![]() |
|
Alles rund um Windows: Windows 8 wird immer langsamerWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
![]() | #1 |
| ![]() Problem: Windows 8 wird immer langsamer Hallo, ich bin zum ersten Mal hier und würde mich sehr über Hilfe freuen. Seit einigen Wochen wird mein Rechner (Lenovo Laptop mit Windows 8 64-Bit, 2GB RAM, AMD E1-2100, vor ca. einem Jahr gekauft) immer langsamer. Programme (z.B. Word, Firefox) hängen sich immer wieder auf oder sind einfach sehr, sehr langsam. Was ich schon versucht habe: Datenträgerbereinigung und Installation von AVG PC TuneUp - Letzteres hat zwar viel gelöscht, geholfen hat es aber nicht. Habe mir jetzt FRST geholt, hier sind die Ergebnisse: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-06-2015 Ran by berit (administrator) on LENOVO-PC on 03-06-2015 21:16:24 Running from C:\Users\berit\Downloads Loaded Profiles: berit (Available Profiles: berit) Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Spotify Ltd) C:\Users\berit\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.17074_none_6233bc1f5106b696\TiWorker.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [899680 2013-02-04] (Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2013-03-05] (Conexant Systems, Inc.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2876816 2013-03-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6339656 2013-04-10] (Realtek semiconductor) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17097200 2013-12-19] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-12-19] (Lenovo(beijing) Limited) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-04-24] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [193568 2014-11-28] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Run: [Spotify Web Helper] => C:\Users\berit\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2021944 2015-05-29] (Spotify Ltd) HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Run: [Amazon Music] => C:\Users\berit\AppData\Local\Amazon Music\Amazon Music Helper.exe [5886784 2015-05-07] () HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Run: [Spotify] => C:\Users\berit\AppData\Roaming\Spotify\Spotify.exe [7323192 2015-05-29] (Spotify Ltd) HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\MountPoints2: {4dc593cf-c76b-11e4-be8b-342387ec0d54} - "F:\ting.exe" HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\MountPoints2: {ca4ed08b-8867-11e4-be89-342387ec0d54} - "F:\LaunchU3.exe" -a Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-12-19] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startfenster.de HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com SearchScopes: HKLM -> DefaultScope {A0B594C2-B07C-4CD5-89EE-EE4B3FB72815} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM -> {A0B594C2-B07C-4CD5-89EE-EE4B3FB72815} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002 -> DefaultScope {A0B594C2-B07C-4CD5-89EE-EE4B3FB72815} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002 -> {6E3BDE14-47C9-4498-80C5-0923E5FC5794} URL = SearchScopes: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002 -> {A0B594C2-B07C-4CD5-89EE-EE4B3FB72815} URL = hxxp://www.sm.de/?q={searchTerms} BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-06] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-06] (Oracle Corporation) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\berit\AppData\Roaming\Mozilla\Firefox\Profiles\avdi35l0.default FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] () FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-08-06] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-08-06] (Oracle Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\berit\AppData\Roaming\Mozilla\Firefox\Profiles\avdi35l0.default\searchplugins\google-images.xml [2014-07-20] FF SearchPlugin: C:\Users\berit\AppData\Roaming\Mozilla\Firefox\Profiles\avdi35l0.default\searchplugins\google-maps.xml [2014-07-20] FF SearchPlugin: C:\Users\berit\AppData\Roaming\Mozilla\Firefox\Profiles\avdi35l0.default\searchplugins\suchmaschine.xml [2015-02-22] FF Extension: Mein Grundeinkommen - CrowdBar - C:\Users\berit\AppData\Roaming\Mozilla\Firefox\Profiles\avdi35l0.default\Extensions\jid1-XGbYhwCViPEOUQ@jetpack.xpi [2015-01-08] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-06-02] FF HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\berit\AppData\Roaming\Mozilla\Firefox\Profiles\avdi35l0.default\extensions\cliqz@cliqz.com ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [103424 2013-04-24] () [File not signed] R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-24] (Advanced Micro Devices, Inc.) [File not signed] R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2228440 2013-04-22] (Broadcom Corporation.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959192 2013-04-22] (Broadcom Corporation.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [92160 2013-02-25] (ELAN Microelectronics Corp.