Hallo, vielen Dank schon mal. Hier die Logdateien:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:03-07-2014
Ran by Lea (administrator) on LEA on 04-07-2014 22:07:04
Running from C:\Users\Lea\Desktop
Platform: Microsoft Windows 8 Pro (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Atheros Commnucations) C:\Windows\System32\AdminService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x86__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
(Spotify Ltd) C:\Users\Lea\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(mIRC Co. Ltd.) C:\Program Files\mIRC\mirc.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2299176 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [5708432 2012-06-12] (Realtek Semiconductor)
HKU\S-1-5-21-3618845328-3567646341-2803681407-1001\...\Run: [Google Update] => C:\Users\Lea\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-01-29] (Google Inc.)
HKU\S-1-5-21-3618845328-3567646341-2803681407-1001\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [18706176 2013-01-08] (Skype Technologies S.A.)
HKU\S-1-5-21-3618845328-3567646341-2803681407-1001\...\Run: [Steam] => D:\Program Files\Steam\steam.exe [1754816 2014-05-29] (Valve Corporation)
HKU\S-1-5-21-3618845328-3567646341-2803681407-1001\...\Run: [Spotify Web Helper] => C:\Users\Lea\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-02-27] (Spotify Ltd)
==================== Internet (Whitelisted) ====================
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Lea\AppData\Roaming\Mozilla\Firefox\Profiles\ahrxp4jq.default
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com')%20%7B%20return%20'PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us14.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us15.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Lea\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Lea\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Anti-Aliasing Tuner - C:\Users\Lea\AppData\Roaming\Mozilla\Firefox\Profiles\ahrxp4jq.default\Extensions\aatuner@hotmint.com [2013-01-29]
FF Extension: Adblock Plus - C:\Users\Lea\AppData\Roaming\Mozilla\Firefox\Profiles\ahrxp4jq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-01-29]
Chrome:
=======
CHR HomePage: hxxp://www.google.de/
CHR StartupUrls: "hxxp://www.google.de/"
CHR Plugin: (Shockwave Flash) - C:\Users\Lea\AppData\Local\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Lea\AppData\Local\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Lea\AppData\Local\Google\Chrome\Application\35.0.1916.153\pdf.dll ()
CHR Plugin: (Google Update) - C:\Users\Lea\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Extension: (Google Docs) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-01-29]
CHR Extension: (Google Drive) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-29]
CHR Extension: (YouTube) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-29]
CHR Extension: (Adblock Plus) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-01-29]
CHR Extension: (Google-Suche) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-29]
CHR Extension: (ProxMate - Improve your Internet!) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm [2013-04-01]
CHR Extension: (Google Wallet) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-05]
CHR Extension: (Google Mail) - C:\Users\Lea\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-29]
========================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 AtherosSvc; C:\Windows\system32\AdminService.exe [157184 2012-02-02] (Atheros Commnucations)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14480 2014-03-28] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 athr; C:\Windows\system32\DRIVERS\athr.sys [2273280 2012-06-02] (Qualcomm Atheros Communications, Inc.)
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [24576 2012-07-26] (Microsoft Corporation)
R3 BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [253288 2012-02-10] (Atheros)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [242240 2013-04-19] (DT Soft Ltd)
R3 RSPCIESTOR; C:\Windows\system32\DRIVERS\RtsPStor.sys [256616 2012-03-29] (Realtek Semiconductor Corp.)
