|
Log-Analyse und Auswertung: Win 7 Browser-Absturz und BluescreenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.07.2015, 21:05 | #1 |
| Win 7 Browser-Absturz und Bluescreen Hallo, wir haben mit unserem PC folgendes Problem: Nach Start des Firefox und IE Browsers kommt es regelmäßig zum Absturz des Programms nach ein paar Minuten gefolgt von einem Bluescreen. Das Virenschutzprogram Kaspersky hängt sich auf. Versuche mit Winzip Malware Protector, Driver Reviver und ReImage waren erfolglos, weil der Browser jedesmal abgestürzt ist. Bluescreen.txt: ================================================== Dump File : 063015-26328-01.dmp Crash Time : 30.06.2015 18:40:26 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00041284 Parameter 2 : 00000000`0b7c9001 Parameter 3 : 00000000`0000a508 Parameter 4 : fffff700`01080000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+748c0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\063015-26328-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 299.704 Dump File Time : 30.06.2015 18:49:07 ================================================== ================================================== Dump File : 063015-29671-01.dmp Crash Time : 30.06.2015 17:15:10 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff880`0409ceda Parameter 3 : fffff880`06916ac0 Parameter 4 : 00000000`00000000 Caused By Driver : klif.sys Caused By Address : klif.sys+87eda File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\063015-29671-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 296.056 Dump File Time : 30.06.2015 17:16:44 ================================================== ================================================== Dump File : 063015-25890-01.dmp Crash Time : 30.06.2015 17:01:07 Bug Check String : KMODE_EXCEPTION_NOT_HANDLED Bug Check Code : 0x0000001e Parameter 1 : ffffffff`c0000005 Parameter 2 : fffff880`03363984 Parameter 3 : 00000000`00000000 Parameter 4 : ffffffff`ffffffff Caused By Driver : klif.sys Caused By Address : klif.sys+8b984 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\063015-25890-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 296.216 Dump File Time : 30.06.2015 17:02:42 ================================================== ================================================== Dump File : 062215-30953-01.dmp Crash Time : 22.06.2015 18:11:41 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff880`04092eda Parameter 3 : fffff880`033a0ac0 Parameter 4 : 00000000`00000000 Caused By Driver : klif.sys Caused By Address : klif.sys+87eda File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\062215-30953-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 295.176 Dump File Time : 22.06.2015 18:41:10 ================================================== ================================================== Dump File : 061615-27718-01.dmp Crash Time : 16.06.2015 19:13:45 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : ffffdd00`0ad93540 Parameter 2 : 00000000`00000000 Parameter 3 : fffff880`0469cefa Parameter 4 : 00000000`00000007 Caused By Driver : dxgmms1.sys Caused By Address : dxgmms1.sys+3ab1c File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\061615-27718-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 295.560 Dump File Time : 16.06.2015 19:31:26 ================================================== ================================================== Dump File : 061215-32859-01.dmp Crash Time : 12.06.2015 15:18:01 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00041287 Parameter 2 : 00000000`00000000 Parameter 3 : 00000000`00000000 Parameter 4 : 00000000`00000000 Caused By Driver : nvlddmkm.sys Caused By Address : nvlddmkm.sys+12a5b0 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\061215-32859-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 295.200 Dump File Time : 12.06.2015 15:19:23 ================================================== ================================================== Dump File : 061015-22625-01.dmp Crash Time : 10.06.2015 19:19:19 Bug Check String : KMODE_EXCEPTION_NOT_HANDLED Bug Check Code : 0x0000001e Parameter 1 : ffffffff`c0000096 Parameter 2 : fffff800`02888a59 Parameter 3 : 00000000`00000000 Parameter 4 : 00000000`00000000 Caused By Driver : fltmgr.sys Caused By Address : fltmgr.sys+13a00 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\061015-22625-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 297.872 Dump File Time : 10.06.2015 20:19:50 ================================================== ================================================== Dump File : 060515-28375-01.dmp Crash Time : 05.06.2015 12:45:40 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00041790 Parameter 2 : fffffa80`00812760 Parameter 3 : 00000000`00000201 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+748c0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\060515-28375-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 