Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Unregelmässiger Computer Freeze ohne ersichtlichem Grund (https://www.trojaner-board.de/163361-unregelmaessiger-computer-freeze-ohne-ersichtlichem-grund.html)

QueenZoe 04.02.2015 21:19

Mein Computer stürtzt immernoch ab :/ ,von daher lösche ich die Programme voresrt mal nicht.

schrauber 05.02.2015 08:26

Jetzt ist aber zumindest mal die Malware weg.

Bitte mal ein Log mit Bluescreenview erstellen:
Windows Bluescreen Absturz analysieren und beheben - so geht's - Anleitungen

QueenZoe 05.02.2015 19:55

Also wenn ich das Starte dann ist da nichts zum markieren.
http://prntscr.com/61ghm1

schrauber 06.02.2015 08:13

Wenn er Rechner abstürzt, was genau passiert dann? kommt ein Bluescreen?

QueenZoe 06.02.2015 20:32

Nein wie im Titel schon steht, er freezed und stürtzt sozusagen nicht ab, ich kann ihn dann aber nur noch manuell ausschalten da er sonst auf nichts anderes mehr reagiert also an Tasten.

schrauber 07.02.2015 12:08

ProcessExplorer als Ersatz für den Windows Taskmanager installieren

Lade Dir den Process Explorer als Ersatz für den Taskmanager herunter und installiere ihn, hier findest Du eine Anleitung. Das ist ein wesentlich leistungsfähigerer Ersatz für den Windows-Taskmanager. Im Menü unter "Options" kannst Du den ProcessExplorer dauerhaft als Ersatz für den Taskmanager einrichten (Replace Taskmanager). Das ist sehr empfehlenswert, weil der ProcessExplorer erheblich mehr Funktionen als der Taskmanager hat. Wenn Du diese Einstellung gemacht hast, öffnet sich mit der Tastenkombination STRG + ALT + Entf. nicht mehr der Taskmanager, sondern der ProcessExplorer. Das kann jederzeit durch Abhaken dieser Einstellung wieder rückgängig gemacht werden.

Was wir jetzt konkret brauchen: In jeder Zeile steht ein Prozess, ein paar der Zeilen sind keine richtigen Prozesse, sondern nur Pseudoprozesse für die Tätigkeit des Windos-Kernels. Im Menü View => Select Columns wird ein Dialog geöffnet, in dem Du auswählen kannst, welche Spalten mit Informationen zu den Prozessen angezeigt werden sollen. In dem gehe in das Register "Process Performance" und stelle sicher, dass dort "CPU Usage" angehakt ist, "CPU History" wäre ebenfalls sinnvoll. Unter "CPU Usage" wird der aktuelle Wert der Prozessorauslastung für jeden Prozess angezeigt (im Tabellentitel steht nur kurz "CPU"), "CPU History" blendet für jeden Prozess ein Diagramm ein, das eine Kurve mit der Prozessorauslastung für die letzte Zeit anzeigt.

Damit sollte es Dir möglich sein, zu identifizieren, welcher Prozess Deine CPU in Trab hält. Mache einen Doppelklick auf den Prozess. Du kannst von dem ganzen auch einen Screenshot machen und ihn als Anhang mit Deiner Antwort hochladen (auf "Erweitert" unter dem Textfeld klicken und über "Anhänge verwalten" auf Deinem Rechner suchen lassen und über "Hochladen" anhängen).


Beobachte die CPU Last wenn er freezed. Kannst Du die Maus bewegen wenn er freezed?

QueenZoe 08.02.2015 15:17

Ich habe mir das Programm runtergeladen, nur wei finde ich jetzt heraus was genau der Freeze auslöst?
Das blöde ist das ich dann genau in nem Spiel bin und das Programm nicht dauernd offen habe. Ich kann es ja bei einem Freeze nicht öffnen oder anschauen.
Wenn mein PC freezed dann kann ich nichts mehr machen nichtmal die Maus bewegen.

schrauber 08.02.2015 18:17

Das Programm immer offen lassen, Spiel nicht Vollbild. Aber wenn Du nit mal die Maus bewegen kannst tönt das so als bleibt die ganze Platte stehen.


Rechner Temperaturen prüfen und auslesen - so geht's - Anleitungen
Zustand der Festplatte herausfinden - so gehts - Anleitungen

QueenZoe 10.02.2015 13:59

Liste der Anhänge anzeigen (Anzahl: 1)
Hm eben ist estwas seltsames passiert, zuerst ist mein Bildschirm kurz schwarz geworden und danach war er Blau und etwas stand in weiss, ich weiss nicht was da stand aber irgend was hat bis 100 gezählt.

Ich habe jetzt danach das Programm wegen der Temperatur geöffnet und davon nen Screen gemacht.
Anhang 72486
Und den zustand der Festplatte habe ich auch kopiert.

