|
Log-Analyse und Auswertung: Laptop bootet nicht mehrWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.10.2013, 10:02 | #1 |
| Laptop bootet nicht mehr Hallo zusammen, folgende Schwierigkeit: der Laptop eines Freundes von mir fährt nach der Installation von 25 Windows-Updates nicht mehr hoch. Es erscheint beim Booten ein blauer Bildschirm mit diesem Hinweis: "STOP: C0000135 The program can't start because %hs is missing. Try resintalling the program" Es handelt sich um ein englisches System. Ich habe das Internet bereits nach Lösungen abgesucht aber bisher hat kein Tip funktioniert. Ich habe jetzt das folgende Logfile erstellt und hoffe, dass hier jemand einen Rat weiss. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-10-2013 Ran by SYSTEM on MININT-FT25GKI on 23-10-2013 20:47:07 Running from F:\ Windows 7 Home Premium (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.) HKLM\...\Run: [SiSTray] - C:\Program Files\SiS VGA Utilities\SiSTray.exe [552960 2009-11-12] (Silicon Integrated Systems Corporation) HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-01] (AlcorMicro Co., Ltd.) HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1022904 2010-02-23] (Trend Micro Inc.) HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-29] (AVAST Software) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.) HKU\asus\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-10-02] (Google Inc.) AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL C:\PROGRA~2\MOVIES~1\Datamngr\x64\mgrldr.dll [22528 2013-09-24] () AppInit_DLLs-x32: c:\progra~2\movies~1\datamngr\mgrldr.dll c:\progra~3\wincert\win32c~1.dll [7168 2013-09-22] () IMEO\bitguard.exe: [Debugger] tasklist.exe IMEO\bprotect.exe: [Debugger] tasklist.exe IMEO\browserdefender.exe: [Debugger] tasklist.exe IMEO\browserprotect.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll [485376 2013-09-24] () <===== ATTENTION HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll [657920 2013-09-24] () <===== ATTENTION BootExecute: autocheck autochk * sdnclean64.exe ==================== Services (Whitelisted) ================= S2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] () S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-29] (AVAST Software) S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-13] (Microsoft Corporation) S2 DatamngrCoordinator; C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3419136 2013-09-24] (Bandoo Media Inc.) S2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [225280 2009-12-22] () S4 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation) S2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.) S3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2009-09-29] (Trend Micro Inc.) S3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2009-09-29] (Trend Micro Inc.) S2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-11-16] (Vodafone) S2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-03] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] () S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-29] (AVAST Software) S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software) S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-29] (AVAST Software) S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-29] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-29] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-29] (AVAST Software) S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-29] (AVAST Software) S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-29] (AVAST Software) S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-29] () S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [250368 2010-04-07] (Huawei Technologies Co., Ltd.) S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [92032 2007-05-31] (Huawei Technologies Co., Ltd.) S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 OXSDIDRV_x64; C:\Windows\System32\DRIVERS\OXSDIDRV_x64.sys [51760 2009-09-28] () S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X64.sys [31280 2010-05-24] () S3 SiS6350; C:\Windows\System32\DRIVERS\SISGRKMD.sys [558080 2009-11-12] (Silicon Integrated Systems Corporation) S0 SISAGP; C:\Windows\System32\DRIVERS\SISAGPX.sys [67104 2009-08-01] (Silicon Integrated Systems Corporation) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-08-12] () S2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.) S1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2009-09-29] (Trend Micro Inc.) S2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.) S2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.) S3 tmlwf; S3 tmwfp; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST 2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP 2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log 2013-10-08 16:39 - 2013-10-12 05:46 - 00000280 _____ C:\Windows\setupact.log 2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log 2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini 2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg 2013-10-06 11:13 - 2013-10-06 11:18 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-06 11:07 - 2013-10-06 11:27 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator 2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys 2013-10-06 11:06 - 2013-10-06 11:09 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe 2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2013-10-06 11:01 - 2013-10-12 11:40 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe 2013-09-25 16:33 - 2013-10-08 15:13 - 00027648 ___SH C:\Users\asus\Downloads\Thumbs.db 2013-09-24 12:47 - 2013-10-12 22:14 - 00000000 ____D C:\ProgramData\Datamngr 2013-09-24 12:47 - 2013-09-24 12:47 - 00000000 ____D C:\Program Files (x86)\Movies Toolbar ==================== One Month Modified Files and Folders ======= 2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST 2013-10-12 22:14 - 2013-09-24 12:47 - 00000000 ____D C:\ProgramData\Datamngr 2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 22:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration 2013-10-12 22:12 - 2011-09-26 17:43 - 00000000 ____D C:\users\asus 2013-10-12 22:12 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP 2013-10-12 12:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\tracing 2013-10-12 11:55 - 2013-08-08 18:02 - 00000000 ____D C:\Windows\System32\MRT 2013-10-12 11:46 - 2013-06-25 08:03 - 01240442 _____ C:\Windows\WindowsUpdate.log 2013-10-12 11:40 - 2013-10-06 11:01 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2013-10-12 11:38 - 2013-05-24 04:24 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-12 11:15 - 2011-10-02 15:28 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-12 06:57 - 2011-10-02 15:28 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-12 05:46 - 2013-10-08 16:39 - 00000280 _____ C:\Windows\setupact.log 2013-10-12 05:46 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 03:10 - 2009-07-13 21:13 - 00726444 _____ C:\Windows\System32\PerfStringBackup.INI 2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log 2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log 2013-10-08 15:13 - 2013-09-25 16:33 - 00027648 ___SH C:\Users\asus\Downloads\Thumbs.db 2013-10-08 05:25 - 2011-10-04 14:37 - 00002145 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-06 11:27 - 2013-10-06 11:07 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator 2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini 2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg 2013-10-06 11:21 - 2012-10-11 06:51 - 00000000 ____D C:\Windows\Minidump 2013-10-06 11:18 - 2013-10-06 11:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-06 11:09 - 2013-10-06 11:06 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe 2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys 2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe 2013-10-06 08:37 - 2012-10-23 06:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-06 01:17 - 2012-10-23 06:50 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-03 16:20 - 2011-09-30 04:12 - 00000000 ____D C:\Users\asus\AppData\Roaming\Microgaming 2013-10-02 12:13 - 2009-07-28 22:03 - 00000000 ____D C:\Windows\Panther 2013-10-02 12:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF 2013-10-01 15:09 - 2011-10-02 15:28 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-01 15:09 - 2011-10-02 15:28 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-24 12:47 - 2013-09-24 12:47 - 00000000 ____D C:\Program Files (x86)\Movies Toolbar 2013-09-24 12:47 - 2013-05-27 15:37 - 00000000 ____D C:\ProgramData\Wincert 2013-09-24 12:47 - 2013-05-27 15:36 - 00000000 ____D C:\Program Files (x86)\Search Results Toolbar ZeroAccess: C:\$Recycle.Bin\S-1-5-21-1013183496-1763523383-1214035250-1000\$53710660ac42bd14fc9048f6c21d0c4f ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$53710660ac42bd14fc9048f6c21d0c4f Files to move or delete: ==================== C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll ==================== Known DLLs (Whitelisted) ================ C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION! C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION! ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 24% Total physical RAM: 1919.34 MB Available physical RAM: 1442.74 MB Total Pagefile: 1919.34 MB Available Pagefile: 1430.13 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:58.22 GB) (Free:14.38 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:158.06 GB) (Free:157.74 GB) NTFS Drive f: (INTENSO USB) (Removable) (Total:14.53 GB) (Free:14.53 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 1674CEE9) Partition 1: (Not Active) - (Size=17 GB) - (Type=1C) Partition 2: (Active) - (Size=58 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=158 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 15 GB) (Disk ID: C7B3A61F) Partition 1: (Active) - (Size=15 GB) - (Type=0C) LastRegBack: 2013-08-20 15:42 ==================== End Of Log ============================ |
24.10.2013, 12:05 | #2 |
/// the machine /// TB-Ausbilder | Laptop bootet nicht mehr Systemwiederherstellung schon versucht?
__________________
__________________ |
24.10.2013, 14:27 | #3 |
| Laptop bootet nicht mehr Ja, funktioniert aber leider nicht. "Repair mode" bringt auch nichts.
