Andi_Abseits | 30.09.2013 20:22 | ja gut. Ich glaube zwar nicht, dass es sich wie von zauberhand was anderes ergeben wird, aber gerne ;)
Ich denke einfach, dass auf einer alten Platte reste einer Win XP part übrig waren und er da was durcheinander kriegt.
Meinst du, dass folgendes vorab helfen könnte?
"Führen Sie jetzt nacheinander folgende Befehle aus: bootrec /fixmbr, bootrec /fixboot und bootrec /rebuildbcd. Danach starten Sie diskpart. Mit list disk sehen Sie die vorhandenen Lauwerke Ihres Systems. Wählen Sie mit select disk [Nummer] die primäre Festplatte, auf der auch Windows installiert ist. Mit list partition und anschließend select partition [Nummer] wird die Partition selektiert, auf der Windows liegt. Abschließend tippen Sie active zum aktivieren der Boot-Partition. Mit exit wird DISKPART verlassen, ein weiteres exit beendet die Kommandozeile. "
Also wie erwartet sah es bei wiederholtem Vorgang genauso aus...
hab jetzt durch den kram meines letzten threads und ein paar weiteren fixes xp-reste entfernen können und ein neues FRST.txt file erstellen können.
Das sieht besser aus:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01
Ran by SYSTEM on MININT-1UEBQTE on 30-09-2013 21:08:52
Running from G:\
Windows 7 Professional (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Recovery
The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ATICustomerCare] - C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [307200 2009-06-14] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-04-06] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [MSSE] - c:\Program Files\Microsoft Security Essentials\msseces.exe [1094224 2010-09-15] (Microsoft Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-10] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5.5ServiceManager] - C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1561768 2012-05-04] (Ask)
HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2404376 2013-09-29] ()
HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM\...\Run: [LogitechCommunicationsManager] - C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe [497200 2006-06-26] (Logitech Inc.)
HKLM\...\Run: [LVCOMSX] - C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe [243248 2006-06-26] (Logitech Inc.)
HKLM\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\QuickCam10\QuickCam10.exe [614960 2006-06-26] ()
HKLM\...\Run: [DATAMNGR] - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\DATAMN~1.EXE [1684096 2012-11-27] (iMesh, Inc)
HKLM\...\Run: [SearchProtectAll] - C:\Program Files\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit)
HKU\Gast\...\Run: [SearchProtect] - C:\Users\Gast\AppData\Roaming\SearchProtect\bin\cltmng.exe [ 2013-05-08] (Conduit)
HKU\j.carstensen\...\Run: [SearchProtect] - C:\Users\j.carstensen\AppData\Roaming\SearchProtect\bin\cltmng.exe [ 2013-05-08] (Conduit)
HKU\j.carstensen\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2013-04-19] (Skype Technologies S.A.)
HKU\j.carstensen\...\Winlogon: [Shell] explorer.exe,C:\Users\j.carstensen\AppData\Roaming\data.dat [ 2011-11-17] () <==== ATTENTION
AppInit_DLLs: c:\progra~2\bitguard\261673~1.238\{c16c1~1\bitguard.dll [ 2013-09-19] ()
========================== Services (Whitelisted) =================
S2 BitGuard; C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3099616 2013-09-19] ()
S2 CltMngSvc; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [93984 2013-02-20] (Conduit)
S2 LVPrcSrv; c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe [99888 2006-06-26] (Logitech Inc.)
S2 LVSrvLauncher; C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe [91696 2006-06-26] (Logitech Inc.)
S2 MsMpSvc; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [17904 2010-03-25] (Microsoft Corporation)
S2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S2 tor; C:\Program Files\Tor\tor.exe [3233806 2013-08-26] ()
S2 vToolbarUpdater17.0.1; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe [1734680 2013-09-29] (AVG Secure Search)
==================== Drivers (Whitelisted) ====================
S1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-09-29] (AVG Technologies)
S1 BIOS; C:\Windows\system32\drivers\BIOS.sys [13696 2009-06-10] (BIOSTAR Group)
S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
S3 LVcKap; C:\Windows\System32\DRIVERS\LVcKap.sys [1587632 2006-06-26] (Logitech Inc.)