----------------------------------------------------------------------------
CrystalDiskInfo 6.3.0 (C) 2008-2015 hiyohiyo
Crystal Dew World : hxxp://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x64)
Date : 2015/02/10 13:57:15

-- Controller Map ----------------------------------------------------------
+ Intel(R) 9 Series Chipset Family SATA AHCI Controller [ATA]
- Samsung SSD 840 EVO 120G SCSI Disk Device
- WDC WD20EARS-00MVWB0 SCSI Disk Device
- ATAPI DVD A DH16A3L SCSI CdRom Device

-- Disk List ---------------------------------------------------------------
(1) Samsung SSD 840 EVO 120GB : 120.0 GB [0/0/0, pd1] - sg
(2) WDC WD20EARS-00MVWB0 : 2000.3 GB [1/0/0, pd1] - wd
(3) WDC WD10JMVW-11AJGS2 : 1000.1 GB [2/X/X, sa1] (V=1058, P=0820) - wd

----------------------------------------------------------------------------
(1) Samsung SSD 840 EVO 120GB
----------------------------------------------------------------------------
Model : Samsung SSD 840 EVO 120GB
Firmware : EXT0BB6Q
Serial Number : S1D5NSBF116763R
Disk Size : 120.0 GB (8.4/120.0/120.0/120.0)
Buffer Size : Unbekannt
Queue Depth : 32
# of Sectors : 234441648
Rotation Rate : ---- (SSD)
Interface : Serial ATA
Major Version : ACS-2
Minor Version : ATA8-ACS version 4c
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 1444 Std.
Power On Count : 527 mal
Host Writes : 1533 GB
Wear Level Count : 17
Temperature : 33 C (91 F)
Health Status : Gut (100 %)
Features : S.M.A.R.T., 48bit LBA, NCQ, TRIM
APM Level : ----
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
05 100 100 _10 000000000000 Anz. wiederzugewiesener Sektoren
09 _99 _99 __0 0000000005A4 Betriebsstunden
0C _99 _99 __0 00000000020F Anz. Geräte-Einschaltvorgänge
B1 _98 _98 __0 000000000011 Verschleißregulierung
B3 100 100 _10 000000000000 Benutzte reservierte Blöcke (gesamt)
B5 100 100 _10 000000000000 Programmfehler (gesamt)
B6 100 100 _10 000000000000 Löschfehler (gesamt)
B7 100 100 _10 000000000000 Laufzeit schlechter Blöcke (gesamt)
BB 100 100 __0 000000000000 Nicht korrigierbare Fehler
BE _67 _65 __0 000000000021 Luftstromtemperatur
C3 200 200 __0 000000000000 ECC-Fehlerrate
C7 100 100 __0 000000000000 CRC-Fehler
EB _99 _99 __0 00000000012B POR-Wiederherstellungszähler
F1 _99 _99 __0 0000BFA87E15 LBA geschrieben (gesamt)

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5331 4435 4E53 4246 3131 3637 3633 5220 2020 2020
020: 0000 0000 0000 4558 5430 4242 3651 5361 6D73 756E
030: 6720 5353 4420 3834 3020 4556 4F20 3132 3047 4220
040: 2020 2020 2020 2020 2020 2020 2020 8001 4001 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0101
060: 4BB0 0DF9 0000 0007 0003 0078 0078 0078 0078 0F10
070: 0000 0000 0000 0000 0000 001F 850E 0046 006C 006C
080: 03FC 0039 746B 7D01 4163 7469 BC01 4163 407F 0001
090: 0004 0000 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 4BB0 0DF9 0000 0000 0000 0008 4000 0000 5002 5388
110: A01E 6219 0000 0000 0000 0000 0000 0000 0000 401E
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 0001 0000 0000
220: 0000 0000 107F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0800 0000 0000 0000 0000
240: 0000 0000 0000 4000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 7DA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 05 33 00 64 64 00 00 00 00 00 00 00 09 32
010: 00 63 63 A4 05 00 00 00 00 00 0C 32 00 63 63 0F
020: 02 00 00 00 00 00 B1 13 00 62 62 11 00 00 00 00
030: 00 00 B3 13 00 64 64 00 00 00 00 00 00 00 B5 32
040: 00 64 64 00 00 00 00 00 00 00 B6 32 00 64 64 00
050: 00 00 00 00 00 00 B7 13 00 64 64 00 00 00 00 00
060: 00 00 BB 32 00 64 64 00 00 00 00 00 00 00 BE 32
070: 00 43 41 21 00 00 00 00 00 00 C3 1A 00 C8 C8 00
080: 00 00 00 00 00 00 C7 3E 00 64 64 00 00 00 00 00
090: 00 00 EB 12 00 63 63 2B 01 00 00 00 00 00 F1 32
0A0: 00 63 63 15 7E A8 BF 00 00 00 00 00 00 00 00 00
0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 68 10 00 53
170: 03 00 01 00 02 46 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 BB

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 05 0A 00 00 00 00 00 00 00 00 00 00 09 00
010: 00 00 00 00 00 00 00 00 00 00 0C 00 00 00 00 00
020: 00 00 00 00 00 00 B1 00 00 00 00 00 00 00 00 00
030: 00 00 B3 0A 00 00 00 00 00 00 00 00 00 00 B5 0A
040: 00 00 00 00 00 00 00 00 00 00 B6 0A 00 00 00 00
050: 00 00 00 00 00 00 B7 0A 00 00 00 00 00 00 00 00
060: 00 00 BB 00 00 00 00 00 00 00 00 00 00 00 BE 00
070: 00 00 00 00 00 00 00 00 00 00 C3 00 00 00 00 00
080: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
090: 00 00 EB 00 00 00 00 00 00 00 00 00 00 00 F1 00
0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4E

