ico0okie | 19.11.2013 15:34 | Hey schrauber,
danke für die schnelle Antwort!
Hier die FRST.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-11-2013
Ran by Tina (administrator) on BABY-LAPTOP on 19-11-2013 15:28:22
Running from C:\Users\Tina\Desktop
Microsoft Windows 8 Pro (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Atheros) C:\Program Files\Qualcomm Atheros\Ath_WlanAgent.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Run: [Sony PC Companion] - C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449248 2013-05-29] (Sony)
Startup: C:\Users\Tina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Tina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF03B291BAA92CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=AE087627375E7844&affID=121565&tsp=5021
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\9pidy6z0.default
FF user.js: detected! => C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\9pidy6z0.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\9pidy6z0.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR HomePage: hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=AE087627375E7844&affID=121565&tsp=5021
CHR RestoreOnStartup: "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=AE087627375E7844&affID=121565&tsp=5021"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Extension: (Google Docs) - C:\Users\Tina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Tina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Tina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Tina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\Tina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Tina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14480 2013-07-01] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-09-10] (Atheros)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [61680 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-08-06] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-08-06] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-08-06] ()
R3 athr; C:\Windows\system32\DRIVERS\athw8.sys [2761728 2012-09-06] (Qualcomm Atheros Communications, Inc.)
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [24576 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [242240 2013-08-08] (DT Soft Ltd)
R3 L1C; C:\Windows\system32\DRIVERS\L1C63x86.sys [93848 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-11-19] (Malwarebytes Corporation)
S3 WUDFWpdComp; C:\Windows\system32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-19 15:28 - 2013-11-19 15:29 - 00009131 _____ C:\Users\Tina\Desktop\FRST.txt
2013-11-19 15:28 - 2013-11-19 15:28 - 00000000 ____D C:\FRST
2013-11-19 15:25 - 2013-11-19 15:26 - 01090881 _____ (Farbar) C:\Users\Tina\Desktop\FRST.exe
2013-11-19 14:35 - 2013-11-19 14:35 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-11-19 01:38 - 2013-11-19 01:38 - 00422896 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-18 23:47 - 2013-11-18 23:47 - 00259584 _____ (OldTimer Tools) C:\Users\Tina\Downloads\OTH (1).scr
2013-11-18 23:43 - 2013-11-18 23:43 - 00259584 _____ (OldTimer Tools) C:\Users\Tina\Downloads\OTH.scr
2013-11-14 22:44 - 2013-08-23 02:44 - 01711616 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-14 22:42 - 2013-10-02 00:37 - 02035712 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 21:45 - 2013-11-05 23:58 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-11-14 21:45 - 2013-11-05 23:58 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-11-13 21:45 - 2013-10-02 00:37 - 01569280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 21:44 - 2013-10-10 11:07 - 00038744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2013-11-13 21:44 - 2013-10-10 10:29 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 21:44 - 2013-10-10 10:28 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-11-13 21:44 - 2013-10-03 00:41 - 01075712 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 21:44 - 2013-09-23 23:30 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 21:44 - 2013-09-13 23:36 - 02600448 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-11-13 21:44 - 2013-08-30 00:48 - 00914432 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2013-11-13 21:44 - 2013-07-25 00:10 - 10799104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2013-11-13 21:43 - 2013-09-13 23:58 - 00052656 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-11-13 21:43 - 2013-09-13 23:36 - 01556992 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-11-13 21:43 - 2013-09-13 23:36 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-11-13 21:43 - 2013-08-30 01:44 - 00054104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys
2013-11-13 21:43 - 2013-08-21 05:28 - 00407384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-11-13 21:43 - 2013-08-10 06:24 - 00123224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2013-11-13 21:43 - 2013-08-10 04:58 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2013-11-13 21:43 - 2013-07-12 02:30 - 00485376 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2013-11-13 21:42 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-13 21:41 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-13 21:41 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-13 21:41 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-13 21:41 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-13 21:41 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-13 21:41 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-13 21:41 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-13 21:41 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-03 13:15 - 2013-11-03 13:15 - 00099840 _____ C:\Users\Tina\Downloads\Uebersicht_PBs_nachFakultaet.xls
==================== One Month Modified Files and Folders =======
2013-11-19 15:29 - 2013-11-19 15:28 - 00009131 _____ C:\Users\Tina\Desktop\FRST.txt
2013-11-19 15:28 - 2013-11-19 15:28 - 00000000 ____D C:\FRST
2013-11-19 15:26 - 2013-11-19 15:25 - 01090881 _____ (Farbar) C:\Users\Tina\Desktop\FRST.exe
2013-11-19 15:20 - 2013-08-12 14:10 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-19 15:08 - 2013-08-06 19:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-19 15:00 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\sru
2013-11-19 14:38 - 2013-08-06 14:21 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-19 14:35 - 2013-11-19 14:35 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-11-19 14:33 - 2013-08-12 14:10 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-19 14:33 - 2013-08-06 19:03 - 00000000 ____D C:\Users\Tina\AppData\Roaming\Dropbox
2013-11-19 14:32 - 2013-08-06 14:11 - 00047494 _____ C:\Windows\PFRO.log
2013-11-19 14:32 - 2012-07-26 07:04 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-19 14:30 - 2013-09-30 10:07 - 00000000 ____D C:\ProgramData\DSearchLink
2013-11-19 14:30 - 2013-08-08 11:35 - 00000000 ____D C:\Users\Tina\AppData\Roaming\SearchProtect
2013-11-19 03:02 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-19 02:50 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\rescache
2013-11-19 02:01 - 2013-08-06 14:23 - 01945006 _____ C:\Windows\WindowsUpdate.log
2013-11-19 01:55 - 2013-08-06 19:09 - 00000000 ___RD C:\Users\Tina\Dropbox
2013-11-19 01:38 - 2013-11-19 01:38 - 00422896 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-18 23:51 - 2012-07-26 05:17 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-11-18 23:50 - 2012-07-26 07:53 - 00000000 ___RD C:\Windows\ToastData
2013-11-18 23:47 - 2013-11-18 23:47 - 00259584 _____ (OldTimer Tools) C:\Users\Tina\Downloads\OTH (1).scr
2013-11-18 23:43 - 2013-11-18 23:43 - 00259584 _____ (OldTimer Tools) C:\Users\Tina\Downloads\OTH.scr
2013-11-18 15:20 - 2013-08-08 13:28 - 00290816 ___SH C:\Users\Tina\Desktop\Thumbs.db
2013-11-18 08:39 - 2013-08-21 10:11 - 00368640 ___SH C:\Users\Tina\Downloads\Thumbs.db
2013-11-16 00:06 - 2013-09-22 20:42 - 00000000 ____D C:\Users\Tina\AppData\Roaming\BOM
2013-11-15 21:59 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\AUInstallAgent
2013-11-15 19:48 - 2013-08-15 18:37 - 00000000 ____D C:\Windows\system32\MRT
2013-11-15 08:52 - 2013-08-10 14:45 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-14 21:41 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\WinStore
2013-11-14 21:41 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-14 14:08 - 2013-08-06 13:43 - 00000000 ____D C:\Users\Tina\Documents\Uni
2013-11-11 11:13 - 2012-07-26 07:03 - 00018205 _____ C:\Windows\setupact.log
2013-11-06 10:40 - 2012-07-26 07:53 - 00000000 ____D C:\Windows\system32\NDF
2013-11-05 23:58 - 2013-11-14 21:45 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-11-05 23:58 - 2013-11-14 21:45 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-11-03 13:15 - 2013-11-03 13:15 - 00099840 _____ C:\Users\Tina\Downloads\Uebersicht_PBs_nachFakultaet.xls
Some content of TEMP:
====================
C:\Users\Tina\AppData\Local\Temp\ose00000.exe
C:\Users\Tina\AppData\Local\Temp\uninst1.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-18 15:50
==================== End Of Log ============================ --- --- ---
Und die Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-11-2013
Ran by Tina at 2013-11-19 15:30:25
Running from C:\Users\Tina\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
avast! Free Antivirus (Version: 8.0.1489.0)
Biet-O-Matic v2.14.12 (Version: 2.14.12)
DAEMON Tools Lite (Version: 4.47.1.0333)
Dropbox (HKCU Version: 2.2.13)
Free YouTube to MP3 Converter version 3.12.13.925 (Version: 3.12.13.925)
Google Chrome (Version: 31.0.1650.57)