298.216 Dump File Time : 05.06.2015 12:47:17 ================================================== ================================================== Dump File : 053115-31765-01.dmp Crash Time : 31.05.2015 16:34:33 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00005003 Parameter 2 : fffff700`01080000 Parameter 3 : 00000000`0000354f Parameter 4 : 0001a64c`0000689e Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+748c0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\053115-31765-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 297.848 Dump File Time : 31.05.2015 16:36:07 ================================================== ================================================== Dump File : 052115-31000-01.dmp Crash Time : 21.05.2015 21:12:17 Bug Check String : DRIVER_VERIFIER_DETECTED_VIOLATION Bug Check Code : 0x000000c4 Parameter 1 : 00000000`00000091 Parameter 2 : 00000000`00000000 Parameter 3 : fffffa80`0238e3b0 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+748c0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+748c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\052115-31000-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 299.384 Dump File Time : 21.05.2015 21:14:05 ================================================== ================================================== Dump File : 051815-43609-01.dmp Crash Time : 18.05.2015 20:56:13 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff880`0413aeda Parameter 3 : fffff880`06a249d0 Parameter 4 : 00000000`00000000 Caused By Driver : klif.sys Caused By Address : klif.sys+87eda File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+72a40 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\051815-43609-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 295.176 Dump File Time : 18.05.2015 20:59:49 ================================================== ================================================== Dump File : 051015-40562-01.dmp Crash Time : 10.05.2015 10:45:50 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00005003 Parameter 2 : fffff700`01080000 Parameter 3 : 00000000`00000b3f Parameter 4 : 00000b41`0000027e Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+72a40 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+72a40 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\051015-40562-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 296.776 Dump File Time : 10.05.2015 10:47:27 ================================================== ================================================== Dump File : 050915-22781-01.dmp Crash Time : 09.05.2015 18:04:16 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : ffffe480`100427a0 Parameter 2 : 00000000`00000001 Parameter 3 : fffff880`03327cca Parameter 4 : 00000000`00000007 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+72a40 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+72a40 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\050915-22781-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 307.176 Dump File Time : 09.05.2015 18:10:03 ================================================== ================================================== Dump File : 042115-37312-01.dmp Crash Time : 21.04.2015 12:26:32 Bug Check String : UNEXPECTED_KERNEL_MODE_TRAP Bug Check Code : 0x0000007f Parameter 1 : 00000000`00000008 Parameter 2 : 00000000`80050031 Parameter 3 : 00000000`000006f8 Parameter 4 : fffff880`04157fb1 Caused By Driver : klif.sys Caused By Address : klif.sys+91fb1 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+72a40 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\042115-37312-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.248 Dump File Time : 21.04.2015 12:28:17 ================================================== ================================================== Dump File : 041815-36656-01.dmp Crash Time : 18.04.2015 19:38:20 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00005003 Parameter 2 : fffff700`01080000 Parameter 3 : 00000000`0000f30f Parameter 4 : 0000f30d`0001d41e Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+74ec0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+74ec0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\041815-36656-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 293.816 Dump File Time : 18.04.2015 19:40:03 ================================================== ================================================== Dump File : 041815-37687-01.dmp Crash Time : 18.04.2015 19:29:43 Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED Bug Check Code : 0x1000007e Parameter 1 : ffffffff`c0000005 Parameter 2 : fffff880`04639e95 Parameter 3 : fffff880`03dd57a8 Parameter 4 : fffff880`03dd5000 Caused By Driver : dxgmms1.sys Caused By Address : dxgmms1.sys+3abee File Description : Product Name : Company : File Version : Processor : x64 Crash Address : dxgmms1.sys+39e95 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\041815-37687-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.312 