----------------------------------------------------------------------------
(2) WDC WD20EARS-00MVWB0
----------------------------------------------------------------------------
Model : WDC WD20EARS-00MVWB0
Firmware : 51.0AB51
Serial Number : WD-WCAZA5644122
Disk Size : 2000.3 GB (8.4/137.4/2000.3/2000.3)
Buffer Size : Unbekannt
Queue Depth : 32
# of Sectors : 3907029168
Rotation Rate : Unbekannt
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : ---- | SATA/300
Power On Hours : 8852 Std.
Power On Count : 1363 mal
Temperature : 31 C (87 F)
Health Status : Gut
Features : S.M.A.R.T., AAM, 48bit LBA, NCQ
APM Level : ----
AAM Level : 80FEh [OFF]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Lesefehlerrate
03 243 168 _21 000000000B09 Mittl. Anlaufzeit
04 _99 _99 __0 000000000728 Start/Stopp-Zyklen d. Spindel
05 200 200 140 000000000000 Anz. wiederzugewiesener Sektoren
07 100 253 __0 000000000000 Anz. Suchfehler
09 _88 _88 __0 000000002294 Betriebsstunden
0A 100 100 __0 000000000000 Anz. misslungener Spindelanläufe
0B 100 100 __0 000000000000 Anz. notwendiger Rekalibrierungen
0C _99 _99 __0 000000000553 Anz. Geräte-Einschaltvorgänge
C0 200 200 __0 0000000000C2 Ausschaltungsabbrüche
C1 180 180 __0 00000000F194 Laden/Entladen-Zyklen
C2 119 109 __0 00000000001F Temperatur
C4 200 200 __0 000000000000 Wiederzuweisungsereignisse
C5 200 200 __0 000000000000 Aktuell schwebende Sektoren
C6 200 200 __0 000000000000 Nicht korrigierbare Sektoren
C7 200 200 __0 000000000000 UltraDMA-CRC-Fehler
C8 200 200 __0 000000000000 Schreibfehlerrate

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5743 415A 4135 3634 3431 3232
020: 0000 0000 0032 3531 2E30 4142 3531 5744 4320 5744
030: 3230 4541 5253 2D30 304D 5657 4230 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 1706 0000 0044 0044
080: 01FE 0000 746B 7F61 4123 7469 BC41 4123 407F 00BB
090: 00BB 0000 FFFE 0000 80FE 0000 0000 0000 0000 0000
100: 88B0 E8E0 0000 0000 0000 0000 0000 0000 5001 4EE2
110: 05A9 7D49 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 3035 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 101E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 5BA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 F3 A8 09 0B 00 00 00 00 00 04 32 00 63 63 28
020: 07 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 64 FD 00 00 00 00 00 00 00 09 32
040: 00 58 58 94 22 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 63 63 53 05 00 00 00 00 00 C0 32
070: 00 C8 C8 C2 00 00 00 00 00 00 C1 32 00 B4 B4 94
080: F1 00 00 00 00 00 C2 22 00 77 6D 1F 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 C8 C8 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 C8 C8 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 82 00 34 8F 01 7B
170: 03 00 01 00 02 FF 05 62 01 00 00 00 00 00 00 00
180: 00 00 01 06 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 C8 C8 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 64 64 64 64 64 64 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 C8 C8 C8 C8 C8 C8 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05

----------------------------------------------------------------------------
(3) WDC WD10JMVW-11AJGS2
----------------------------------------------------------------------------
Enclosure : WD My Passport 0820 USB Device (V=1058, P=0820, sa1) - wd
Model : WDC WD10JMVW-11AJGS2
Firmware : 01.01A01
Serial Number : WD-WXH1AA3S8510
Disk Size : 1000.1 GB (8.4/137.4/1000.1/1000.1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1953459633
Rotation Rate : 5400 RPM
Interface : USB (Serial ATA)
Major Version : ACS-2
Minor Version : ----
Transfer Mode : SATA/300 | SATA/300
Power On Hours : 1075 Std.
Power On Count : 195 mal
Temperature : 36 C (96 F)
Health Status : Gut
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Lesefehlerrate
03 142 131 _21 000000000F12 Mittl. Anlaufzeit
04 100 100 __0 0000000001A1 Start/Stopp-Zyklen d. Spindel
05 200 200 140 000000000000 Anz. wiederzugewiesener Sektoren
07 100 253 __0 000000000000 Anz. Suchfehler
09 _99 _99 __0 000000000433 Betriebsstunden
0A 100 100 __0 000000000000 Anz. misslungener Spindelanläufe
0B 100 100 __0 000000000000 Anz. notwendiger Rekalibrierungen
0C 100 100 __0 0000000000C3 Anz. Geräte-Einschaltvorgänge
C0 200 200 __0 00000000003A Ausschaltungsabbrüche
C1 197 197 __0 000000002AF6 Laden/Entladen-Zyklen
C2 111 105 __0 000000000024 Temperatur
C4 200 200 __0 000000000000 Wiederzuweisungsereignisse
C5 200 200 __0 000000000000 Aktuell schwebende Sektoren
C6 100 253 __0 000000000000 Nicht korrigierbare Sektoren
C7 200 200 __0 000000000000 UltraDMA-CRC-Fehler
C8 100 253 __0 000000000000 Schreibfehlerrate

