So, habe nun die andere Festplatte abgesteckt und nochmals einen Scan durchgeführt - ich glaube das es nun passt.
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-12-2014
Ran by SYSTEM on MININT-S7T6SQN on 01-01-2015 17:35:03
Running from F:\
Platform: Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [52392 2009-01-29] (Elaborate Bytes AG)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5223016 2014-10-31] (AVAST Software)
HKLM\...\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM\...\Run: [ConnectionCenter] => C:\Program Files\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM\...\Run: [Redirector] => C:\Program Files\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\Administrator\...\Run: [DriverMax] => C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe [9621368 2014-05-08] (Innovative Solutions)
HKU\Administrator\...\Run: [DriverMax_RESTART] => [X]
HKU\Büro\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\Büro\...\Winlogon: [Shell] C:\Users\Büro\AppData\Roaming\Other.res [400896 2014-05-19] (Codmaster) <==== ATTENTION
IFEO\eraser.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
IFEO\helplauncher.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
IFEO\vcd-uninst.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
IFEO\vcdmount.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
IFEO\vcdprefs.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-27] (AVAST Software)
S2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [247152 2009-01-21] ()
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3e\RpcAgentSrv.exe [73200 2014-10-06] (SiSoftware)
S2 UserAccess7; C:\Windows\system32\UAService7.exe [143360 2014-10-08] (Sony DADC Austria AG.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC.SYS [4172832 2000-01-01] (Realtek Semiconductor Corp.)
S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-10-27] ()
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2014-10-31] (AVAST Software)
S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-10-27] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2014-10-27] ()
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2014-11-22] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2014-11-22] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [91496 2014-10-27] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [206248 2014-10-27] ()
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-06-16] (Disc Soft Ltd)
S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [24232 2009-02-17] (Elaborate Bytes AG)
S3 HCWBT8xx; C:\Windows\System32\drivers\HCWBT8XX.sys [472644 2006-01-25] (Hauppauge Computer Works)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3e\WNt600x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
S2 SecDrv; C:\Windows\system32\drivers\SECDRV.SYS [11376 2003-09-09] ()
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2014-05-18] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-01 17:34 - 2015-01-01 17:35 - 00000000 ____D () C:\FRST
2014-12-29 01:44 - 2014-12-29 01:44 - 00003224 ____N () C:\bootsqm.dat
2014-12-22 11:25 - 2014-12-22 11:25 - 00223711 _____ () C:\Users\Büro\Documents\comic.pptx
2014-12-18 19:48 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2014-12-14 13:06 - 2014-12-25 13:11 - 00000000 ____D () C:\Users\Büro\Desktop\eli
2014-12-14 03:21 - 2014-12-14 03:34 - 39687370 _____ () C:\Users\Büro\Downloads\AY_fshujhg7).rar
2014-12-14 03:16 - 2014-12-14 03:26 - 31170116 _____ () C:\Users\Büro\Downloads\A Mgfjhgyjuhgio.rar
2014-12-10 22:37 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2014-12-10 22:37 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2014-12-10 22:37 - 2014-11-22 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2014-12-10 22:37 - 2014-11-22 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2014-12-10 22:37 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-12-10 22:37 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2014-12-10 22:36 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2014-12-10 22:36 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-12-10 22:36 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-12-10 22:36 - 2014-11-22 03:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2014-12-10 22:36 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2014-12-10 22:36 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2014-12-10 22:36 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2014-12-10 22:36 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-12-10 22:36 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2014-12-10 22:36 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-12-10 22:36 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2014-12-10 22:36 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2014-12-10 22:36 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2014-12-10 22:36 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2014-12-10 22:36 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2014-12-10 22:36 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-12-10 22:36 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-12-10 22:36 - 2014-11-22 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2014-12-10 22:36 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-12-10 22:36 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2014-12-10 22:36 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-12-10 22:36 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2014-12-10 22:36 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-12-10 22:36 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2014-12-09 20:22 - 2014-12-09 20:22 - 00001584 _____ () C:\Users\Public\Desktop\Terraria.lnk
2014-12-09 20:22 - 2014-12-09 20:22 - 00000000 ____D () C:\Program Files\Microsoft XNA
2014-12-09 20:22 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\System32\XAudio2_6.dll
2014-12-09 20:22 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\System32\xactengine3_6.dll
2014-12-09 20:22 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\System32\XAPOFX1_4.dll
2014-12-09 20:22 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\System32\X3DAudio1_7.dll
2014-12-09 20:22 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\System32\xinput1_3.dll
2014-12-09 17:33 - 2014-12-09 17:34 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-12-09 16:28 - 2014-12-09 16:28 - 109190808 _____ (GOG.com ) C:\Users\Büro\Downloads\setup_terraria_2.0.0.1.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-29 09:21 - 2014-10-10 23:02 - 00009650 _____ () C:\Windows\setupact.log
2014-12-29 08:43 - 2010-11-20 22:01 - 01507106 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-12-29 08:32 - 2009-07-14 05:34 - 00021312 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-29 08:32 - 2009-07-14 05:34 - 00021312 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-29 08:28 - 2014-05-18 09:11 - 01116725 _____ () C:\Windows\WindowsUpdate.log
2014-12-29 08:15 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\LogFiles
2014-12-29 01:35 - 2014-08-26 11:41 - 00000000 ____D () C:\Users\Büro\Desktop\Japan 2
2014-12-26 22:17 - 2014-10-28 10:58 - 00000000 ____D () C:\Program Files\Steam
2014-12-26 00:30 - 2014-11-06 19:13 - 00000000 ____D () C:\Users\Büro\AppData\Roaming\TS3Client
2014-12-23 21:36 - 2014-05-18 11:54 - 00024815 _____ () C:\hph7345.log
2014-12-23 21:36 - 2014-05-18 11:54 - 00000000 _____ () C:\hpfr5550.xml
2014-12-22 12:42 - 2014-05-20 21:59 - 00000000 ____D () C:\Users\Büro\AppData\Local\Battle.net
2014-12-22 11:25 - 2014-05-18 09:30 - 00000000 ____D () C:\users\Büro
2014-12-16 01:05 - 2014-05-20 21:58 - 00000000 ____D () C:\Program Files\Battle.net
2014-12-13 17:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-12-13 13:09 - 2014-05-18 12:00 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2014-12-13 13:09 - 2014-05-18 12:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2014-12-13 13:09 - 2014-05-18 11:59 - 00000000 ____D () C:\Users\Büro\AppData\Local\Adobe
2014-12-12 21:04 - 2014-07-26 20:32 - 00002081 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-12 20:17 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\de-DE
2014-12-11 01:52 - 2014-05-19 14:46 - 00000000 ____D () C:\Windows\System32\MRT
2014-12-11 01:47 - 2014-05-19 14:46 - 109818608 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2014-12-10 22:23 - 2014-05-18 10:45 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-12-09 20:25 - 2014-10-02 18:47 - 00000000 ____D () C:\Users\Büro\Documents\My Games
2014-12-09 20:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-12-09 20:21 - 2014-05-18 23:22 - 00000000 ____D () C:\Games
2014-12-09 19:21 - 2014-11-10 00:34 - 00000000 ____D () C:\Windows\pss
2014-12-07 23:55 - 2014-05-19 16:38 - 00000000 ____D () C:\Users\Büro\AppData\Roaming\Skype
2014-12-05 20:02 - 2014-05-21 10:11 - 00000000 ____D () C:\Program Files\Hearthstone
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\oi_{27AFDF3D-62C3-4E16-94BA-E24521B52999}.exe
C:\Users\Büro\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprkt4ir.dll
C:\Users\Büro\AppData\Local\Temp\install_flashplayer16x32au_mssd_aaa_aih.exe
C:\Users\Büro\AppData\Local\Temp\SRLDetectionLibrary8322397628942996893.dll
C:\Users\Büro\AppData\Local\Temp\stuprt.exe
==================== Known DLLs (Whitelisted) ============
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe
[2014-10-15 10:06] - [2014-07-17 02:39] - 0304128 ____A (Microsoft Corporation) 52449FD429D6053B78AE564DEF303870
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Restore Points =========================
Restore point made on: 2014-12-16 22:56:00
Restore point made on: 2014-12-19 02:17:04
Restore point made on: 2014-12-23 11:36:52
Restore point made on: 2014-12-26 20:46:04
==================== Memory info ===========================
Percentage of memory in use: 37%
Total physical RAM: 1023.55 MB
Available physical RAM: 641.48 MB
Total Pagefile: 1023.55 MB
Available Pagefile: 638.1 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:148.95 GB) (Free:78.1 GB) NTFS
Drive f: () (Removable) (Total:29.8 GB) (Free:1.22 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 00910090)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 29.8 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
LastRegBack: 2014-12-25 02:01
==================== End Of Log ============================
--- --- ---
Grüße, Kaesbrot