S3 LVMVDrv; C:\Windows\System32\DRIVERS\LVMVDrv.sys [1952816 2006-06-26] (Logitech Inc.)
S3 LVPr2Mon; C:\Windows\System32\drivers\LVPr2Mon.sys [23472 2006-06-26] ()
S3 mfwamidi; C:\Windows\System32\drivers\mfwamidi.sys [26736 2010-09-20] (Mark of the Unicorn)
S3 mfwawave; C:\Windows\System32\drivers\mfwawave.sys [70256 2010-09-20] (Mark of the Unicorn)
S3 motubus; C:\Windows\System32\drivers\MotuBus.sys [23664 2010-09-20] (Mark of the Unicorn)
S3 MotuFWA; C:\Windows\System32\drivers\motufwa.sys [472688 2010-09-20] (Mark of the Unicorn)
S1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [151216 2010-03-25] (Microsoft Corporation)
S3 MpNWMon; C:\Windows\System32\DRIVERS\MpNWMon.sys [42368 2010-03-25] (Microsoft Corporation)
S1 ckignqbb; \??\C:\Windows\system32\drivers\ckignqbb.sys [x]
S1 msporqsb; \??\C:\Windows\system32\drivers\msporqsb.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-30 21:08 - 2013-09-30 21:08 - 00000000 ____D C:\FRST
2013-09-27 18:42 - 2013-09-27 18:42 - 00000000 ____D C:\Users\Gast\AppData\Local\AVG Secure Search
2013-09-27 18:40 - 2013-09-27 18:40 - 00000000 ____D C:\Users\Gast\AppData\Roaming\SearchProtect
2013-09-25 10:06 - 2013-09-27 18:56 - 00000004 _____ C:\Users\j.carstensen\AppData\Roaming\settings.ini
2013-09-25 09:51 - 2013-09-25 09:51 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{B97B8545-16E9-4444-B99B-C62D25BB1D47}
2013-09-25 09:48 - 2013-09-25 09:48 - 00000000 ____D C:\ProgramData\BitGuard
2013-09-19 16:45 - 2013-09-19 16:45 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{9AED06FB-C805-4957-A9F0-56E37D81C1E5}
2013-09-16 17:49 - 2013-09-16 17:49 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{F669B073-2F98-40AE-BCCD-5E2F4E4B9595}
2013-09-03 16:41 - 2013-09-03 16:41 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{4CEEE4A1-06F2-4607-A3BE-5996F02E8413}
2013-09-01 15:50 - 2013-09-01 15:50 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{1C79E17F-5D6F-4B50-A2A8-A16289D97F3F}
==================== One Month Modified Files and Folders =======
2013-09-30 21:08 - 2013-09-30 21:08 - 00000000 ____D C:\FRST
2013-09-30 19:08 - 2009-07-14 05:39 - 00102214 _____ C:\Windows\setupact.log
2013-09-30 17:22 - 2010-11-23 15:23 - 01164930 _____ C:\Windows\WindowsUpdate.log
2013-09-30 17:20 - 2009-07-14 05:34 - 00014624 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-30 17:20 - 2009-07-14 05:34 - 00014624 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-30 17:15 - 2010-08-26 16:05 - 01480602 _____ C:\Windows\System32\PerfStringBackup.INI
2013-09-29 17:55 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Public\Libraries
2013-09-29 17:38 - 2013-01-27 16:31 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-29 17:19 - 2012-11-08 17:53 - 00037664 _____ (AVG Technologies) C:\Windows\System32\Drivers\avgtpx86.sys
2013-09-29 17:19 - 2012-07-13 14:43 - 00000000 ____D C:\Program Files\AVG Secure Search
2013-09-27 18:56 - 2013-09-25 10:06 - 00000004 _____ C:\Users\j.carstensen\AppData\Roaming\settings.ini