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 4831 4141 3353 3835 3130
020: 0000 4000 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3130 4A4D 5657 2D31 3141 4A47 5332 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0107 0003 0078 0078 0078 0078 0010
070: 0000 0000 0000 0000 0000 001F 9F06 0004 004C 0000
080: 03FE 0000 706B 7C69 6123 7069 BC49 6123 007F 00B3
090: 0001 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB1 746F 0000 0000 0000 0000 6003 0000 5001 4EE6
110: 596E F820 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0021 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 DBA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 8E 83 12 0F 00 00 00 00 00 04 32 00 64 64 A1
020: 01 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 64 FD 00 00 00 00 00 00 00 09 32
040: 00 63 63 33 04 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 64 64 C3 00 00 00 00 00 00 C0 32
070: 00 C8 C8 3A 00 00 00 00 00 00 C1 32 00 C5 C5 F6
080: 2A 00 00 00 00 00 C2 22 00 6F 69 24 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 64 FD 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 64 FD 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 20 49 01 7B
170: 03 00 01 00 02 D1 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 AF

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 64 64 64 64 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D

schrauber 10.02.2015 18:28

Bitte mal nen Bericht mit Bluescreenview erstellen:

Windows Bluescreen Absturz analysieren und beheben - so geht's - Anleitungen

QueenZoe 10.02.2015 20:34

Liste der Anhänge anzeigen (Anzahl: 2)
Jetzt sind es wieder normale Freezes, ich habe nach dem noch mal 2 Screens wegen den Temperaturen und der Festplatte gemacht.

Anhang 72501

Anhang 72502

Ach wegen der CPU auslastung, ich glaube Java ist daran schuld, das braucht teilweise wenn ich gerade schaue 90% der Kapatzität. Oder wenn ich ein bestimtes Spiel von Steam spiele, dann freezed er auch.

schrauber 11.02.2015 07:38

Deinstalliere alles von Java und installere neu. Die Temps sind schon grenzwertig.
Bericht von Bluescreenview bitte noch.

QueenZoe 11.02.2015 10:36

Hier der Bericht vom Bluescreen, es ist jetzt schon 2 mal passiert.

Code:

==================================================
Dump File        : 021015-9968-01.dmp
Crash Time        : 10.02.2015 13:45:46
Bug Check String  :
Bug Check Code    : 0x00000124
Parameter 1      : 00000000`00000000
Parameter 2      : fffffa80`07839028
Parameter 3      : 00000000`be000000
Parameter 4      : 00000000`0100110a
Caused By Driver  : hal.dll
Caused By Address : hal.dll+12a3b
File Description  :
Product Name      :
Company          :
File Version      :
Processor        : x64
Crash Address    : ntoskrnl.exe+76e80
Stack Address 1  :
Stack Address 2  :
Stack Address 3  :
Computer Name    :
Full Path        : C:\Windows\Minidump\021015-9968-01.dmp
Processors Count  : 8
Major Version    : 15
Minor Version    : 7601
Dump File Size    : 281'664
Dump File Time    : 10.02.2015 13:46:47
==================================================

==================================================
Dump File        : 021015-12760-01.dmp
Crash Time        : 10.02.2015 17:45:31
Bug Check String  :
Bug Check Code    : 0x00000124
Parameter 1      : 00000000`00000000
Parameter 2      : fffffa80`07827028
Parameter 3      : 00000000`be000000
Parameter 4      : 00000000`0100110a
Caused By Driver  : hal.dll
Caused By Address : hal.dll+12a3b
File Description  :
Product Name      :
Company          :
File Version      :
Processor        : x64
Crash Address    : ntoskrnl.exe+76e80
Stack Address 1  :
Stack Address 2  :
Stack Address 3  :
Computer Name    :
Full Path        : C:\Windows\Minidump\021015-12760-01.dmp
Processors Count  : 8
Major Version    : 15
Minor Version    : 7601
Dump File Size    : 281'664
Dump File Time    : 10.02.2015 17:46:19
==================================================


schrauber 11.02.2015 17:03

Poste mal bitte ein frisches FRST.log.