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2967864 2015-05-15] (AVG Technologies) R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-12-19] () R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17504 2013-02-08] (Advanced Micro Devices, INC.) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [94208 2013-02-14] (Advanced Micro Devices) R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [172760 2013-04-22] (Broadcom Corporation.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [9500336 2013-04-27] (Broadcom Corporation) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 BTWPANFL; C:\WINDOWS\system32\drivers\btwpanfl.sys [44912 2013-01-20] (Broadcom Corporation.) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243272 2013-04-10] (Realtek Semiconductor Corp.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2015-05-15] (TuneUp Software) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S1 MpKslfa5b47f4; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2C07E661-9E16-455A-9B71-B5434D568EB8}\MpKslfa5b47f4.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-03 21:16 - 2015-06-03 21:18 - 00017335 _____ C:\Users\berit\Downloads\FRST.txt 2015-06-03 21:15 - 2015-06-03 21:16 - 00000000 ____D C:\FRST 2015-06-03 21:15 - 2015-06-03 21:15 - 02108928 _____ (Farbar) C:\Users\berit\Downloads\FRST64.exe 2015-06-03 21:12 - 2015-06-03 21:12 - 01147392 _____ (Farbar) C:\Users\berit\Downloads\FRST.exe 2015-06-02 22:29 - 2015-06-02 22:29 - 00019953 _____ C:\Users\berit\Desktop\Protokoll Elternabend.odt 2015-06-02 22:26 - 2015-06-03 20:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-05-29 15:36 - 2015-05-15 15:57 - 00041784 _____ (AVG Technologies) C:\WINDOWS\system32\TURegOpt.exe 2015-05-29 15:36 - 2015-05-15 15:57 - 00030520 _____ (AVG Technologies) C:\WINDOWS\system32\authuitu.dll 2015-05-29 15:36 - 2015-05-15 15:57 - 00025912 _____ (AVG Technologies) C:\WINDOWS\SysWOW64\authuitu.dll 2015-05-29 15:35 - 2015-05-29 15:35 - 00002240 _____ C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk 2015-05-29 15:35 - 2015-05-29 15:35 - 00002228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk 2015-05-29 15:35 - 2015-05-29 15:35 - 00002216 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2015.lnk 2015-05-29 15:35 - 2015-05-29 15:35 - 00000000 ____D C:\Users\berit\AppData\Roaming\AVG 2015-05-29 15:34 - 2015-05-29 15:34 - 00000000 ____D C:\Program Files (x86)\AVG 2015-05-29 15:32 - 2015-05-29 15:32 - 00000000 ____D C:\Users\berit\AppData\Local\Avg 2015-05-29 15:31 - 2015-05-29 15:36 - 00000000 ____D C:\ProgramData\AVG 2015-05-29 15:30 - 2015-05-29 15:30 - 50867000 _____ (AVG Technologies) C:\Users\berit\Downloads\avg_tuht_stf_de_2015_518_15cmp16.exe 2015-05-15 18:56 - 2015-05-15 18:56 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-05-13 19:33 - 2015-05-13 19:33 - 00000000 ____D C:\Users\berit\Tracing 2015-05-11 10:25 - 2015-05-30 21:14 - 00000000 ___RD C:\Users\berit\Dropbox 2015-05-11 10:25 - 2015-05-11 10:25 - 00001138 _____ C:\Users\berit\Desktop\Dropbox.lnk 2015-05-11 10:23 - 2015-05-11 10:23 - 00000000 ____D C:\Users\berit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-05-11 10:18 - 2015-05-30 21:14 - 00000000 ____D C:\Users\berit\AppData\Roaming\Dropbox 2015-05-11 10:17 - 2015-05-11 10:18 - 00356272 _____ (Dropbox, Inc.) C:\Users\berit\Downloads\DropboxInstaller.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-03 21:18 - 2013-12-19 18:24 - 01213139 _____ C:\WINDOWS\WindowsUpdate.log 2015-06-03 21:12 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-06-03 21:09 - 2014-07-19 23:33 - 00000000 ____D C:\Users\berit\AppData\Roaming\ClassicShell 2015-06-03 21:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru 2015-06-03 20:57 - 2014-08-05 20:32 - 00000000 ____D C:\Users\berit\Desktop\UNI 2015-06-03 20:51 - 2014-07-18 22:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-06-03 20:51 - 2013-03-25 23:02 - 00021702 _____ C:\WINDOWS\PFRO.log 2015-06-03 20:51 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-06-03 20:36 - 2014-07-19 09:59 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-06-03 20:35 - 2014-08-30 09:41 - 00000000 ____D C:\Users\berit\AppData\Roaming\Spotify 2015-06-03 20:34 - 2014-11-17 11:12 - 00000000 ____D C:\Users\berit\AppData\Local\Spotify 2015-06-03 20:34 - 2014-09-22 12:33 - 00003138 _____ C:\WINDOWS\System32\Tasks\{C76ED1BA-6B03-4A25-9155-69629C5A1AD8} 2015-06-02 23:08 - 2013-12-19 19:05 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin 2015-06-02 23:07 - 2014-07-19 07:30 - 14336008 _____ C:\Users\Public\CAFADEBUG.log 2015-05-29 18:58 - 2015-01-23 21:28 - 00000000 ____D C:\Users\berit\Desktop\Kram 2015-05-29 15:53 - 2014-10-13 11:15 - 00000000 ____D C:\Users\berit\.thumbnails 2015-05-29 15:53 - 2014-09-22 12:35 - 00000000 ____D C:\Users\berit\AppData\Roaming\Skype 2015-05-29 15:53 - 2013-12-19 19:32 - 00000000 ____D C:\ProgramData\Temp 2015-05-29 15:53 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2015-05-29 13:09 - 2014-10-13 09:17 - 00000000 ____D C:\Users\berit\.gimp-2.8 2015-05-29 12:59 - 