Google Update Helper (Version: 1.3.21.165)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1)
Mozilla Maintenance Service (Version: 23.0.1)
Mozilla Thunderbird 17.0.8 (x86 de) (Version: 17.0.8)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: 2.1.0.7)
Qualcomm Atheros WiFi Driver Installation (Version: 11.13)
Sony Ericsson Update Engine (Version: 2.13.10.201308300830)
Sony PC Companion 2.10.174 (Version: 2.10.174)
WinRAR 4.20 (32-Bit) (Version: 4.20.0)
==================== Restore Points =========================
28-10-2013 09:55:57 Geplanter Prüfpunkt
05-11-2013 07:04:11 Geplanter Prüfpunkt
14-11-2013 12:04:27 Windows Update
==================== Hosts content: ==========================
2012-07-26 05:17 - 2012-07-26 05:17 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {31A4A9BE-F558-4F76-9AC8-46AC61B7B000} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {4DDF655E-F564-4E5B-B4B2-8F60A4830FAE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software)
Task: {C24BDAC0-7431-4613-8577-FC5F178D8797} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-12] (Google Inc.)
Task: {D76803ED-3E05-4F91-8312-EDA3A5EE0B6F} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {DFDF4C33-7256-4AE9-AE4D-6894F08AB207} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {E175B927-9D76-4DEE-AA40-792EDB2ADEBE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-03-16 23:11 - 2011-03-16 23:11 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-11-15 03:37 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-15 03:37 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-15 03:37 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-15 03:37 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-15 03:37 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-15 03:37 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Bluetooth-Gerät (PAN)
Description: Bluetooth-Gerät (PAN)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthPan
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/19/2013 01:56:10 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Dropbox.exe, Version: 2.2.13.0, Zeitstempel: 0x519ea916
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x1e126874
ID des fehlerhaften Prozesses: 0xe84
Startzeit der fehlerhaften Anwendung: 0xDropbox.exe0
Pfad der fehlerhaften Anwendung: Dropbox.exe1
Pfad des fehlerhaften Moduls: Dropbox.exe2
Berichtskennung: Dropbox.exe3
Vollständiger Name des fehlerhaften Pakets: Dropbox.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Dropbox.exe5
Error: (11/18/2013 03:31:19 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 23.0.1.4974, Zeitstempel: 0x520bc252
Name des fehlerhaften Moduls: xul.dll, Version: 23.0.1.4974, Zeitstempel: 0x520bc166
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0017af08
ID des fehlerhaften Prozesses: 0x1288
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3
Vollständiger Name des fehlerhaften Pakets: firefox.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: firefox.exe5
Error: (11/17/2013 10:52:00 PM) (Source: Chrome) (User: NT-AUTORITÄT)
Description: Chrome has encountered a fatal error.
ver=31.0.1650.57;lang=;id=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files\Google\CrashReports\48bdd716-5281-4f88-a507-c16a45ec8f69.dmp
Error: (11/15/2013 10:14:36 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/15/2013 08:51:49 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/11/2013 01:37:58 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/11/2013 01:35:32 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/11/2013 01:22:55 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: POWERPNT.EXE, Version: 14.0.6009.1000, Zeitstempel: 0x4cc1a4ed
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.2.9200.16451, Zeitstempel: 0x50988a1f
Ausnahmecode: 0xe0000002
Fehleroffset: 0x00012005
ID des fehlerhaften Prozesses: 0x1558
Startzeit der fehlerhaften Anwendung: 0xPOWERPNT.EXE0
Pfad der fehlerhaften Anwendung: POWERPNT.EXE1
Pfad des fehlerhaften Moduls: POWERPNT.EXE2
Berichtskennung: POWERPNT.EXE3
Vollständiger Name des fehlerhaften Pakets: POWERPNT.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: POWERPNT.EXE5
Error: (11/06/2013 00:05:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/06/2013 11:02:28 AM) (Source: Application Hang) (User: )
Description: Programm chrome.exe, Version 30.0.1599.101 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 978
Startzeit: 01cedad6d3eef94b
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\Google\Chrome\Application\chrome.exe
Berichts-ID: 8838f5de-46ca-11e3-afa6-dc0ea153367b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
System errors:
=============
Error: (11/19/2013 02:32:40 PM) (Source: BTHUSB) (User: )
Description: Der Bluetooth-Treiber hat ein HCI-Ereignis mit einer bestimmten Größe erwartet, das aber nicht empfangen wurde.