S3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation)
S3 amdiox86; \SystemRoot\System32\drivers\amdiox86.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-04 22:07 - 2014-07-04 22:07 - 00009912 _____ () C:\Users\Lea\Desktop\FRST.txt
2014-07-04 22:06 - 2014-07-04 22:07 - 00000000 ____D () C:\FRST
2014-07-04 22:03 - 2014-07-04 22:03 - 01073664 _____ (Farbar) C:\Users\Lea\Desktop\FRST.exe
2014-06-27 21:51 - 2014-06-27 21:51 - 01742864 _____ () C:\Users\Lea\Downloads\wrar510.exe
2014-06-26 22:58 - 2014-06-26 22:58 - 02347384 _____ (ESET) C:\Users\Lea\Downloads\esetsmartinstaller_deu.exe
2014-06-26 22:58 - 2014-06-26 22:58 - 00000000 ____D () C:\Program Files\ESET
2014-06-26 20:03 - 2014-06-26 20:03 - 00000000 ____D () C:\ProgramData\Blizzard
2014-06-22 05:56 - 2014-06-22 05:56 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3618845328-3567646341-2803681407-1001Core1cf8dcdeaf0100c.job
2014-06-13 06:00 - 2014-07-02 01:01 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-13 06:00 - 2014-06-13 06:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-13 05:59 - 2014-06-13 05:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lea\Documents\mbam-setup-2.0.2.1012.exe
2014-06-13 05:59 - 2014-06-13 05:59 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-13 05:59 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-13 05:59 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-12 16:02 - 2014-05-24 03:27 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 16:02 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 16:02 - 2014-05-24 03:26 - 00661504 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-12 16:02 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 16:02 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 16:02 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 16:02 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 16:02 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 16:02 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 16:02 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 16:01 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 16:01 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 16:01 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 16:01 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 16:01 - 2014-05-03 06:06 - 02800128 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-12 16:01 - 2014-04-30 00:31 - 01075712 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-12 16:01 - 2014-04-03 11:17 - 01799512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 16:01 - 2014-04-03 10:47 - 00297304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-12 16:01 - 2014-04-03 05:09 - 00495104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-12 16:01 - 2014-04-01 00:07 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-12 16:01 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-12 16:01 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-10 21:50 - 2014-06-10 21:50 - 00000092 _____ () C:\Users\Lea\Desktop\eis.de bestellung.txt
==================== One Month Modified Files and Folders =======
2014-07-04 22:07 - 2014-07-04 22:07 - 00009912 _____ () C:\Users\Lea\Desktop\FRST.txt
2014-07-04 22:07 - 2014-07-04 22:06 - 00000000 ____D () C:\FRST
2014-07-04 22:03 - 2014-07-04 22:03 - 01073664 _____ (Farbar) C:\Users\Lea\Desktop\FRST.exe
2014-07-04 21:09 - 2013-01-29 22:22 - 00000000 ____D () C:\Users\Lea\AppData\Roaming\mIRC
2014-07-04 21:00 - 2012-07-26 08:53 - 00000000 ____D () C:\Windows\system32\sru
2014-07-04 18:12 - 2013-01-29 20:45 - 01364474 _____ () C:\Windows\WindowsUpdate.log
2014-07-04 05:33 - 2012-07-26 08:53 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-07-04 00:44 - 2012-07-26 06:17 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-07-03 05:18 - 2013-01-29 23:17 - 00000000 ____D () C:\Users\Lea\AppData\Roaming\Skype
2014-07-02 01:01 - 2014-06-13 06:00 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-02 00:53 - 2013-01-29 20:48 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-30 12:06 - 2012-07-26 08:53 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-06-27 21:51 - 2014-06-27 21:51 - 01742864 _____ () C:\Users\Lea\Downloads\wrar510.exe
2014-06-27 21:51 - 2013-02-05 02:54 - 00000000 ____D () C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-06-27 21:51 - 2013-02-05 02:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-06-27 21:51 - 2013-02-05 02:54 - 00000000 ____D () C:\Program Files\WinRAR
2014-06-26 22:58 - 2014-06-26 22:58 - 02347384 _____ (ESET) C:\Users\Lea\Downloads\esetsmartinstaller_deu.exe
2014-06-26 22:58 - 2014-06-26 22:58 - 00000000 ____D () C:\Program Files\ESET
2014-06-26 21:55 - 2013-01-29 22:48 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-06-26 21:55 - 2013-01-29 20:38 - 00005088 _____ () C:\Windows\PFRO.log
2014-06-26 21:55 - 2012-07-26 08:04 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-26 20:03 - 2014-06-26 20:03 - 00000000 ____D () C:\ProgramData\Blizzard