2013-09-27 18:56 - 2012-10-14 17:16 - 00000000 ____D C:\Users\j.carstensen\AppData\Roaming\Skype
2013-09-27 18:42 - 2013-09-27 18:42 - 00000000 ____D C:\Users\Gast\AppData\Local\AVG Secure Search
2013-09-27 18:40 - 2013-09-27 18:40 - 00000000 ____D C:\Users\Gast\AppData\Roaming\SearchProtect
2013-09-27 18:40 - 2012-02-04 10:43 - 00122944 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-25 10:10 - 2012-12-11 20:15 - 00000000 ____D C:\ProgramData\Browser Manager
2013-09-25 10:10 - 2010-11-26 13:43 - 00050516 _____ C:\Windows\PFRO.log
2013-09-25 09:51 - 2013-09-25 09:51 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{B97B8545-16E9-4444-B99B-C62D25BB1D47}
2013-09-25 09:48 - 2013-09-25 09:48 - 00000000 ____D C:\ProgramData\BitGuard
2013-09-19 16:45 - 2013-09-19 16:45 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{9AED06FB-C805-4957-A9F0-56E37D81C1E5}
2013-09-16 18:03 - 2011-11-18 14:49 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-16 17:58 - 2013-08-16 15:17 - 00000000 ____D C:\Windows\System32\MRT
2013-09-16 17:56 - 2010-11-24 08:18 - 76725432 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-09-16 17:49 - 2013-09-16 17:49 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{F669B073-2F98-40AE-BCCD-5E2F4E4B9595}
2013-09-03 16:41 - 2013-09-03 16:41 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{4CEEE4A1-06F2-4607-A3BE-5996F02E8413}
2013-09-01 15:50 - 2013-09-01 15:50 - 00000000 ____D C:\Users\j.carstensen\AppData\Local\{1C79E17F-5D6F-4B50-A2A8-A16289D97F3F}
Files to move or delete:
====================
C:\Users\j.carstensen\AppData\Roaming\data.dat
C:\Users\j.carstensen\AppData\Roaming\settings.ini
C:\Users\j.carstensen\AppData\Roaming\i.ini
Some content of TEMP:
====================
C:\Users\j.carstensen\AppData\Local\Temp\aacdec.exe
C:\Users\j.carstensen\AppData\Local\Temp\APNStub.exe
C:\Users\j.carstensen\AppData\Local\Temp\avguidx.dll
C:\Users\j.carstensen\AppData\Local\Temp\CommonInstaller.exe
C:\Users\j.carstensen\AppData\Local\Temp\doxillionsetup.exe
C:\Users\j.carstensen\AppData\Local\Temp\fbjsjhdhekyywgodsnbundfpehwnb.exe
C:\Users\j.carstensen\AppData\Local\Temp\ffmpeg15.exe
C:\Users\j.carstensen\AppData\Local\Temp\ffunzip.exe
C:\Users\j.carstensen\AppData\Local\Temp\GLF22F6.tmp.ConduitEngineSetup.exe
C:\Users\j.carstensen\AppData\Local\Temp\iGearedHelper.dll
C:\Users\j.carstensen\AppData\Local\Temp\iMesh_setup.exe
C:\Users\j.carstensen\AppData\Local\Temp\Installhelper.dll
C:\Users\j.carstensen\AppData\Local\Temp\laxiiaarkkpypnpqikg.bfg
C:\Users\j.carstensen\AppData\Local\Temp\MachineIdCreator.exe
C:\Users\j.carstensen\AppData\Local\Temp\mp3el.exe
C:\Users\j.carstensen\AppData\Local\Temp\MSN39A.exe
C:\Users\j.carstensen\AppData\Local\Temp\nsj6DF4.exe
C:\Users\j.carstensen\AppData\Local\Temp\nsv2A0E.tmp.ConduitEngineEmbbed.exe
C:\Users\j.carstensen\AppData\Local\Temp\nsy93D1.exe
C:\Users\j.carstensen\AppData\Local\Temp\oi_{5ACDA8FF-6585-4CF8-A623-6CBDF9566B7C}.exe
C:\Users\j.carstensen\AppData\Local\Temp\ose00000.exe
C:\Users\j.carstensen\AppData\Local\Temp\prismsetup.exe
C:\Users\j.carstensen\AppData\Local\Temp\SecondStepInstaller.exe
C:\Users\j.carstensen\AppData\Local\Temp\setup_fsu_cid.exe
C:\Users\j.carstensen\AppData\Local\Temp\SkypeSetup.exe
C:\Users\j.carstensen\AppData\Local\Temp\softonic-de3.exe
C:\Users\j.carstensen\AppData\Local\Temp\Softonicde3.exe
C:\Users\j.carstensen\AppData\Local\Temp\SPStub.exe
C:\Users\j.carstensen\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\j.carstensen\AppData\Local\Temp\tbFre2.dll
C:\Users\j.carstensen\AppData\Local\Temp\tbsof0.dll
C:\Users\j.carstensen\AppData\Local\Temp\ToolbarInstaller.exe
C:\Users\j.carstensen\AppData\Local\Temp\TorchSetupFull.exe
C:\Users\j.carstensen\AppData\Local\Temp\wpsetup.exe
==================== Known DLLs (Whitelisted) ============
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
26
Restore point made on: 2013-08-04 20:51:41
Restore point made on: 2013-08-07 16:34:44
Restore point made on: 2013-08-08 21:18:47
Restore point made on: 2013-08-11 18:35:16
Restore point made on: 2013-08-15 19:54:13
Restore point made on: 2013-08-16 15:17:25
Restore point made on: 2013-08-18 19:16:16
Restore point made on: 2013-08-23 14:27:05
Restore point made on: 2013-08-23 14:32:54
Restore point made on: 2013-08-26 18:16:54
Restore point made on: 2013-08-27 14:10:25
Restore point made on: 2013-09-01 15:54:28
Restore point made on: 2013-09-01 20:00:07
Restore point made on: 2013-09-03 16:41:54
Restore point made on: 2013-09-16 17:52:24
Restore point made on: 2013-09-16 17:56:28
Restore point made on: 2013-09-19 16:47:24
Restore point made on: 2013-09-19 16:59:50
Restore point made on: 2013-09-19 17:48:11
Restore point made on: 2013-09-19 21:35:55
Restore point made on: 2013-09-25 09:56:07
Restore point made on: 2013-09-25 10:08:39
Restore point made on: 2013-09-25 10:20:25
Restore point made on: 2013-09-29 17:29:18
Restore point made on: 2013-09-29 18:03:17
Restore point made on: 2013-09-30 17:22:24
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 4095.3 MB
Available physical RAM: 3568.51 MB
Total Pagefile: 4093.58 MB
Available Pagefile: 3570.33 MB
Total Virtual: 2047.88 MB
Available Virtual: 1943.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.61 GB) (Free:346.9 GB) NTFS
Drive d: (System-reserviert) (Fixed) (Total:0.15 GB) (Free:0.13 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive g: (INTENSO) (Removable) (Total:7.26 GB) (Free:0.01 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: () (Fixed) (Total:279.45 GB) (Free:138.48 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 279 GB) (Disk ID: ACE22E9E)
Partition 1: (Active) - (Size=279 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DA449325)
Partition 1: (Active) - (Size=157 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 7 GB) (Disk ID: 03E8323A)
Partition 1: (Not Active) - (Size=7 GB) - (Type=0B)
LastRegBack: 2013-09-17 09:33
==================== End Of Log ============================ --- --- ---
--- --- --- |