__________________ |
25.10.2013, 08:50 | #4 |
/// the machine /// TB-Ausbilder | Laptop bootet nicht mehr Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter LastRegBack: 2013-08-20 15:42
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.10.2013, 12:38 | #5 |
| Laptop bootet nicht mehr Alles wie beschrieben gemacht. Habe danach versucht den Laptop hochzufahren aber es erscheint nach wie vor die gleiche Fehlermeldung. (Dachte durch die erfolgreichen Kopien in der Registry wäre das Problem behoben aber zu früh gefreut). Anbei die Fixlogdatei: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-10-2013 Ran by SYSTEM at 2013-10-25 10:53:21 Run:2 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** LastRegBack: 2013-08-20 15:42 ***************** DEFAULT hive was successfully copied to System32\config\HiveBackup DEFAULT hive was successfully restored from registry back up. SAM hive was successfully copied to System32\config\HiveBackup SAM hive was successfully restored from registry back up. SECURITY hive was successfully copied to System32\config\HiveBackup SECURITY hive was successfully restored from registry back up. SOFTWARE hive was successfully copied to System32\config\HiveBackup SOFTWARE hive was successfully restored from registry back up. SYSTEM hive was successfully copied to System32\config\HiveBackup SYSTEM hive was successfully restored from registry back up. ==== End of Fixlog ==== |
26.10.2013, 12:02 | #6 |
/// the machine /// TB-Ausbilder | Laptop bootet nicht mehr Poste nochmal ein frisches FRST log aus der Recovery bitte.
__________________ --> Laptop bootet nicht mehr |
30.10.2013, 10:26 | #7 |
| Laptop bootet nicht mehr Voila: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-10-2013 Ran by SYSTEM on MININT-9F9PQQS on 30-10-2013 07:20:57 Running from F:\ Windows 7 Home Premium (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.) HKLM\...\Run: [SiSTray] - C:\Program Files\SiS VGA Utilities\SiSTray.exe [552960 2009-11-12] (Silicon Integrated Systems Corporation) HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-01] (AlcorMicro Co., Ltd.) HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1022904 2010-02-23] (Trend Micro Inc.) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-29] (AVAST Software) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.) HKLM-x32\...\Run: [DATAMNGR] - C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~2.EXE HKU\asus\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-10-02] (Google Inc.) AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll [97280 2009-07-13] () AppInit_DLLs-x32: C:\PROGRA~3\Wincert\WIN32C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\mgrldr.dll [ ] () HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\apcrtldr.dll <===== ATTENTION HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\apcrtldr.dll <===== ATTENTION ==================== Services (Whitelisted) ================= S2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] () S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-29] (AVAST Software) S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-13] (Microsoft Corporation) S2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [225280 2009-12-22] () S4 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation) S2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.) S3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2009-09-29] (Trend Micro Inc.) S3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2009-09-29] (Trend Micro Inc.) S2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-11-16] (Vodafone) S2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-03] (Microsoft Corporation) S2 DatamngrCoordinator; C:\Program Files (x86)\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe [x] ==================== Drivers (Whitelisted) ==================== S2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] () S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-29] (AVAST Software) S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software) S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-29] (AVAST Software) S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-29] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-29] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-29] (AVAST Software) S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-29] (AVAST Software) S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-29] (AVAST Software) S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-29] () S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [250368 2010-04-07] (Huawei Technologies Co., Ltd.) S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [92032 2007-05-31] (Huawei Technologies Co., Ltd.) S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 OXSDIDRV_x64; C:\Windows\System32\DRIVERS\OXSDIDRV_x64.sys [51760 2009-09-28] () S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X64.sys [31280 2010-05-24] () S3 SiS6350; C:\Windows\System32\DRIVERS\SISGRKMD.sys [558080 2009-11-12] (Silicon Integrated Systems Corporation) S0 SISAGP; C:\Windows\System32\DRIVERS\SISAGPX.sys [67104 2009-08-01] (Silicon Integrated Systems Corporation) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-08-12] () S2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.) S1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2009-09-29] (Trend Micro Inc.) S2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.) S2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.) S3 tmlwf; S3 tmwfp; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-25 10:53 - 2013-10-25 10:53 - 00000000 ____D C:\Windows\System32\config\HiveBackup 2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST 2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP 2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log 2013-10-08 16:39 - 2013-10-12 05:46 - 00000280 _____ C:\Windows\setupact.log 2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log 2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini 2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg 2013-10-06 11:13 - 2013-10-06 11:18 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-06 11:07 - 2013-10-06 11:27 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator 2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys 2013-10-06 11:06 - 2013-10-06 11:09 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe 2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2013-10-06 11:01 - 2013-10-12 11:40 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe ==================== One Month Modified Files and Folders ======= 2013-10-25 10:53 - 2013-10-25 10:53 - 00000000 ____D C:\Windows\System32\config\HiveBackup 2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST 2013-10-12 22:14 - 2013-09-24 12:47 - 00000000 ____D C:\ProgramData\Datamngr 2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 22:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration 2013-10-12 22:12 - 2011-09-26 17:43 - 00000000 ____D C:\users\asus 2013-10-12 22:12 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP 2013-10-12 12:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\tracing 2013-10-12 11:57 - 2013-08-08 18:02 - 00000000 ____D C:\Windows\System32\MRT 2013-10-12 11:46 - 2013-06-25 08:03 - 01240442 _____ C:\Windows\WindowsUpdate.log 2013-10-12 11:40 - 2013-10-06 11:01 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl 2013-10-12 11:38 - 2013-05-24 04:24 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-12 11:15 - 2011-10-02 15:28 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-12 06:57 - 2011-10-02 15:28 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-12 05:46 - 2013-10-08 16:39 - 00000280 _____ C:\Windows\setupact.log 2013-10-12 05:46 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-10 03:10 - 2009-07-13 21:13 - 00726444 _____ C:\Windows\System32\PerfStringBackup.INI 2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log 2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log 2013-10-08 15:13 - 2013-09-25 16:33 - 00027648 ___SH C:\Users\asus\Downloads\Thumbs.db 2013-10-08 05:25 - 2011-10-04 14:37 - 00002145 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-06 11:27 - 2013-10-06 11:07 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator 2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini 2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg 2013-10-06 11:21 - 2012-10-11 06:51 - 00000000 ____D C:\Windows\Minidump 2013-10-06 11:18 - 2013-10-06 11:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-06 11:09 - 2013-10-06 11:06 - 37672592 _____ (Safer-Networking Ltd. ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe 2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys 2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe 2013-10-06 08:37 - 2012-10-23 06:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-06 01:17 - 2012-10-23 06:50 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-03 16:20 - 2011-09-30 04:12 - 00000000 ____D C:\Users\asus\AppData\Roaming\Microgaming 2013-10-02 12:13 - 2009-07-28 22:03 - 00000000 ____D C:\Windows\Panther 2013-10-02 12:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF 2013-10-01 15:09 - 2011-10-02 15:28 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-01 15:09 - 2011-10-02 15:28 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore ZeroAccess: C:\$Recycle.Bin\S-1-5-21-1013183496-1763523383-1214035250-1000\$53710660ac42bd14fc9048f6c21d0c4f ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$53710660ac42bd14fc9048f6c21d0c4f ==================== Known DLLs (Whitelisted) ================ C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION! C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION! ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 23% Total physical RAM: 1919.34 MB Available physical RAM: 1459.75 MB Total Pagefile: 1919.34 MB Available Pagefile: 1446.23 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:58.22 GB) (Free:14.3 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:158.06 GB) (Free:157.74 GB) NTFS Drive f: (INTENSO USB) (Removable) (Total:14.53 GB) (Free:14.53 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 1674CEE9) Partition 1: (Not Active) - (Size=17 GB) - (Type=1C) Partition 2: (Active) - (Size=58 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=158 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 15 GB) (Disk ID: C7B3A61F) Partition 1: (Active) - (Size=15 GB) - (Type=0C) LastRegBack: 2013-08-20 15:42 ==================== End Of Log ============================ |
30.10.2013, 14:42 | #8 |
/// the machine /// TB-Ausbilder | Laptop bootet nicht mehr Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll [97280 2009-07-13] () AppInit_DLLs-x32: C:\PROGRA~3\Wincert\WIN32C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\mgrldr.dll [ ] () HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\apcrtldr.dll <===== ATTENTION HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\apcrtldr.dll <===== ATTENTION HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1022904 2010-02-23] (Trend Micro Inc.) S2 DatamngrCoordinator; C:\Program Files (x86)\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe [x] 2013-10-12 22:14 - 2013-09-24 12:47 - 00000000 ____D C:\ProgramData\Datamngr ZeroAccess: C:\$Recycle.Bin\S-1-5-21-1013183496-1763523383-1214035250-1000\$53710660ac42bd14fc9048f6c21d0c4f ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$53710660ac42bd14fc9048f6c21d0c4f
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Dann nochmal FRST öffnen, in das Suchfeld LPK.dll eintippen und Search klicken.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Laptop bootet nicht mehr |
.dll, adobe, adobe flash player, antivirus, association, asus, avast, bandoo, bildschirm, booten, desktop, dllhost.exe, explorer, farbar, farbar recovery scan tool, flash player, google, home, installation, internet, logfile, microsoft, msiexec.exe, registry, scan, security, services.exe, software, spyware, svchost.exe, winlogon.exe, wsearch |