Dump File Time : 18.04.2015 19:31:35 ================================================== ================================================== Dump File : 040615-32562-01.dmp Crash Time : 06.04.2015 17:22:36 Bug Check String : NTFS_FILE_SYSTEM Bug Check Code : 0x00000024 Parameter 1 : 00000000`001904fb Parameter 2 : fffff880`02d76c28 Parameter 3 : fffff880`02d76480 Parameter 4 : fffff880`0183d22c Caused By Driver : Ntfs.sys Caused By Address : Ntfs.sys+f22c File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+74ec0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\040615-32562-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.264 Dump File Time : 06.04.2015 17:23:52 ================================================== ================================================== Dump File : 040315-32875-01.dmp Crash Time : 03.04.2015 12:07:38 Bug Check String : KMODE_EXCEPTION_NOT_HANDLED Bug Check Code : 0x0000001e Parameter 1 : ffffffff`c000001d Parameter 2 : fffff880`047e0c9a Parameter 3 : 00000000`00000000 Parameter 4 : ffffffff`ffffff00 Caused By Driver : dxgmms1.sys Caused By Address : dxgmms1.sys+39c9a File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+74ec0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\040315-32875-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 307.424 Dump File Time : 03.04.2015 12:09:14 ================================================== ================================================== Dump File : 032915-29968-01.dmp Crash Time : 29.03.2015 17:40:50 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff800`02bbba00 Parameter 3 : fffff880`06380a10 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+74ec0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+74ec0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\032915-29968-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.288 Dump File Time : 29.03.2015 17:42:37 ================================================== ================================================== Dump File : 032915-33328-01.dmp Crash Time : 29.03.2015 17:28:20 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : fffff880`03e7c78e Parameter 2 : 00000000`00000008 Parameter 3 : fffff880`03e7c78e Parameter 4 : 00000000`00000000 Caused By Driver : klflt.sys Caused By Address : klflt.sys+a8fb File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+74ec0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\032915-33328-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 302.952 Dump File Time : 29.03.2015 17:29:54 ================================================== ================================================== Dump File : 021815-30093-01.dmp Crash Time : 18.02.2015 20:57:41 Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 00000000`00000003 Parameter 2 : fffffa80`01837540 Parameter 3 : 00000000`09ad9a00 Parameter 4 : fffffa80`01837540 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+74ec0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+74ec0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\021815-30093-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.248 Dump File Time : 18.02.2015 20:59:17 ================================================== ================================================== Dump File : 122914-25203-01.dmp Crash Time : 29.12.2014 09:55:15 Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED Bug Check Code : 0x1000007e Parameter 1 : ffffffff`c0000005 Parameter 2 : fffff880`0492dccc Parameter 3 : fffff880`03429348 Parameter 4 : fffff880`03428ba0 Caused By Driver : dxgmms1.sys Caused By Address : dxgmms1.sys+26be7 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : dxgmms1.sys+26ccc Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\122914-25203-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 307.400 Dump File Time : 29.12.2014 09:56:33 ================================================== ================================================== Dump File : 122714-29187-01.dmp Crash Time : 27.12.2014 18:29:20 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00005003 Parameter 2 : fffff700`01080000 Parameter 3 : 00000000`0000424c Parameter 4 : 000072ae`0000b098 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\122714-29187-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 307.432 Dump File Time : 27.12.2014 18:30:46 ================================================== ================================================== Dump File : 122714-29750-01.dmp Crash Time : 27.12.2014 18:18:44 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : ffffe480`10a7d0d0 Parameter 2 : 00000000`00000001 Parameter 3 : fffff880`040e8cca Parameter 4 : 00000000`00000007 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\122714-29750-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 307.392 Dump File Time : 27.12.2014 18:20:07 ================================================== ================================================== Dump