Error: (11/19/2013 02:32:18 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT)
Description: 0xc000014d0
Error: (11/19/2013 11:41:55 AM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 4
Error: (11/19/2013 10:35:51 AM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 4
Error: (11/19/2013 09:51:59 AM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 4
Error: (11/19/2013 04:30:10 AM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 4
Error: (11/19/2013 01:57:46 AM) (Source: BTHUSB) (User: )
Description: Der Bluetooth-Treiber hat ein HCI-Ereignis mit einer bestimmten Größe erwartet, das aber nicht empfangen wurde.
Error: (11/19/2013 01:41:07 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1070
Error: (11/19/2013 01:41:07 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSDP-Suche" wurde nicht richtig gestartet.
Error: (11/19/2013 01:40:57 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde nicht richtig gestartet.
Microsoft Office Sessions:
=========================
Error: (11/19/2013 01:56:10 AM) (Source: Application Error)(User: )
Description: Dropbox.exe2.2.13.0519ea916unknown0.0.0.000000000c00000051e126874e8401cee4c1c0c89d75C:\Users\Tina\AppData\Roaming\Dropbox\bin\Dropbox.exeunknown6089fc20-50b5-11e3-afa8-dc0ea153367b
Error: (11/18/2013 03:31:19 PM) (Source: Application Error)(User: )
Description: firefox.exe23.0.1.4974520bc252xul.dll23.0.1.4974520bc166c00000050017af08128801cee46a9ec9a2c0C:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Mozilla Firefox\xul.dll164a3bb0-505e-11e3-afa7-dc0ea153367b
Error: (11/17/2013 10:52:00 PM) (Source: Chrome)(User: NT-AUTORITÄT)
Description: Chrome has encountered a fatal error.
ver=31.0.1650.57;lang=;id=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files\Google\CrashReports\48bdd716-5281-4f88-a507-c16a45ec8f69.dmp
Error: (11/15/2013 10:14:36 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Sony\sony pc companion\Drivers\DPInst64.exe
Error: (11/15/2013 08:51:49 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Sony\sony pc companion\Drivers\DPInst64.exe
Error: (11/11/2013 01:37:58 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Sony\sony pc companion\Drivers\DPInst64.exe
Error: (11/11/2013 01:35:32 AM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Sony\sony pc companion\Drivers\DPInst64.exe
Error: (11/11/2013 01:22:55 AM) (Source: Application Error)(User: )
Description: POWERPNT.EXE14.0.6009.10004cc1a4edKERNELBASE.dll6.2.9200.1645150988a1fe000000200012005155801cede6a391af8eeC:\Program Files\Microsoft Office\Office14\POWERPNT.EXEC:\Windows\system32\KERNELBASE.dll6885cbbf-4a67-11e3-afa6-dc0ea153367b
Error: (11/06/2013 00:05:21 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Sony\sony pc companion\Drivers\DPInst64.exe
Error: (11/06/2013 11:02:28 AM) (Source: Application Hang)(User: )
Description: chrome.exe30.0.1599.10197801cedad6d3eef94b4294967295C:\Program Files\Google\Chrome\Application\chrome.exe8838f5de-46ca-11e3-afa6-dc0ea153367b
==================== Memory info ===========================
Percentage of memory in use: 37%
Total physical RAM: 3578.9 MB
Available physical RAM: 2251.64 MB
Total Pagefile: 4218.9 MB
Available Pagefile: 2600.68 MB
Total Virtual: 2047.88 MB
Available Virtual: 1845.38 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:297.75 GB) (Free:244.28 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 000BF567)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |