DAnke für die schnelle Antwort
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013
Ran by SYSTEM on 11-08-2013 16:53:47
Running from H:\
Windows 7 Ultimate (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12666984 2011-08-09] (Realtek Semiconductor)
HKLM\...\Run: [XFast LAN] - C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe [1441152 2011-10-19] (cFos Software GmbH)
HKLM\...\Run: [THXCfg64] - C:\Windows\system32\THXCfg64.dll [26624 2011-05-13] (Creative Technology Ltd.)
HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-05-20] (FNet Co., Ltd.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [THX TruStudio NB Settings] - C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKU\Tobias\...\Run: [ASRockOCTuner] - [x]
HKU\Tobias\...\Run: [ASRockIES] - [x]
HKU\Tobias\...\Run: [zASRockInstantBoot] - [x]
HKU\Tobias\...\Run: [Steam] - D:\Program Files (x86)\Steam\Steam.exe [1807272 2013-07-26] (Valve Corporation)
HKU\Tobias\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Services (Whitelisted) =================
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-06-17] ()
S2 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [395136 2011-10-19] (cFos Software GmbH)
S2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2470736 2013-06-28] (LogMeIn Inc.)
S2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe [138760 2011-08-10] (Symantec Corporation)
S2 DisplayFusionService; "D:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe" [x]
==================== Drivers (Whitelisted) ====================
S2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices)
S0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
S0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [1151096 2011-07-25] (Symantec Corporation)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [1151096 2011-07-25] (Symantec Corporation)
S3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1301000.01C\ccSetx64.sys [167048 2011-08-08] (Symantec Corporation)
S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2013-05-21] (FNet Co., Ltd.)
S1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-05-20] (FNet Co., Ltd.)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20110726.001\IDSVia64.sys [488568 2011-07-20] (Symantec Corporation)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20110726.001\IDSVia64.sys [488568 2011-07-20] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20110810.019\ENG64.SYS [117880 2011-08-10] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20110810.019\ENG64.SYS [117880 2011-08-10] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20110810.019\EX64.SYS [2048632 2011-08-10] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20110810.019\EX64.SYS [2048632 2011-08-10] (Symantec Corporation)
S3 SRTSP; C:\Windows\system32\drivers\NISx64\1301000.01C\SRTSP64.SYS [729720 2011-08-02] (Symantec Corporation)
S3 SRTSPX; C:\Windows\system32\drivers\NISx64\1301000.01C\SRTSPX64.SYS [37496 2011-08-02] (Symantec Corporation)
S3 SymDS; C:\Windows\system32\drivers\NISx64\1301000.01C\SYMDS64.SYS [451192 2011-07-25] (Symantec Corporation)
S3 SymEFA; C:\Windows\system32\drivers\NISx64\1301000.01C\SYMEFA64.SYS [1084536 2011-07-28] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2013-05-20] (Symantec Corporation)
S3 SymIRON; C:\Windows\system32\drivers\NISx64\1301000.01C\Ironx64.SYS [189560 2011-07-25] (Symantec Corporation)
S3 SymNetS; C:\Windows\system32\drivers\NISx64\1301000.01C\SYMNETS.SYS [401016 2011-07-25] (Symantec Corporation)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-25 17:20 - 2013-07-25 17:31 - 00000000 ____D C:\Users\Tobias\Desktop\Backup Walkman
2013-07-20 14:07 - 2013-07-20 14:07 - 08775080 _____ (Wargaming.net ) C:\Users\Tobias\Downloads\WoWP_internet_install_eu.exe
2013-07-18 18:44 - 2013-07-18 18:44 - 00000000 ____D C:\Program Files (x86)\Java
==================== One Month Modified Files and Folders =======
2013-08-11 11:38 - 2009-07-14 18:58 - 00653928 _____ C:\Windows\System32\perfh007.dat
2013-08-11 11:38 - 2009-07-14 18:58 - 00129800 _____ C:\Windows\System32\perfc007.dat
2013-08-11 11:38 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\System32\PerfStringBackup.INI
2013-08-11 11:29 - 2013-05-28 17:35 - 00000000 ____D C:\Users\Tobias\AppData\Local\LogMeIn Hamachi
2013-08-11 11:29 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-11 11:29 - 2009-07-14 05:51 - 00035805 _____ C:\Windows\setupact.log
2013-08-11 10:02 - 2013-05-20 14:56 - 01945165 _____ C:\Windows\WindowsUpdate.log
2013-08-11 09:49 - 2013-06-20 14:45 - 00000000 ____D C:\Users\Tobias\AppData\Local\Pokki
2013-08-11 09:45 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-11 09:45 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-11 09:41 - 2013-06-14 20:38 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Skype
2013-08-10 21:17 - 2013-05-24 18:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-10 21:11 - 2013-05-28 17:33 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\.minecraft
2013-08-10 20:22 - 2013-05-24 22:03 - 00001090 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-07-26 17:36 - 2013-06-16 18:00 - 00000000 ____D C:\Users\Tobias\AppData\Local\Warframe
2013-07-25 17:31 - 2013-07-25 17:20 - 00000000 ____D C:\Users\Tobias\Desktop\Backup Walkman
2013-07-20 14:30 - 2013-05-21 18:40 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Wargaming.net
2013-07-20 14:08 - 2013-05-21 18:06 - 00000000 ___RD C:\Users\Tobias\Desktop\Spiele Tobi
2013-07-20 14:08 - 2013-05-20 19:18 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-07-20 14:07 - 2013-07-20 14:07 - 08775080 _____ (Wargaming.net ) C:\Users\Tobias\Downloads\WoWP_internet_install_eu.exe
2013-07-18 18:44 - 2013-07-18 18:44 - 00000000 ____D C:\Program Files (x86)\Java
2013-07-18 18:44 - 2013-05-28 17:33 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-18 18:44 - 2013-05-28 17:33 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-07-18 18:44 - 2013-05-28 17:33 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-18 18:44 - 2013-05-28 17:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-18 18:44 - 2013-05-28 17:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-18 18:44 - 2013-05-28 17:33 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-17 18:47 - 2013-06-14 20:44 - 00000000 ____D C:\Users\Tobias\AppData\Local\Adobe
2013-07-17 18:47 - 2013-05-24 18:05 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-17 18:47 - 2013-05-24 18:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-17 18:47 - 2013-05-24 18:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-14 15:59 - 2013-05-20 19:28 - 00133191 _____ C:\Windows\DirectX.log
2013-07-14 15:57 - 2013-05-20 15:02 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-14 09:56 - 2013-06-14 20:38 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-14 09:56 - 2013-06-14 20:37 - 00000000 ____D C:\ProgramData\Skype
2013-07-13 14:01 - 2013-06-16 15:54 - 00000000 ____D C:\Users\Tobias\AppData\Local\ArmA 2 OA
2013-07-13 13:52 - 2013-07-10 20:20 - 00000000 ____D C:\ProgramData\WarThunder
2013-07-13 10:55 - 2013-05-21 18:52 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\TS3Client
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-07-04 17:52:09
Restore point made on: 2013-07-09 16:44:04
Restore point made on: 2013-07-10 20:48:02
Restore point made on: 2013-07-13 18:27:45
Restore point made on: 2013-07-14 15:59:08
Restore point made on: 2013-07-14 15:59:44
Restore point made on: 2013-07-16 18:36:04
Restore point made on: 2013-07-18 18:43:43
Restore point made on: 2013-07-20 09:39:47
Restore point made on: 2013-07-23 16:47:15
Restore point made on: 2013-08-10 20:20:51
==================== Memory info ===========================
Percentage of memory in use: 10%
Total physical RAM: 8175.24 MB
Available physical RAM: 7339.99 MB
Total Pagefile: 8173.39 MB
Available Pagefile: 7345.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:119.14 GB) (Free:45.67 GB) NTFS (Disk=0 Partition=2) ==>[Drive with boot components (obtained from BCD)]
Drive d: (Festplatte) (Fixed) (Total:465.66 GB) (Free:203.4 GB) NTFS (Disk=1 Partition=2)
Drive e: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]
Drive f: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=1 Partition=1) ==>[System with boot components (obtained from reading drive)]
Drive g: (bie764g) (CDROM) (Total:2.85 GB) (Free:0 GB) CDFS
Drive h: (VOLUME) (Removable) (Total:7.45 GB) (Free:7.44 GB) FAT32 (Disk=2 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: BDA8CD62)
Partition 1: (Not Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=119 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 9ABD1A82)
Partition 1: (Not Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 7 GB) (Disk ID: C1475B4D)
Partition 1: (Active) - (Size=7 GB) - (Type=0B)
LastRegBack: 2013-07-25 18:36
==================== End Of Log ============================
--- --- ---
Zitat:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-08-2013
Ran by SYSTEM at 2013-08-11 17:03:58 Run:1
Running from H:\
Boot Mode: Recovery
==============================================
HKU\Ingo Parche\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value not found.
"C:\Users\Ingo Parche\AppData\Roaming\skype.dat " => File/Directory not found.
"C:\Users\Ingo Parche\AppData\Roaming\skype.ini" => File/Directory not found.
==== End of Fixlog ====
__________________