File : 122514-34140-01.dmp Crash Time : 25.12.2014 09:58:52 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00041284 Parameter 2 : 00000000`0354e001 Parameter 3 : 00000000`00006d4a Parameter 4 : fffff700`01080000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\122514-34140-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 299.464 Dump File Time : 25.12.2014 10:58:53 ================================================== ================================================== Dump File : 121414-36468-01.dmp Crash Time : 14.12.2014 12:17:58 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c000001d Parameter 2 : fffff880`045d32ce Parameter 3 : fffff880`05e64ac0 Parameter 4 : 00000000`00000000 Caused By Driver : luafv.sys Caused By Address : luafv.sys+22ce File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\121414-36468-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 282.792 Dump File Time : 14.12.2014 12:19:34 ================================================== ================================================== Dump File : 110914-30234-01.dmp Crash Time : 09.11.2014 16:35:39 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : fffff800`00001000 Parameter 2 : 00000000`00000001 Parameter 3 : fffff880`01918f64 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\110914-30234-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 290.864 Dump File Time : 09.11.2014 16:37:09 ================================================== ================================================== Dump File : 101514-32687-01.dmp Crash Time : 15.10.2014 17:18:44 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : ffffffff`ffffffff Parameter 2 : 00000000`00000008 Parameter 3 : ffffffff`ffffffff Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\101514-32687-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.248 Dump File Time : 15.10.2014 17:40:31 ================================================== ================================================== Dump File : 100714-29453-01.dmp Crash Time : 07.10.2014 12:33:55 Bug Check String : NTFS_FILE_SYSTEM Bug Check Code : 0x00000024 Parameter 1 : 00000000`001904fb Parameter 2 : fffff880`07e5d948 Parameter 3 : fffff880`07e5d1a0 Parameter 4 : fffff880`0181322c Caused By Driver : Ntfs.sys Caused By Address : Ntfs.sys+f22c File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\100714-29453-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 343.840 Dump File Time : 07.10.2014 12:35:16 ================================================== ================================================== Dump File : 100714-29500-01.dmp Crash Time : 07.10.2014 12:11:17 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff800`028d1cc4 Parameter 3 : fffff880`06225900 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\100714-29500-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.184 Dump File Time : 07.10.2014 12:12:43 ================================================== ================================================== Dump File : 100714-30500-01.dmp Crash Time : 07.10.2014 12:01:22 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c000001d Parameter 2 : fffff880`04132ed8 Parameter 3 : fffff880`0681d990 Parameter 4 : 00000000`00000000 Caused By Driver : klif.sys Caused By Address : klif.sys+69ed8 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\100714-30500-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 303.320 Dump File Time : 07.10.2014 12:04:30 ================================================== ================================================== Dump File : 100614-36062-01.dmp Crash Time : 06.10.2014 12:27:45 Bug Check String : PFN_LIST_CORRUPT Bug Check Code : 0x0000004e Parameter 1 : 00000000`00000099 Parameter 2 : 00000000`00000000 Parameter 3 : 00000000`00000000 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\100614-36062-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 293.720 Dump File Time : 06.10.2014 12:29:42 ================================================== ================================================== Dump File : 080114-30390-01.dmp Crash Time : 01.08.2014 17:03:58 Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED Bug Check Code : 0x1000007e Parameter 1 : ffffffff`c0000005 Parameter 2 : fffff880`03e20ed8 Parameter 3 : fffff880`037a76a8 Parameter 4 : fffff880`037a6f00 Caused By Driver : dxgmms1.sys Caused By Address : dxgmms1.sys+1dfa5 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : dxgmms1.sys+20ed8 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\080114-30390-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 282.792 Dump File Time : 01.08.2014 17:05:41 ================================================== ================================================== Dump File : 061314-55437-01.dmp Crash Time : 13.06.2014 18:27:06 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff800`02887e94 Parameter 3 : fffff880`05b36c20 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\061314-55437-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 281.360 Dump File Time : 13.06.2014 18:36:22 ================================================== ================================================== Dump File : 050714-32531-01.dmp Crash Time : 07.05.2014 18:59:22 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00041284 Parameter 2 : 00000000`1b30c001 Parameter 3 : 00000000`00012544 Parameter 4 : fffff700`01080000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\050714-32531-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 283.392 Dump File Time : 07.05.2014 19:00:49 ================================================== ================================================== Dump File : 050314-32562-01.dmp Crash Time : 03.05.2014 12:32:09 Bug Check String : SYSTEM_SERVICE_EXCEPTION Bug Check Code : 0x0000003b Parameter 1 : 00000000`c0000005 Parameter 2 : fffff960`001ac31e Parameter 3 : fffff880`060c2ee0 Parameter 4 : 00000000`00000000 Caused By Driver : win32k.sys Caused By Address : win32k.sys+cc31e File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\050314-32562-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 282.952 Dump File Time : 03.05.2014 12:34:00 ================================================== ================================================== Dump File : 042614-28656-01.dmp Crash Time : 26.04.2014 16:47:45 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : fffffa80`4b5fe474 Parameter 2 : 00000000`00000001 Parameter 3 : fffff880`03d4be69 Parameter 4 : 00000000`00000005 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\042614-28656-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 284.552 Dump File Time : 26.04.2014 16:49:36 ================================================== ================================================== Dump File : 042014-43031-01.dmp Crash Time : 20.04.2014 20:40:50 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00005003 Parameter 2 : fffff700`01080000 Parameter 3 : 00000000`0000293f Parameter 4 : 00002941`0000d07e Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\042014-43031-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 283.992 Dump File Time : 20.04.2014 20:42:22 ================================================== ================================================== Dump File : 042014-38468-01.dmp Crash Time : 20.04.2014 18:19:44 Bug Check String : MEMORY_MANAGEMENT Bug Check Code : 0x0000001a Parameter 1 : 00000000`00005003 Parameter 2 : fffff700`01080000 Parameter 3 : 00000000`00002747 Parameter 4 : 00002749`0000228e Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\042014-38468-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 283.192 Dump File Time : 20.04.2014 20:22:04 ================================================== ================================================== Dump File : 042014-42093-01.dmp Crash Time : 20.04.2014 17:57:53 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : fffff880`06553870 Parameter 2 : 00000000`00000001 Parameter 3 : fffff880`03f06c00 Parameter 4 : 00000000`00000001 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\042014-42093-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 290.920 Dump File Time : 20.04.2014 17:59:36 ================================================== ================================================== Dump File : 042014-92671-01.dmp Crash Time : 19.04.2014 22:31:46 Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA Bug Check Code : 0x00000050 Parameter 1 : fffff8a0`0d1a0160 Parameter 2 : 00000000`00000000 Parameter 3 : fffff800`02b5f4f4 Parameter 4 : 00000000`00000000 Caused By Driver : Wdf01000.sys Caused By Address : Wdf01000.sys+ab2b File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\042014-92671-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 281.336 Dump File Time : 20.04.2014 17:08:19 ================================================== ================================================== Dump File : 041914-33828-01.dmp Crash Time : 19.04.2014 21:54:36 Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 00000000`00000003 Parameter 2 : fffff8a0`01eccec0 Parameter 3 : fffff8a0`01eccec0 Parameter 4 : 00000000`00000000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\041914-33828-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 281.360 Dump File Time : 19.04.2014 22:05:17 ================================================== ================================================== Dump File : 041914-40906-01.dmp Crash Time : 19.04.2014 18:27:52 Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 00000000`00000003 Parameter 2 : fffffa80`018367c0 Parameter 3 : 67cf5ce0`5e802517 Parameter 4 : fffffa80`018367c0 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+75bc0 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.1.7601.18869 (win7sp1_gdr.150525-0603) Processor : x64 Crash Address : ntoskrnl.exe+75bc0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\041914-40906-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 281.360 Dump File Time : 19.04.2014 18:30:06 ================================================== Herzliche Grüße |