2013-12-20 02:53 - 00753134 _____ C:\WINDOWS\system32\perfh007.dat 2015-05-29 12:59 - 2013-12-20 02:53 - 00155826 _____ C:\WINDOWS\system32\perfc007.dat 2015-05-29 12:59 - 2012-07-26 09:28 - 01745416 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-05-29 12:53 - 2012-07-26 09:21 - 00036801 _____ C:\WINDOWS\setupact.log 2015-05-27 23:13 - 2014-09-22 12:35 - 00000000 ___RD C:\Program Files (x86)\Skype 2015-05-25 22:42 - 2013-12-19 19:41 - 00012800 _____ C:\WINDOWS\system32\VfService.trf 2015-05-19 22:16 - 2014-12-12 11:49 - 00001141 _____ C:\Users\berit\Desktop\Amazon Music.lnk 2015-05-17 19:51 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent 2015-05-15 18:57 - 2014-07-29 15:16 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2015-05-13 19:33 - 2014-07-18 22:22 - 00000000 ____D C:\Users\berit 2015-05-13 19:32 - 2014-09-22 12:34 - 00000000 ____D C:\ProgramData\Skype 2015-05-11 10:46 - 2015-04-18 07:34 - 00000000 ____D C:\Users\berit\AppData\Roaming\dvdcss ==================== Files in the root of some directories ======= 2014-07-29 12:12 - 2014-07-29 12:12 - 0087040 _____ (Software Installer ) C:\Users\berit\AppData\Roaming\setup.exe 2015-01-26 21:58 - 2015-01-26 21:58 - 0002107 _____ () C:\Users\berit\AppData\Local\recently-used.xbel 2013-12-19 19:11 - 2013-12-19 19:11 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== C:\Users\berit\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpewidx1.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-27 22:42 ==================== End of log ============================ Addition:FRST Additions Logfile: [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version:03-06-2015 Ran by berit at 2015-06-03 21:23:45 Running from C:\Users\berit\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2988672238-2959486261-4195868787-500 - Administrator - Disabled) berit (S-1-5-21-2988672238-2959486261-4195868787-1002 - Administrator - Enabled) => C:\Users\berit Gast (S-1-5-21-2988672238-2959486261-4195868787-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Amazon Music (HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Amazon Amazon Music) (Version: 3.9.5.820 - Amazon Services LLC) AMD Catalyst Install Manager (HKLM\...\{02054CB4-661A-C582-0F83-E966ADFB8289}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.4.0 - AppEx Networks) AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.518 - AVG Technologies) Hidden AVG PC TuneUp 2015 (HKLM-x32\...\AVG PC TuneUp) (Version: 15.0.1001.518 - AVG Technologies) AVG PC TuneUp 2015 (x32 Version: 15.0.1001.518 - AVG Technologies) Hidden Benutzerhandbuch (x32 Version: 1.0.0.17 - Lenovo) Hidden Canon MP Navigator EX 2.0 (HKLM-x32\...\MP Navigator EX 2.0) (Version: - ) Canon MP540 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP540_series) (Version: - ) Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.64.49.0 - Conexant) Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.17 - Dolby Laboratories Inc) Dropbox (HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.) DVD Shrink 3.2 deutsch (DeCSS-frei) (HKLM-x32\...\DVD Shrink DE_is1) (Version: - DVD Shrink) Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.11 - Lenovo) Energy Management (x32 Version: 8.0.2.11 - Lenovo) Hidden f4 3.1.0 (HKLM-x32\...\f4) (Version: 3.1.0 - MAXqda) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33057) (Version: 3.6.1.33057.10 - Intel) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java(TM) 6 Update 7 (HKLM-x32\...\{3248F0A8-6813-11D6-A77B-00B0D0160070}) (Version: 1.6.0.70 - Sun Microsystems, Inc.) Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Juniper_Setup_Client) (Version: 7.1.17.41283 - Juniper Networks, Inc.) Juniper Networks, Inc. Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.) Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.6600 - Broadcom Corporation) Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10227 - Realtek Semiconductor Corp.) Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.1219 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.0.0.1219 - CyberLink Corp.) Hidden Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.14.1 - ELAN Microelectronic Corp.) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5108.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5108.52 - CyberLink Corp.) Hidden Lenovo VeriFace (HKLM\...\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo) Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.30.223.75 - Lenovo) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Mozilla Firefox 38.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) OEM Application Profile (HKLM-x32\...\{C89A97B6-F991-EBB5-77B7-927BCF420EBE}) (Version: 1.00.0000 - Ihr Firmenname) OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) PDF24 Creator 6.9.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.9109 - CyberLink Corp.) Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.16 - Qualcomm Atheros Communications Inc.) Realtek USB Card Reader (HKLM-x32\...