2014-06-22 05:56 - 2014-06-22 05:56 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3618845328-3567646341-2803681407-1001Core1cf8dcdeaf0100c.job
2014-06-18 16:28 - 2014-05-10 05:03 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-06-13 15:01 - 2013-02-03 14:26 - 00000000 ____D () C:\Program Files\Common Files\Steam
2014-06-13 12:50 - 2012-07-26 08:53 - 00000000 ____D () C:\Windows\rescache
2014-06-13 12:24 - 2012-07-26 06:17 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-13 06:00 - 2014-06-13 06:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-13 06:00 - 2013-07-24 09:31 - 00000000 ____D () C:\Users\Lea\AppData\Roaming\Malwarebytes
2014-06-13 06:00 - 2013-07-24 09:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-13 05:59 - 2014-06-13 05:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lea\Documents\mbam-setup-2.0.2.1012.exe
2014-06-13 05:59 - 2014-06-13 05:59 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-13 04:31 - 2013-08-15 07:40 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-13 04:26 - 2013-01-30 20:54 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 16:14 - 2012-07-26 08:43 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-12 16:12 - 2012-07-26 08:53 - 00000000 ____D () C:\Windows\system32\de-DE
2014-06-10 21:50 - 2014-06-10 21:50 - 00000092 _____ () C:\Users\Lea\Downloads\bestell.txt
Some content of TEMP:
====================
C:\Users\Lea\AppData\Local\Temp\13-1_mobility_vista_win7_win8_32_dd_ccc_whql.exe
C:\Users\Lea\AppData\Local\Temp\devcon.exe
C:\Users\Lea\AppData\Local\Temp\mirc729.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-03 16:55
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:03-07-2014
Ran by Lea at 2014-07-04 22:08:20
Running from C:\Users\Lea\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 12.5.100.21219 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{625F07A5-04BC-4C60-7B55-5CE9A967E18B}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2012.1219.1521.27485 - Ihr Firmenname) Hidden
AMD VISION Engine Control Center (Version: 2012.1219.1521.27485 - Ihr Firmenname) Hidden
Audacity 2.0.5 (HKLM\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment)
Catalyst Control Center - Branding (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
ccc-utility (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Google Chrome (HKCU\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Hearthstone (HKLM\...\Hearthstone) (Version: - Blizzard Entertainment)
Hotline Miami (HKLM\...\Steam App 219150) (Version: - Dennaton Games)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x86__8wekyb3d8bbwe (x86) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
mIRC (HKLM\...\mIRC) (Version: 7.29 - mIRC Co. Ltd.)
Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden
OpenAL (HKLM\...\OpenAL) (Version: - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
Skype™ 6.1 (HKLM\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.1.129 - Skype Technologies S.A.)
Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB)
Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)
Windows Live Communications Platform (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Messenger (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
WinRAR 5.10 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
==================== Restore Points =========================
10-06-2014 15:18:17 Geplanter Prüfpunkt
20-06-2014 05:54:21 Geplanter Prüfpunkt
28-06-2014 05:31:00 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2012-07-26 06:17 - 2012-07-26 06:17 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1E84DCB8-8C84-4436-A108-209A65086823} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {3D27B6DC-5D28-49C6-A027-3F49AB41E401} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-06-13] (Microsoft Corporation)
Task: {545C008C-4471-44F8-AD15-96CB8BB2BB0C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {56F59500-C4D1-4720-859F-13B4998AA792} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {5A69D491-538F-41EE-851E-277EF291238F} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation)
Task: {99768757-32DC-4E02-BE1E-2FE4783695EE} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {EF9592CE-7796-47A6-9CD5-8630640D45BB} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3618845328-3567646341-2803681407-1001Core1cf8dcdeaf0100c.job => C:\Users\Lea\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2012-12-19 16:31 - 2012-12-19 16:31 - 00065024 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2012-12-19 16:31 - 2012-12-19 16:31 - 00095232 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
HKCU\...\StartupApproved\Run: => "Google Update"
HKCU\...\StartupApproved\Run: => "Skype"
HKCU\...\StartupApproved\Run: => "Steam"
==================== Faulty Device Manager Devices =============
Name: HP Webcam-101
Description: USB-Videogerät
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/28/2014 06:57:50 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Map.exe, Version 1.2.0.136 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 2d4
Startzeit: 01cf928d6b949486
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\WindowsApps\Microsoft.BingMaps_1.2.0.136_x86__8wekyb3d8bbwe\Map.exe
Berichts-ID: b639500c-fe80-11e3-afcc-d0df9a1a31be
Vollständiger Name des fehlerhaften Pakets: Microsoft.BingMaps_1.2.0.136_x86__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexMaps
Error: (06/28/2014 06:57:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: LEA)
Description: Das Paket „Microsoft.BingMaps_1.2.0.136_x86__8wekyb3d8bbwe“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (06/25/2014 08:57:36 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (06/21/2014 06:29:44 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (06/19/2014 04:17:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233
Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0xb80
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5
Error: (06/19/2014 04:17:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 30.0.0.5269 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 11cc
Startzeit: 01cf8bc2cbe0f585
Endzeit: 62
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: 7ea79393-f7bc-11e3-afcb-d0df9a1a31be
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/18/2014 02:13:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: c64
Startzeit: 01cf8aec2efb0fd2
Endzeit: 15
Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe
Berichts-ID: f67285ec-f6e1-11e3-afcb-d0df9a1a31be
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/18/2014 01:22:07 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LEA)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (06/18/2014 01:22:07 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LEA)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (06/18/2014 00:06:13 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
System errors:
=============
Error: (07/04/2014 01:31:54 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/03/2014 02:06:49 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/02/2014 08:19:26 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/02/2014 07:23:07 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/01/2014 06:51:14 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (07/01/2014 05:23:55 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (06/30/2014 00:47:53 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (06/27/2014 08:38:01 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (06/26/2014 09:55:53 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 26.06.2014 um 20:13:27 unerwartet heruntergefahren.
Error: (06/26/2014 08:34:33 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Microsoft Office Sessions:
=========================
Error: (06/28/2014 06:57:50 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Map.exe1.2.0.1362d401cf928d6b9494864294967295C:\Program Files\WindowsApps\Microsoft.BingMaps_1.2.0.136_x86__8wekyb3d8bbwe\Map.exeb639500c-fe80-11e3-afcc-d0df9a1a31beMicrosoft.BingMaps_1.2.0.136_x86__8wekyb3d8bbweAppexMaps
Error: (06/28/2014 06:57:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: LEA)
Description: Microsoft.BingMaps_1.2.0.136_x86__8wekyb3d8bbwe
Error: (06/25/2014 08:57:36 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (06/21/2014 06:29:44 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (06/19/2014 04:17:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141bb8001cf8bc5c03914bbC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll81c2a1a2-f7bc-11e3-afcb-d0df9a1a31be
Error: (06/19/2014 04:17:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe30.0.0.526911cc01cf8bc2cbe0f58562C:\Program Files\Mozilla Firefox\firefox.exe7ea79393-f7bc-11e3-afcb-d0df9a1a31be
Error: (06/18/2014 02:13:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe29.0.1.5239c6401cf8aec2efb0fd215C:\Program Files\Mozilla Firefox\firefox.exef67285ec-f6e1-11e3-afcb-d0df9a1a31be
Error: (06/18/2014 01:22:07 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LEA)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (06/18/2014 01:22:07 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LEA)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (06/18/2014 00:06:13 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
==================== Memory info ===========================
Percentage of memory in use: 23%
Total physical RAM: 3578.9 MB
Available physical RAM: 2755.08 MB
Total Pagefile: 4266.9 MB
Available Pagefile: 3230.32 MB
Total Virtual: 2047.88 MB
Available Virtual: 1847.31 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:102.68 GB) (Free:72.8 GB) NTFS
Drive d: () (Fixed) (Total:195.31 GB) (Free:100.54 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: B03E7563)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=103 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=195 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |