00915960 _____ (Symantec Corporation) C:\Users\Thomas\Downloads\Norton_Download_Manager.exe
2013-06-29 18:17 - 2013-06-29 18:17 - 00000000 ____D C:\Users\Public\Downloads\Norton
2013-06-29 02:34 - 2013-06-29 02:34 - 00156719 _____ C:\Users\Thomas\Downloads\[kickass.to]metro.last.light.reloaded.torrent
2013-06-28 01:17 - 2013-06-28 01:17 - 00002994 _____ C:\Windows\System32\Tasks\{919192AE-2B82-4672-84ED-4F0B300EC2A9}
2013-06-28 01:15 - 2013-06-28 01:15 - 00002998 _____ C:\Windows\System32\Tasks\{CD6A54F4-1D52-4014-AC68-9D317A05E377}
2013-06-28 01:15 - 2013-06-28 01:15 - 00002998 _____ C:\Windows\System32\Tasks\{5B91C125-B450-4E29-9851-F70F76C130BD}
2013-06-28 01:15 - 2013-06-28 01:15 - 00002998 _____ C:\Windows\System32\Tasks\{1AE1C097-21B6-4F7D-AACD-52E7D3F37C48}
2013-06-28 01:11 - 2013-06-28 01:11 - 00003006 _____ C:\Windows\System32\Tasks\{E9C8BB16-3278-45AF-B83B-10BDCFC219EE}
2013-06-28 01:09 - 2013-06-28 01:09 - 00002936 _____ C:\Windows\System32\Tasks\{8D938569-FD2F-47BE-963B-2C9E800CC5A8}
2013-06-28 01:08 - 2013-06-28 01:08 - 00003006 _____ C:\Windows\System32\Tasks\{7A265765-3807-4542-A510-89E7F613B51B}
2013-06-28 01:08 - 2013-06-28 01:08 - 00003006 _____ C:\Windows\System32\Tasks\{4B058D46-4E13-42AA-A958-47C57A55EB2D}
2013-06-28 01:08 - 2013-06-28 01:08 - 00002948 _____ C:\Windows\System32\Tasks\{9EFDB496-3F35-4201-94FC-0C21DBA3B8AD}
2013-06-28 01:08 - 2013-06-28 01:08 - 00002948 _____ C:\Windows\System32\Tasks\{7C0C073B-EF12-4E9E-AFDC-0230BBDAF335}
2013-06-28 01:05 - 2013-06-28 01:05 - 00002994 _____ C:\Windows\System32\Tasks\{D44CEBB5-5D6D-4A31-ABCB-D858F1068CF1}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{DBBECB5E-92C1-4F69-A453-294BBE75BE4A}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{9D2E3F92-3C44-4C34-BCB7-B53FF4011EAC}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{8F52A8C5-B29D-42A9-B9EB-A0D204FA21D7}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{3007051E-A6AD-4856-B51E-E5047D05BE25}
2013-06-28 01:01 - 2013-06-28 01:01 - 00003006 _____ C:\Windows\System32\Tasks\{7A2D8C2C-3DBB-4BE5-B7DD-AAE8D5E03124}
2013-06-28 01:00 - 2013-06-28 01:00 - 00003006 _____ C:\Windows\System32\Tasks\{C2FB6E04-D7A2-4AB5-8F34-69601B1C3ECB}
2013-06-28 00:59 - 2013-06-28 00:59 - 00002994 _____ C:\Windows\System32\Tasks\{6E78D882-B5AF-4FFD-8A61-470E12A4DB6C}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{D98A728C-9280-4150-8140-246856147BF1}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{63522A55-1FF7-407D-9424-93010766DB64}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{31CF1282-D6DB-4D97-9037-4A00E1E676AF}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{00D7E840-C0EF-4BCB-AF65-9F0E0D638EFA}
2013-06-28 00:56 - 2013-06-28 00:56 - 00003006 _____ C:\Windows\System32\Tasks\{4B7ADB9A-9409-4BC4-94DF-6364C4B3389D}
2013-06-28 00:55 - 2013-06-28 00:55 - 00002994 _____ C:\Windows\System32\Tasks\{B6B47F50-62CD-4F5F-AD2A-B9AFD1D25F96}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{DE3201B3-5506-4309-8B7D-8C5D5C43AACC}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{D59F5E6C-E026-45CF-A6A5-EE285B4651E3}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{D3A55335-6357-4820-8290-BEDFDCD19779}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{BB21EA02-8F78-42FB-BDAB-D8F52AE12437}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{AC27E048-A0D5-44A2-BCB5-2C6E240B1D39}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{6D8E6FC0-2DEA-4C3E-AA72-953C10BC3BBD}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{655A8288-41C6-4CC3-A365-1FCF3A6243BE}
2013-06-28 00:54 - 2013-06-28 00:54 - 00002994 _____ C:\Windows\System32\Tasks\{6195DA7A-9123-4002-B8D4-BE995932FC98}
2013-06-28 00:53 - 2013-06-28 00:53 - 00002994 _____ C:\Windows\System32\Tasks\{332D1F18-3C9B-43ED-8CDB-1BB11E9CC084}
2013-06-28 00:51 - 2013-06-28 00:51 - 00002994 _____ C:\Windows\System32\Tasks\{31E78281-B712-40C6-9CA9-34B259C9653C}
2013-06-28 00:43 - 2013-06-28 00:43 - 00002994 _____ C:\Windows\System32\Tasks\{E764AAB2-291F-48CD-B5BD-C0F074FABA37}
2013-06-27 10:00 - 2013-06-27 10:00 - 12228373 _____ C:\Users\Thomas\Downloads\d3d9.zip
2013-06-27 09:57 - 2013-06-27 09:58 - 04241280 _____ (Dll-Files.com ) C:\Users\Thomas\Downloads\dffsetup-d3d9.exe
2013-06-24 16:05 - 2013-06-24 16:11 - 00000000 ____D C:\Users\Thomas\AppData\Local\Darksiders
2013-06-23 21:10 - 2013-06-23 21:10 - 00158243 _____ C:\Users\Thomas\Downloads\no$gba-w.2.6a.zip
2013-06-23 21:07 - 2013-06-23 21:07 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Sun
2013-06-23 21:01 - 2013-06-23 21:02 - 00178833 _____ C:\Users\Thomas\Downloads\PkmnEmeraldRandomizer_v1.0.zip
2013-06-23 21:00 - 2013-06-23 21:01 - 06868618 _____ C:\Users\Thomas\Downloads\Pokemon Emerald.zip
2013-06-23 21:00 - 2013-06-23 21:00 - 00659797 _____ C:\Users\Thomas\Downloads\VisualBoyAdvance-1.8.0-beta3.zip
==================== One Month Modified Files and Folders =======
2013-07-19 16:01 - 2013-07-19 16:01 - 00000000 ____D C:\FRST
2013-07-19 16:01 - 2012-10-01 19:26 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Skype
2013-07-19 16:01 - 2012-05-19 19:24 - 00000000 ____D C:\Users\Thomas\AppData\Local\PMB Files
2013-07-19 16:00 - 2013-07-19 16:00 - 01778207 _____ (Farbar) C:\Users\Thomas\Downloads\frst64.exe
2013-07-19 15:57 - 2013-07-19 15:57 - 01218862 _____ (Farbar) C:\Users\Thomas\Downloads\FRST.exe
2013-07-19 15:35 - 2012-05-01 00:26 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-19 15:30 - 2012-11-09 17:55 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001UA.job
2013-07-19 15:25 - 2012-04-30 23:57 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Xfire
2013-07-19 15:05 - 2013-07-19 15:05 - 00001297 _____ C:\Users\Thomas\Desktop\asda.txt
2013-07-19 13:53 - 2012-05-01 00:04 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\TS3Client
2013-07-19 13:48 - 2012-05-19 19:24 - 00000000 ____D C:\ProgramData\PMB Files
2013-07-19 13:13 - 2012-08-13 17:03 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Spotify
2013-07-19 13:12 - 2010-12-02 02:12 - 01675062 _____ C:\Windows\WindowsUpdate.log
2013-07-19 12:30 - 2012-11-09 17:55 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001Core.job
2013-07-19 12:20 - 2012-05-01 04:02 - 00282472 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-07-19 12:20 - 2012-05-01 04:02 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-07-19 12:20 - 2012-05-01 04:01 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-07-19 12:12 - 2013-07-19 12:12 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes
2013-07-19 12:12 - 2013-07-19 12:12 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-19 12:12 - 2013-07-19 12:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-19 12:12 - 2013-07-19 12:11 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Thomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-19 09:57 - 2009-07-14 06:45 - 00015568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-19 09:57 - 2009-07-14 06:45 - 00015568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-19 09:53 - 2012-05-01 01:32 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\ICQ
2013-07-19 09:50 - 2013-02-10 02:00 - 00020038 _____ C:\Windows\setupact.log
2013-07-19 09:50 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-19 00:05 - 2012-05-01 00:03 - 00000000 ____D C:\Program Files (x86)\Steam
2013-07-18 19:05 - 2013-07-18 19:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-07-18 16:27 - 2013-07-18 16:27 - 00127843 _____ C:\Users\Thomas\Downloads\1311201730_special_gamefonts_pc.rar
2013-07-18 14:17 - 2013-07-07 20:02 - 00000000 ____D C:\Users\Thomas\AppData\Local\CrashDumps
2013-07-18 13:30 - 2013-07-10 12:45 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-07-18 00:59 - 2012-04-30 23:57 - 00000000 ____D C:\ProgramData\Xfire
2013-07-18 00:03 - 2012-05-07 18:41 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\mIRC
2013-07-17 23:53 - 2012-05-07 18:41 - 00000000 ____D C:\Program Files (x86)\mIRC
2013-07-16 21:44 - 2013-07-16 21:40 - 154954737 _____ C:\Users\Thomas\Downloads\Demos(4).rar
2013-07-16 19:13 - 2013-07-16 19:12 - 05487912 _____ (TeamViewer GmbH) C:\Users\Thomas\Downloads\TeamViewer_Setup_de_8.0.19617.exe
2013-07-16 19:07 - 2013-07-16 19:07 - 04179944 _____ (TeamViewer) C:\Users\Thomas\Downloads\TeamViewerQS_de.exe
2013-07-16 10:28 - 2013-02-11 17:44 - 00470584 _____ C:\Windows\PFRO.log
2013-07-15 12:25 - 2012-11-09 17:55 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001UA
2013-07-15 12:25 - 2012-11-09 17:55 - 00003704 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4240377317-2580135182-2221074664-1001Core
2013-07-13 00:03 - 2013-07-16 21:49 - 00000000 ____D C:\Users\Thomas\Desktop\Demos
2013-07-10 23:49 - 2013-07-10 23:10 - 119972102 _____ C:\Users\Thomas\Downloads\gntdn.rar
2013-07-10 13:10 - 2010-12-02 02:37 - 00654372 _____ C:\Windows\system32\perfh007.dat
2013-07-10 13:10 - 2010-12-02 02:37 - 00129986 _____ C:\Windows\system32\perfc007.dat
2013-07-10 13:10 - 2009-07-14 07:13 - 01499844 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-10 12:45 - 2013-07-10 12:43 - 83293072 _____ (Blizzard Entertainment) C:\Users\Thomas\Downloads\World-of-Warcraft-Setup-deDE.exe
2013-07-10 12:26 - 2013-07-10 12:26 - 22125133 _____ C:\Users\Thomas\Downloads\Cataclysm_434.rar
2013-07-09 22:22 - 2012-08-13 17:03 - 00000000 ____D C:\Users\Thomas\AppData\Local\Spotify
2013-07-07 23:25 - 2013-07-07 22:57 - 84751212 _____ C:\Users\Thomas\Downloads\Prinz Pi - Hallo Musik.rar
2013-07-07 22:54 - 2013-07-07 22:53 - 00000000 ____D C:\ProgramData\eSafe
2013-07-07 22:53 - 2012-04-30 23:14 - 00001651 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-07 22:53 - 2012-04-30 23:14 - 00001629 _____ C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-07-07 22:53 - 2011-02-20 00:03 - 00420944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2013-07-07 22:53 - 2011-02-19 01:40 - 00773712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2013-07-07 22:52 - 2012-05-15 16:24 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\BitTorrent
2013-07-07 22:51 - 2013-07-07 22:51 - 00021610 _____ C:\Users\Thomas\Downloads\-Prinz Pi - Hallo Musik Akustik Live-MAG-DVD-DE-2012-YSP.found.on.www.byte.to (1).torrent
2013-07-07 22:51 - 2013-07-07 22:51 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\eIntaller
2013-07-07 22:50 - 2013-07-07 22:50 - 00021610 _____ C:\Users\Thomas\Downloads\-Prinz Pi - Hallo Musik Akustik Live-MAG-DVD-DE-2012-YSP.found.on.www.byte.to.torrent
2013-07-07 22:49 - 2013-07-07 22:49 - 00297968 _____ (StarApp) C:\Users\Thomas\Downloads\TorrentDownload.exe
2013-07-07 22:49 - 2013-07-07 22:49 - 00021676 _____ C:\Users\Thomas\Downloads\[torrent.cd].Prinz_Pi_-_Hallo_Musik_Akustik_Live-MAG-DVD-DE-2012-YSP (2).torrent
2013-07-07 22:49 - 2013-07-07 22:49 - 00021676 _____ C:\Users\Thomas\Downloads\[torrent.cd].Prinz_Pi_-_Hallo_Musik_Akustik_Live-MAG-DVD-DE-2012-YSP (1).torrent
2013-07-07 22:49 - 2013-07-07 22:47 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2013-07-07 22:48 - 2013-07-07 22:48 - 00021676 _____ C:\Users\Thomas\Downloads\[torrent.cd].Prinz_Pi_-_Hallo_Musik_Akustik_Live-MAG-DVD-DE-2012-YSP.torrent
2013-07-07 22:47 - 2013-07-07 22:47 - 00014650 _____ C:\Users\Thomas\Downloads\CFCF1B99B5C95F9C359A3739FE908A3F1A70FB08.torrent
2013-07-07 22:47 - 2013-07-07 22:47 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2013-07-07 22:46 - 2013-07-07 22:46 - 00644152 _____ C:\Users\Thomas\Downloads\BitLordInstaller - Prinz Pi Hallo Musik 2011.exe
2013-07-07 22:46 - 2013-07-07 22:46 - 00261456 _____ C:\Users\Thomas\Downloads\Prinz_Pi_Hallo_Musik_2011.exe
2013-07-07 22:46 - 2013-07-07 22:46 - 00261456 _____ C:\Users\Thomas\Downloads\Prinz_Pi_Hallo_Musik_2011 (1).exe
2013-07-07 22:40 - 2013-07-07 22:40 - 00014620 _____ C:\Users\Thomas\Downloads\[isoHunt] Prinz Pi Hallo Musik 2011.torrent
2013-07-03 22:08 - 2013-07-03 22:08 - 00436249 _____ C:\Users\Thomas\Downloads\UPRandomizer-120a.zip
2013-07-03 22:07 - 2013-07-03 22:07 - 01000193 _____ C:\Users\Thomas\Downloads\VisualBoyAdvanceM1097.7z
2013-07-01 19:34 - 2013-07-01 19:34 - 00010704 _____ C:\Users\Thomas\Downloads\01_01.wma
2013-07-01 12:30 - 2013-07-01 12:30 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360
2013-07-01 12:25 - 2013-06-30 08:37 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-07-01 12:25 - 2013-06-30 08:36 - 00000000 ____D C:\Windows\system32\Drivers\N360x64
2013-06-30 19:03 - 2013-06-30 08:37 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-06-30 19:03 - 2013-06-30 08:37 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-06-30 17:01 - 2013-04-02 14:36 - 00001161 _____ C:\Windows\LkmdfCoInst.log
2013-06-30 17:01 - 2012-05-19 16:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2013-06-30 08:51 - 2012-05-12 10:39 - 00001912 _____ C:\Windows\epplauncher.mif
2013-06-30 08:41 - 2013-06-30 08:41 - 00000000 ____D C:\N360_BACKUP
2013-06-30 08:38 - 2013-06-29 18:17 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
2013-06-30 08:38 - 2010-12-02 02:47 - 00000000 ____D C:\ProgramData\Norton
2013-06-30 08:37 - 2013-06-30 08:37 - 00000000 ____D C:\Program Files\Symantec
2013-06-30 08:37 - 2013-06-30 08:37 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-06-30 08:36 - 2013-06-30 08:36 - 00000000 ____D C:\Program Files (x86)\Norton 360
2013-06-29 19:02 - 2013-06-29 19:02 - 00000000 ____D C:\Users\Thomas\Documents\4A Games
2013-06-29 18:57 - 2013-06-29 18:57 - 00000000 ____D C:\Users\Thomas\AppData\Local\4A Games
2013-06-29 18:48 - 2013-06-29 18:48 - 00002972 _____ C:\Windows\System32\Tasks\{1B624F83-E6F3-4843-A760-F6380B4B214F}
2013-06-29 18:48 - 2013-06-29 18:48 - 00002972 _____ C:\Windows\System32\Tasks\{16A6CAEA-2E76-406C-900F-064FCEE11455}
2013-06-29 18:17 - 2013-06-29 18:17 - 00915960 _____ (Symantec Corporation) C:\Users\Thomas\Downloads\Norton_Download_Manager.exe
2013-06-29 18:17 - 2013-06-29 18:17 - 00000000 ____D C:\Users\Public\Downloads\Norton
2013-06-29 02:34 - 2013-06-29 02:34 - 00156719 _____ C:\Users\Thomas\Downloads\[kickass.to]metro.last.light.reloaded.torrent
2013-06-28 01:17 - 2013-06-28 01:17 - 00002994 _____ C:\Windows\System32\Tasks\{919192AE-2B82-4672-84ED-4F0B300EC2A9}
2013-06-28 01:15 - 2013-06-28 01:15 - 00002998 _____ C:\Windows\System32\Tasks\{CD6A54F4-1D52-4014-AC68-9D317A05E377}
2013-06-28 01:15 - 2013-06-28 01:15 - 00002998 _____ C:\Windows\System32\Tasks\{5B91C125-B450-4E29-9851-F70F76C130BD}
2013-06-28 01:15 - 2013-06-28 01:15 - 00002998 _____ C:\Windows\System32\Tasks\{1AE1C097-21B6-4F7D-AACD-52E7D3F37C48}
2013-06-28 01:11 - 2013-06-28 01:11 - 00003006 _____ C:\Windows\System32\Tasks\{E9C8BB16-3278-45AF-B83B-10BDCFC219EE}
2013-06-28 01:09 - 2013-06-28 01:09 - 00002936 _____ C:\Windows\System32\Tasks\{8D938569-FD2F-47BE-963B-2C9E800CC5A8}
2013-06-28 01:08 - 2013-06-28 01:08 - 00003006 _____ C:\Windows\System32\Tasks\{7A265765-3807-4542-A510-89E7F613B51B}
2013-06-28 01:08 - 2013-06-28 01:08 - 00003006 _____ C:\Windows\System32\Tasks\{4B058D46-4E13-42AA-A958-47C57A55EB2D}
2013-06-28 01:08 - 2013-06-28 01:08 - 00002948 _____ C:\Windows\System32\Tasks\{9EFDB496-3F35-4201-94FC-0C21DBA3B8AD}
2013-06-28 01:08 - 2013-06-28 01:08 - 00002948 _____ C:\Windows\System32\Tasks\{7C0C073B-EF12-4E9E-AFDC-0230BBDAF335}
2013-06-28 01:05 - 2013-06-28 01:05 - 00002994 _____ C:\Windows\System32\Tasks\{D44CEBB5-5D6D-4A31-ABCB-D858F1068CF1}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{DBBECB5E-92C1-4F69-A453-294BBE75BE4A}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{9D2E3F92-3C44-4C34-BCB7-B53FF4011EAC}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{8F52A8C5-B29D-42A9-B9EB-A0D204FA21D7}
2013-06-28 01:02 - 2013-06-28 01:02 - 00003006 _____ C:\Windows\System32\Tasks\{3007051E-A6AD-4856-B51E-E5047D05BE25}
2013-06-28 01:01 - 2013-06-28 01:01 - 00003006 _____ C:\Windows\System32\Tasks\{7A2D8C2C-3DBB-4BE5-B7DD-AAE8D5E03124}
2013-06-28 01:00 - 2013-06-28 01:00 - 00003006 _____ C:\Windows\System32\Tasks\{C2FB6E04-D7A2-4AB5-8F34-69601B1C3ECB}
2013-06-28 00:59 - 2013-06-28 00:59 - 00002994 _____ C:\Windows\System32\Tasks\{6E78D882-B5AF-4FFD-8A61-470E12A4DB6C}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{D98A728C-9280-4150-8140-246856147BF1}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{63522A55-1FF7-407D-9424-93010766DB64}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{31CF1282-D6DB-4D97-9037-4A00E1E676AF}
2013-06-28 00:57 - 2013-06-28 00:57 - 00003006 _____ C:\Windows\System32\Tasks\{00D7E840-C0EF-4BCB-AF65-9F0E0D638EFA}
2013-06-28 00:56 - 2013-06-28 00:56 - 00003006 _____ C:\Windows\System32\Tasks\{4B7ADB9A-9409-4BC4-94DF-6364C4B3389D}
2013-06-28 00:55 - 2013-06-28 00:55 - 00002994 _____ C:\Windows\System32\Tasks\{B6B47F50-62CD-4F5F-AD2A-B9AFD1D25F96}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{DE3201B3-5506-4309-8B7D-8C5D5C43AACC}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{D59F5E6C-E026-45CF-A6A5-EE285B4651E3}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{D3A55335-6357-4820-8290-BEDFDCD19779}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{BB21EA02-8F78-42FB-BDAB-D8F52AE12437}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{AC27E048-A0D5-44A2-BCB5-2C6E240B1D39}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{6D8E6FC0-2DEA-4C3E-AA72-953C10BC3BBD}
2013-06-28 00:54 - 2013-06-28 00:54 - 00003006 _____ C:\Windows\System32\Tasks\{655A8288-41C6-4CC3-A365-1FCF3A6243BE}
2013-06-28 00:54 - 2013-06-28 00:54 - 00002994 _____ C:\Windows\System32\Tasks\{6195DA7A-9123-4002-B8D4-BE995932FC98}
2013-06-28 00:53 - 2013-06-28 00:53 - 00002994 _____ C:\Windows\System32\Tasks\{332D1F18-3C9B-43ED-8CDB-1BB11E9CC084}
2013-06-28 00:51 - 2013-06-28 00:51 - 00002994 _____ C:\Windows\System32\Tasks\{31E78281-B712-40C6-9CA9-34B259C9653C}
2013-06-28 00:43 - 2013-06-28 00:43 - 00002994 _____ C:\Windows\System32\Tasks\{E764AAB2-291F-48CD-B5BD-C0F074FABA37}
2013-06-27 10:00 - 2013-06-27 10:00 - 12228373 _____ C:\Users\Thomas\Downloads\d3d9.zip
2013-06-27 09:58 - 2013-06-27 09:57 - 04241280 _____ (Dll-Files.com ) C:\Users\Thomas\Downloads\dffsetup-d3d9.exe
2013-06-24 16:11 - 2013-06-24 16:05 - 00000000 ____D C:\Users\Thomas\AppData\Local\Darksiders
2013-06-23 21:10 - 2013-06-23 21:10 - 00158243 _____ C:\Users\Thomas\Downloads\no$gba-w.2.6a.zip
2013-06-23 21:07 - 2013-06-23 21:07 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Sun
2013-06-23 21:02 - 2013-06-23 21:01 - 00178833 _____ C:\Users\Thomas\Downloads\PkmnEmeraldRandomizer_v1.0.zip
2013-06-23 21:01 - 2013-06-23 21:00 - 06868618 _____ C:\Users\Thomas\Downloads\Pokemon Emerald.zip
2013-06-23 21:00 - 2013-06-23 21:00 - 00659797 _____ C:\Users\Thomas\Downloads\VisualBoyAdvance-1.8.0-beta3.zip
2013-06-23 10:28 - 2013-05-26 12:36 - 00000000 ____D C:\Program Files (x86)\StarCraft II
ZeroAccess:
C:\Windows\Installer\{43052835-0e74-b0ab-3a54-c943fa54b21c}
C:\Windows\Installer\{43052835-0e74-b0ab-3a54-c943fa54b21c}\L
C:\Windows\Installer\{43052835-0e74-b0ab-3a54-c943fa54b21c}\U
C:\Windows\Installer\{43052835-0e74-b0ab-3a54-c943fa54b21c}\L\00000004.@
C:\Windows\Installer\{43052835-0e74-b0ab-3a54-c943fa54b21c}\L\201d3dde
ZeroAccess:
C:\Users\Thomas\AppData\Local\{43052835-0e74-b0ab-3a54-c943fa54b21c}
C:\Users\Thomas\AppData\Local\{43052835-0e74-b0ab-3a54-c943fa54b21c}\L
C:\Users\Thomas\AppData\Local\{43052835-0e74-b0ab-3a54-c943fa54b21c}\U
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-15 16:33
==================== End Of Log ============================ --- --- --- |