\{1E496A68-4943-424E-829D-5C3C85B7B8F2}) (Version: 6.2.9200.39041 - Realtek Semiconductor Corp.) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.4 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.4.102 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\Spotify) (Version: 1.0.6.80.g2a801a53 - Spotify AB) SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.61.90905 - SugarSync, Inc.) UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.17 - Lenovo) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (HKLM\...\71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42) (Version: 06/15/2012 8.1.0.1 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (HKLM\...\8A223E56FB1ED4F697B54E5BF96F1EB63B512684) (Version: 06/19/2012 10.13.29.733 - Lenovo) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2988672238-2959486261-4195868787-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\berit\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 26-04-2015 14:26:29 Geplanter Prüfpunkt 14-05-2015 09:50:16 Geplanter Prüfpunkt 29-05-2015 15:32:20 AVG PC TuneUp 2015 wird installiert ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {28CA0833-CEB5-4310-870F-4C479F547135} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe Task: {4175ED8B-45CA-4CE4-8BAF-F0C11B56BD4C} - System32\Tasks\Microsoft\Windows\Setup\8.1 auto install => C:\WINDOWS\system32\NotificationUI.exe [2014-08-21] (Microsoft Corporation) Task: {46B0EDCF-68D4-4679-9C00-B3514FFD4A95} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated) Task: {ADFCA2F9-3F3F-4B14-B65E-6127CE1ADF1B} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2012-08-31] (Dolby Laboratories Inc.) Task: {BD0BBFE1-F3C3-4E1A-B324-50C482A17382} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [2012-03-08] () Task: {C2CF5F25-1BF8-428F-B00D-0C5FBCC8DF08} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {CABD9FC6-0943-41E3-AF2B-CF25526DC5BA} - System32\Tasks\{C76ED1BA-6B03-4A25-9155-69629C5A1AD8} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.20.0.104&LastError=2 Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (Whitelisted) ============== 2013-04-24 18:11 - 2013-04-24 18:11 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe 2013-04-24 18:10 - 2013-04-24 18:10 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2013-04-22 18:16 - 2013-04-22 18:16 - 00049368 _____ () C:\Program Files\Lenovo\Bluetooth Software\btwleapi.dll 2015-05-15 15:57 - 2015-05-15 15:57 - 00718136 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll 2013-12-19 19:41 - 2013-12-19 19:41 - 00068368 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe 2013-12-19 19:41 - 2013-12-19 19:41 - 00669288 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfDataStorageInterface.dll 2015-05-15 15:58 - 2015-05-15 15:58 - 00862008 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tulnga.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "Bluetooth.lnk" HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "StartCCC" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "mcui_exe" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\StartupApproved\Run: => "Amazon Music" HKU\S-1-5-21-2988672238-2959486261-4195868787-1002\...\StartupApproved\Run: => "Free Download Manager" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{B137B027-4A59-4CD0-91FA-AADD5A9CA93E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{5EBEE923-A79C-4BF1-9840-3B64E9FE89A9}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [TCP Query User{654B0146-966C-475D-8D02-02C82C0EEEBE}C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe FirewallRules: [UDP Query User{A16D19FC-AFA6-46D5-8639-D9C7D85D6865}C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe FirewallRules: [TCP Query User{5F406FB0-EA68-41EE-AF9C-57A1039ED986}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{288B8F12-E8C5-40CF-8712-7688BC1F6700}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{388B95D2-16C8-4386-9B95-CB4665975734}C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe FirewallRules: [UDP Query User{23DAD76E-BA2E-482B-B7EC-CF9D88A9A801}C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe FirewallRules: [TCP Query User{48367951-B1F2-4706-B2AF-DC16F1DCE73F}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{A4977D04-259C-41D2-8207-4BD3B0C3B884}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{6469BD91-C0F0-4F7C-AA9F-9173BBAC0578}C:\users\berit\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\berit\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{F87D82A7-FFB6-436B-930E-A6C74E19B5E4}C:\users\berit\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\berit\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{81D7CA85-CAEB-4CD5-AC0B-DFC288D41995}C:\users\berit\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\berit\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{53CE84AA-1202-4C9C-B93D-6E4AE96AA569}C:\users\berit\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\berit\appdata\roaming\spotify\spotify.exe FirewallRules: [{85FF143B-BC01-4D86-8408-87F21449E695}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5FA1F8A6-9E13-4C3A-981C-8EEAC3D15F3B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{4D14F3EF-DD0B-4ABD-AA65-6B3CA586A57A}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{69AB4143-310B-4AC4-9B76-0A31F6EABAC3}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{4DB561E6-93F1-4980-8BAF-E42845173E8F}] => (Allow) C:\Users\berit\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{EFF7C38A-B90A-4F66-8C6A-D4BDFD4B23AA}] => (Allow) C:\Users\berit\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{ABF74FFA-CEC2-4441-BC92-25EFF51CF950}C:\users\berit\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\berit\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{06F3B56A-F0C1-47C4-8E10-479F68FB8B13}C:\users\berit\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\berit\appdata\roaming\dropbox\bin\dropbox.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/03/2015 08:53:47 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Explorer.EXE, Version 6.2.9200.16628 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c7c Startzeit: 01d09e2e789d3584 Endzeit: 23618 Anwendungspfad: C:\WINDOWS\Explorer.EXE Berichts-ID: ce981dcd-0a21-11e5-be8d-342387ec0d54 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/03/2015 08:34:07 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 11:07:51 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 11:07:50 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 11:07:50 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 11:07:48 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 11:07:40 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 10:43:54 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 10:39:58 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2015 09:58:24 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed System errors: ============= Error: (06/03/2015 08:52:40 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1070 Error: (06/03/2015 08:52:38 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde nicht richtig gestartet. Error: (06/03/2015 08:51:36 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 03.06.2015 um 20:32:21 unerwartet heruntergefahren. Error: (05/27/2015 11:13:40 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Erkennung interaktiver Dienste" wurde mit folgendem Fehler beendet: %%1 Error: (05/23/2015 08:54:33 PM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung vom Remoteendpunkt empfangen. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Error: (05/17/2015 07:48:52 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Spooler erreicht. Error: (05/17/2015 07:48:22 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Spooler erreicht. Error: (05/10/2015 07:38:06 PM) (Source: cdrom) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (04/11/2015 03:43:51 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 11.04.2015 um 13:48:06 unerwartet heruntergefahren. Error: (04/10/2015 11:00:10 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {D63B10C5-BB46-4990-A94F-E40B9D520160} Microsoft Office: ========================= Error: (06/03/2015 08:53:47 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Explorer.EXE6.2.9200.16628c7c01d09e2e789d358423618C:\WINDOWS\Explorer.EXEce981dcd-0a21-11e5-be8d-342387ec0d54 Error: (06/03/2015 08:34:07 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 11:07:51 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 11:07:50 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 11:07:50 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 11:07:48 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 11:07:40 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 10:43:54 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 10:39:58 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: Error: (06/02/2015 09:58:24 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ==================== Memory info =========================== Processor: AMD E1-2100 APU with Radeon(TM) HD Graphics Percentage of memory in use: 84% Total physical RAM: 1737.25 MB Available physical RAM: 264.29 MB Total Pagefile: 3529.25 MB Available Pagefile: 1720.63 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:427.08 GB) (Free:361.9 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.81 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 8160E07C) Partition: GPT Partition Type. ==================== End of log ============================ --- --- --- Ich hoffe, ich habe halbwegs Sinnvolles geschrieben, habe leider nicht wirklich Ahnung von Computern... Vielen Dank schon mal für eure Tipps! |
Themen zu Windows 8 wird immer langsamer |
adware, avg, browser, computer, defender, desktop, error, feedback, firefox, firefox 38.0.5, flash player, free download, homepage, hängen, installation, logfile, mozilla, realtek, registry, security, services.exe, software, svchost.exe, system, udp, usb, warnung, windows, windowsapps |