QueenZoe 11.02.2015 23:14

FRST.log :


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-02-2015 02
Ran by Chiara (administrator) on BLUESTAR on 11-02-2015 23:13:03
Running from C:\Users\Chiara\Downloads
Loaded Profiles: Chiara (Available profiles: Chiara & Gast)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) D:\Steam\Steam.exe
(Oracle Corporation) C:\Users\Chiara\Downloads\runtime\jre-x64\1.8.0_25\bin\java.exe
(Oracle Corporation) C:\Users\Chiara\Downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7572696 2014-04-17] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-18] (AVAST Software)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3977576 2015-01-20] (LogMeIn Inc.)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1934744 2015-01-31] (APN)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts)
HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
IFEO\taskmgr.exe: [Debugger] "C:\USERS\CHIARA\APPDATA\LOCAL\TEMP\RAR$EXA0.637\PROCEXP.EXE"
Startup: C:\Users\Chiara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49174;https=127.0.0.1:49174
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1268736343-3887576109-2910839842-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} ->  No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247
FF Homepage: hxxp://www.search.ask.com/?tpid=ORJ-ST-SPE&o=APN11464&pf=V7&trgb=FF&p2=%5EBEA%5EOSJ000%5EYY%5ECH&gct=hp&apn_ptnrs=BEA&apn_dtid=%5EOSJ000%5EYY%5ECH&apn_dbr=ff_35.0.1.5500&apn_uid=CFFB9BD3-36CC-4E25-B3AF-350A80C85E92&itbv=12.24.1.53&doi=2015-02-11&psv=&pt=tb
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1268736343-3887576109-2910839842-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Chiara\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\searchplugins\google-maps.xml
FF Extension: amptrakeepacom - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\amptra@keepa.com [2014-09-08]
FF Extension: Web Helper Lite - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\{53ecb410-cb6c-474d-8ce2-8f9e2c15a4a7} [2014-10-09]
FF Extension: Cliqz Beta - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\cliqz@cliqz.com.xpi [2014-10-07]
FF Extension: MEGA - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\firefox@mega.co.nz.xpi [2014-11-02]
FF Extension: Search App by Ask - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\toolbar_ORJ-SPE@apn.ask.com.xpi [2015-01-31]
FF Extension: Shopping App by Ask - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\toolbar_ORJ-ST-SPE@apn.ask.com.xpi [2015-01-31]
FF Extension: ooVoo Search App powered by Ask - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\toolbar_OVO2-SP@apn.ask.com.xpi [2014-09-11]
FF Extension: Search App - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\{1d33817b-02d7-4cfa-a618-2d2fe2f6add4}.xpi [2014-12-23]
FF Extension: mpeg4 shield - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\{3d69b985-bc93-4bb9-9a0a-e16269028e65}.xpi [2014-10-10]
FF Extension: {9b0ceae4-a807-4940-a439-ad70def3437d} - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\{9b0ceae4-a807-4940-a439-ad70def3437d}.xpi [2014-10-05]
FF Extension: Adblock Plus - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-23]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-18]
FF HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF HKU\S-1-5-21-1268736343-3887576109-2910839842-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Chiara\AppData\Roaming\Mozilla\Firefox\Profiles\wblsi6v6.default-1408827089247\extensions\cliqz@cliqz.com

Chrome:
=======
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_ggbc_14_47_ff&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzyyEzytCzztAtC0AtB0EtCtN0D0Tzu0StCtDyDyBtN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0EtC0DzytAtDyEtG0FyDtC0CtGtDyCtCyBtG0DzzzyyBtGyB0Dzy0CtCyE0B0A0EtCtAtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyDyE0D0CzytDzytG0D0ByDtCtGyE0BtCtCtGzytA0DzytG0D0EyEtD0ByByB0AyBtC0D0E2Q&cr=423194433&ir=
CHR StartupUrls: Default -> "https://www.google.com/?trackid=sp-006"
CHR DefaultSearchURL: Default -> https://www.google.de/search?q={searchTerms}?trackid=sp-006
CHR DefaultSuggestURL: Default -> https://www.google.com/complete/search?client=chrome&q={searchTerms}
CHR Profile: C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-14]
CHR Extension: (Google Docs) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-14]
CHR Extension: (Google Drive) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-14]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07]
CHR Extension: (YouTube) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-26]
CHR Extension: (Google-Suche) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-26]
CHR Extension: (Google Tabellen) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-14]
CHR Extension: (Avira Browserschutz) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-09-08]
CHR Extension: (Skype Click to Call) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-07-31]
CHR Extension: (Google Wallet) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-26]
CHR Extension: (Amazon) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj [2014-10-05]
CHR Extension: (Disable AntiAdblock) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\oimhabmdhenmcaligiilhadkdliolpah [2014-07-31]
CHR Extension: (Google Mail) - C:\Users\Chiara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-26]
CHR HKLM\...\Chrome\Extension: [Äÿ] - No Path
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-18]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\Chiara\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-10-04]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-11-16] (Adobe Systems) [File not signed]
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [177560 2015-01-31] (APN LLC.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2014-01-28] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-18] (AVAST Software)
R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2485608 2015-01-20] (LogMeIn Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [329104 2014-10-03] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2013-01-16] (Hewlett-Packard Company) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-10-18] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-01-28] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-01-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-18] (AVAST Software)
S3 aswTap; C:\Windows\System32\DRIVERS\aswTap.sys [44640 2015-01-18] (The OpenVPN Project)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-18] ()
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [487704 2014-03-14] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2014-04-11] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-11 10:34 - 2015-02-11 10:34 - 00000000 ____D () C:\Users\Chiara\Downloads\runtime
2015-02-11 10:34 - 2015-02-11 10:34 - 00000000 ____D () C:\Users\Chiara\Downloads\game
2015-02-11 10:33 - 2015-02-11 10:33 - 01294088 _____ (Mojang) C:\Users\Chiara\Downloads\Minecraft(2).exe
2015-02-11 10:31 - 2015-02-11 10:31 - 00003626 _____ () C:\Users\Chiara\Desktop\BlueScreenView.txt
2015-02-11 10:29 - 2015-02-11 10:29 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-02-11 10:29 - 2015-02-11 10:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-02-11 10:29 - 2015-02-11 10:29 - 00000000 ____D () C:\Program Files (x86)\Java
2015-02-11 10:27 - 2015-02-11 10:27 - 00000000 ____D () C:\Users\Chiara\AppData\Local\AskPartnerNetwork
2015-02-11 10:27 - 2015-02-11 10:27 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2015-02-11 10:27 - 2015-02-11 10:27 - 00000000 ____D () C:\ProgramData\APN
2015-02-11 10:27 - 2015-02-11 10:27 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2015-02-11 10:24 - 2015-02-11 10:24 - 00639912 _____ (Oracle Corporation) C:\Users\Chiara\Downloads\jxpiinstall.exe
2015-02-11 09:50 - 2015-02-11 09:50 - 00000000 ____D () C:\Users\Chiara\AppData\Local\IsolatedStorage
2015-02-11 09:39 - 2015-02-11 09:48 - 00000000 ____D () C:\ProgramData\Screaming Bee
2015-02-11 09:38 - 2015-02-11 09:38 - 01198368 _____ () C:\Users\Chiara\Downloads\MorphVOX Pro - CHIP-Installer.exe
2015-02-10 21:58 - 2015-02-11 09:50 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\Screaming Bee
2015-02-10 21:57 - 2015-02-11 10:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screaming Bee
2015-02-10 21:57 - 2015-02-11 10:21 - 00000000 ____D () C:\Program Files (x86)\Screaming Bee
2015-02-10 21:57 - 2015-02-10 21:57 - 00002270 _____ () C:\Users\Chiara\Desktop\MorphVOX Junior.lnk
2015-02-10 21:57 - 2015-02-10 21:57 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Screaming Bee
2015-02-10 21:56 - 2015-02-10 21:56 - 02970992 _____ () C:\Users\Chiara\Downloads\MorphVOXJunior_Install-1.exe
2015-02-10 17:46 - 2015-02-10 17:46 - 00281664 _____ () C:\Windows\Minidump\021015-12760-01.dmp
2015-02-10 13:46 - 2015-02-10 17:46 - 00000000 ____D () C:\Windows\Minidump
2015-02-10 13:46 - 2015-02-10 13:46 - 00281664 _____ () C:\Windows\Minidump\021015-9968-01.dmp
2015-02-10 11:24 - 2015-02-10 11:24 - 00001196 _____ () C:\Users\Chiara\Desktop\CrystalDiskInfo.lnk
2015-02-10 11:24 - 2015-02-10 11:24 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\OpenCandy
2015-02-10 11:24 - 2015-02-10 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2015-02-10 11:24 - 2015-02-10 11:24 - 00000000 ____D () C:\Program Files (x86)\CrystalDiskInfo
2015-02-10 11:23 - 2015-02-10 11:23 - 03014272 _____ (Crystal Dew World ) C:\Users\Chiara\Downloads\CrystalDiskInfo6_3_0-en.exe
2015-02-08 19:53 - 2015-02-08 19:53 - 00526371 _____ () C:\Users\Chiara\Desktop\openhardwaremonitor-v0.6.0-beta.zip
2015-02-08 09:38 - 2015-02-08 09:38 - 01188194 _____ () C:\Users\Chiara\Downloads\ProcessExplorer.zip
2015-02-05 19:45 - 2015-02-05 19:48 - 00067892 _____ () C:\Users\Chiara\Downloads\bluescreenview_v1.55.zip
2015-02-03 18:40 - 2015-02-03 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-02 22:13 - 2015-02-03 18:46 - 00036680 _____ () C:\Users\Chiara\Desktop\FRST.txt
2015-02-02 22:11 - 2015-02-02 22:11 - 00000965 _____ () C:\Users\Chiara\Desktop\checkup.txt
2015-02-02 22:10 - 2015-02-02 22:10 - 00852573 _____ () C:\Users\Chiara\Downloads\SecurityCheck.exe
2015-02-02 22:01 - 2015-02-02 22:01 - 00010992 _____ () C:\Users\Chiara\Desktop\ESET.txt
2015-02-02 21:19 - 2015-02-02 21:19 - 02347384 _____ (ESET) C:\Users\Chiara\Downloads\esetsmartinstaller_deu.exe
2015-02-02 21:11 - 2015-02-02 21:11 - 00011853 _____ () C:\Users\Chiara\AppData\Local\recently-used.xbel
2015-01-31 22:07 - 2015-02-11 23:13 - 00000000 ____D () C:\Users\Chiara\Downloads\FRST-OlderVersion
2015-01-31 22:04 - 2015-01-31 22:04 - 01707939 _____ (Thisisu) C:\Users\Chiara\Downloads\JRT.exe
2015-01-31 22:01 - 2015-01-31 22:02 - 00000000 ____D () C:\AdwCleaner
2015-01-31 22:00 - 2015-01-31 22:00 - 02194432 _____ () C:\Users\Chiara\Downloads\AdwCleaner_4.109.exe
2015-01-31 21:50 - 2015-01-31 21:52 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-31 21:50 - 2015-01-31 21:50 - 00000618 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-31 21:50 - 2015-01-31 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-31 21:50 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-31 21:50 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-31 21:50 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-31 21:48 - 2015-01-31 21:48 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Chiara\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-31 11:20 - 2015-01-31 11:20 - 01770497 _____ () C:\Users\Chiara\Documents\Pferd Mystisch.xcf
2015-01-30 22:30 - 2015-01-30 22:30 - 00039626 _____ () C:\ComboFix.txt
2015-01-30 22:25 - 2015-01-30 22:25 - 05611408 ____R (Swearware) C:\Users\Chiara\Downloads\ComboFix.exe
2015-01-30 22:25 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-01-30 22:25 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-01-30 22:25 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-01-30 22:25 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-01-30 22:25 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-01-30 22:25 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-01-30 22:25 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-01-30 22:25 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-01-30 22:19 - 2015-01-30 22:30 - 00000000 ____D () C:\Qoobox
2015-01-30 22:04 - 2015-01-30 22:04 - 00000610 _____ () C:\Users\Chiara\Desktop\Revo Uninstaller.lnk
2015-01-30 22:03 - 2015-01-30 22:03 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Chiara\Downloads\revosetup95.exe
2015-01-29 18:42 - 2015-01-29 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-01-24 16:01 - 2015-01-24 16:02 - 00067728 _____ () C:\Users\Chiara\Downloads\SEUS-v10.1-Standard.zip
2015-01-24 15:46 - 2015-01-24 15:46 - 00878207 _____ () C:\Users\Chiara\Downloads\OptiFine_1.8.0_HD_U_B6.jar
2015-01-24 15:46 - 2015-01-24 15:46 - 00340976 _____ () C:\Users\Chiara\Downloads\ShadersMod-v2.4.7mc1.8.jar
2015-01-24 15:01 - 2015-01-24 15:01 - 00000000 ____D () C:\Users\Chiara\Desktop\Terraria
2015-01-24 14:59 - 2015-01-24 14:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2015-01-24 14:59 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2015-01-24 14:59 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2015-01-24 14:59 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2015-01-24 14:59 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2015-01-24 14:59 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2015-01-24 14:59 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2015-01-19 20:59 - 2015-01-19 20:59 - 00000202 _____ () C:\Users\Chiara\Desktop\APB Reloaded.url
2015-01-18 16:24 - 2015-01-18 16:24 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-01-18 16:23 - 2015-01-18 16:24 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\Dropbox
2015-01-18 16:19 - 2015-02-11 22:55 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-18 16:19 - 2015-01-18 16:19 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-01-18 16:19 - 2015-01-18 16:19 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00087912 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00044640 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\aswTap.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-01-18 16:19 - 2015-01-18 16:19 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-01-18 16:19 - 2015-01-18 16:19 - 00001930 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-01-18 16:19 - 2015-01-18 16:19 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\AVAST Software
2015-01-18 16:19 - 2015-01-18 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-18 16:19 - 2015-01-18 16:19 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-18 16:18 - 2015-01-18 16:18 - 132469808 _____ (AVAST Software) C:\Users\Chiara\Downloads\avast_free_antivirus_setup.exe
2015-01-14 18:09 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 18:09 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 18:09 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 18:09 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 18:09 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 18:09 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 18:09 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 18:09 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 18:09 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 18:09 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 18:09 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 18:09 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 18:09 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 18:05 - 2015-01-14 18:05 - 00000959 _____ () C:\Users\Chiara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2015-01-14 18:05 - 2015-01-14 18:05 - 00000951 _____ () C:\Users\Chiara\Desktop\osu!.lnk
2015-01-14 18:04 - 2015-01-24 14:44 - 00000000 ____D () C:\Users\Chiara\AppData\Local\osu!
2015-01-14 18:04 - 2015-01-14 18:04 - 03200584 _____ (ppy) C:\Users\Chiara\Downloads\osu!install.exe
2015-01-14 18:04 - 2015-01-14 18:04 - 00000000 ____D () C:\Users\Chiara\Downloads\Localisation

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-11 23:13 - 2014-09-17 17:50 - 00000000 ____D () C:\FRST
2015-02-11 23:13 - 2014-09-16 17:42 - 00022506 _____ () C:\Users\Chiara\Downloads\FRST.txt
2015-02-11 23:13 - 2014-09-16 17:41 - 02134016 _____ (Farbar) C:\Users\Chiara\Downloads\FRST64.exe
2015-02-11 23:12 - 2014-08-02 13:55 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\TS3Client
2015-02-11 23:12 - 2014-07-31 21:39 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\Skype
2015-02-11 23:11 - 2014-07-31 21:34 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\.minecraft
2015-02-11 22:51 - 2014-10-06 12:27 - 00000000 ____D () C:\Users\Chiara\AppData\Local\LogMeIn Hamachi
2015-02-11 22:38 - 2014-08-13 10:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-11 22:20 - 2014-09-07 12:57 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-11 19:59 - 2009-07-14 05:45 - 00023088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-11 19:59 - 2009-07-14 05:45 - 00023088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-11 19:58 - 2009-07-14 18:58 - 00700414 _____ () C:\Windows\system32\perfh007.dat
2015-02-11 19:58 - 2009-07-14 18:58 - 00150052 _____ () C:\Windows\system32\perfc007.dat
2015-02-11 19:58 - 2009-07-14 06:13 - 01623866 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-11 19:54 - 2014-07-26 19:39 - 00006462 _____ () C:\Windows\SysWOW64\Gms.log
2015-02-11 19:52 - 2014-09-07 12:57 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-11 19:52 - 2014-08-26 21:52 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-02-11 19:52 - 2014-08-01 13:15 - 00000000 ____D () C:\ProgramData\Origin
2015-02-11 19:52 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-11 19:52 - 2009-07-14 05:51 - 00057332 _____ () C:\Windows\setupact.log
2015-02-11 19:34 - 2014-07-26 18:30 - 01751885 _____ () C:\Windows\WindowsUpdate.log
2015-02-11 17:26 - 2014-08-01 16:22 - 00000000 ____D () C:\Users\Chiara\Downloads\Gameforge Live
2015-02-11 10:31 - 2014-07-26 22:25 - 00000000 ____D () C:\ProgramData\Oracle
2015-02-11 10:24 - 2014-09-01 13:46 - 00000000 ____D () C:\Program Files\Java
2015-02-11 10:21 - 2014-07-26 18:56 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-10 21:27 - 2014-08-26 22:18 - 00347464 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-02-10 21:27 - 2014-08-26 22:15 - 00347464 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-02-08 14:47 - 2014-08-01 16:03 - 00347464 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-02-08 14:33 - 2014-08-01 12:28 - 00000000 ____D () C:\Users\Chiara\.gimp-2.8
2015-02-06 19:21 - 2014-09-07 12:57 - 00002239 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-06 19:15 - 2014-09-07 12:57 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-06 19:15 - 2014-09-07 12:57 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 18:59 - 2014-12-20 21:25 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-04 20:38 - 2014-08-13 10:30 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-04 20:38 - 2014-08-13 10:30 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-04 20:38 - 2014-08-13 10:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-03 18:43 - 2014-08-13 10:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-03 18:43 - 2014-07-26 18:58 - 02110688 _____ () C:\Windows\PFRO.log
2015-02-02 21:11 - 2014-08-01 12:29 - 00000000 ____D () C:\Users\Chiara\AppData\Local\gtk-2.0
2015-01-31 22:02 - 2014-10-03 18:16 - 00000000 ____D () C:\Users\Chiara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
2015-01-31 21:59 - 2014-08-02 17:14 - 00000000 ____D () C:\Windows\de
2015-01-30 22:29 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-30 22:11 - 2014-07-26 18:30 - 00000000 ____D () C:\Users\Chiara
2015-01-29 21:06 - 2014-09-16 17:42 - 00037574 _____ () C:\Users\Chiara\Downloads\Addition.txt
2015-01-24 14:59 - 2014-08-17 13:24 - 00000000 ____D () C:\Users\Chiara\Documents\My Games
2015-01-21 20:46 - 2014-10-05 15:54 - 00000000 ____D () C:\Users\Chiara\Documents\MC skins
2015-01-18 16:20 - 2014-10-11 15:59 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-01-18 16:19 - 2014-09-07 12:56 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-14 23:03 - 2014-07-26 21:01 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 23:01 - 2014-07-26 21:01 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 18:04 - 2014-11-09 19:19 - 00000000 ____D () C:\Program Files (x86)\Skype
2015-01-14 18:04 - 2014-07-31 21:39 - 00000000 ____D () C:\ProgramData\Skype
2015-01-14 11:32 - 2014-11-02 13:46 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys

==================== Files in the root of some directories =======

2014-10-04 19:34 - 2013-03-07 12:48 - 0036864 _____ (Microsoft Corporation) C:\Program Files (x86)\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll
2014-10-04 19:34 - 2013-03-10 05:38 - 0084736 _____ (Microsoft Corporation) C:\Program Files (x86)\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll
2014-10-04 19:34 - 2006-10-03 17:26 - 0037063 _____ () C:\Program Files (x86)\Office Word 2003 Look.dotx
2014-11-23 16:41 - 2014-12-09 18:41 - 0000162 _____ () C:\Users\Chiara\AppData\Roaming\WB.CFG
2014-11-25 19:41 - 2014-12-02 18:41 - 0000002 _____ () C:\Users\Chiara\AppData\Local\DSI.DAT
2015-02-02 21:11 - 2015-02-02 21:11 - 0011853 _____ () C:\Users\Chiara\AppData\Local\recently-used.xbel

Some content of TEMP:
====================
C:\Users\Chiara\AppData\Local\Temp\APNSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-05 19:26

==================== End Of Log ============================

--- --- ---


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:32 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130