04.07.2015, 07:26 | #2 |
/// the machine /// TB-Ausbilder | Win 7 Browser-Absturz und Bluescreen Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
14.07.2015, 18:09 | #3 |
| Win 7 Browser-Absturz und Bluescreen Hi,
__________________war eine Woche auf Dienstreise, daher kam ich erst heute zum Scan. Wärend des Scans kam es wieder zum Bluescreen aber es wurden txt files angelegt. *Frst.txt: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015 Ran by Muckl (administrator) on MUCKL-PC on 14-07-2015 18:49:32 Running from C:\Users\Muckl\Desktop\Reparatur Loaded Profiles: Muckl (Available Profiles: Muckl) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe (Nico Mak Computing) C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWXConfigManager.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-660126614-4194368626-223086476-1001\Software\Microsoft\Internet Explorer\Main,Start Page = Dell Official Site - The Power To Do More | Dell HKU\S-1-5-21-660126614-4194368626-223086476-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell Official Site - The Power To Do More | Dell BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-25] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-25] (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{8D560065-A93F-4412-8D8A-845E3D0F0415}: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Muckl\AppData\Roaming\Mozilla\Firefox\Profiles\32zh6dju.default-1435249966264 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-06-25] () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-25] () FF Plugin-x32: @kaspersky.com/content_blocker -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-12-25] () FF Plugin-x32: @kaspersky.com/online_banking -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-12-25] () FF Plugin-x32: @kaspersky.com/virtual_keyboard -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-12-25] () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF user.js: detected! => C:\Users\Muckl\AppData\Roaming\Mozilla\Firefox\Profiles\32zh6dju.default-1435249966264\user.js [2015-06-25] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-12-25] Chrome: ======= CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO) R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7414256 2015-05-19] (Reimage®) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC64.SYS [3491616 2009-06-18] (Realtek Semiconductor Corp.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [457824 2014-02-20] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [141320 2014-12-25] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [243808 2014-04-10] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [793800 2014-12-25] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2014-03-25] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179296 2014-03-26] (Kaspersky Lab ZAO) S3 cpuz134; \??\C:\Users\Muckl\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 18:46 - 2015-07-14 18:50 - 00000000 ____D C:\FRST 2015-07-13 20:00 - 2015-07-13 20:00 - 00000464 _____ C:\Windows\system32\ScannerSettings 2015-07-05 12:59 - 2015-07-14 18:09 - 00003116 _____ C:\Windows\System32\Tasks\WinZip Malware Protector_startup 2015-07-05 12:54 - 2015-07-05 12:54 - 00262144 _____ C:\Windows\Minidump\070515-30500-01.dmp 2015-07-01 18:09 - 2015-07-01 18:09 - 00003434 _____ C:\Windows\System32\Tasks\Reimage Reminder 2015-07-01 18:08 - 2015-07-01 18:08 - 00004274 _____ C:\Windows\System32\Tasks\ReimageUpdater 2015-07-01 18:08 - 2015-07-01 18:08 - 00001901 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk 2015-07-01 18:08 - 2015-07-01 18:08 - 00000000 ____D C:\ProgramData\Reimage Protector 2015-07-01 18:08 - 2015-07-01 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2015-07-01 18:08 - 2015-07-01 18:08 - 00000000 ____D C:\Program Files\Reimage 2015-07-01 18:07 - 2015-07-01 18:09 - 00000165 _____ C:\Windows\Reimage.ini 2015-07-01 18:07 - 2015-07-01 18:09 - 00000000 ____D C:\rei 2015-07-01 18:06 - 2015-07-01 18:06 - 00772016 _____ (Reimage®) C:\Users\Muckl\Downloads\ReimageRepair.exe 2015-07-01 17:38 - 2015-07-01 17:38 - 00000000 ____D C:\Users\Muckl\AppData\Roaming\Nico Mak Computing 2015-07-01 17:26 - 2015-07-01 17:38 - 00001189 _____ C:\Users\Public\Desktop\WinZip Malware Protector.lnk 2015-07-01 17:26 - 2015-07-01 17:38 - 00000000 ____D C:\ProgramData\Nico Mak Computing 2015-07-01 17:26 - 2015-07-01 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector 2015-07-01 17:25 - 2015-07-01 17:38 - 00000000 ____D C:\Program Files (x86)\WinZip Malware Protector 2015-07-01 17:25 - 2013-03-15 17:10 - 00020480 _____ C:\Windows\system32\wsusnative64.exe 2015-07-01 17:19 - 2015-07-14 18:49 - 00000000 ____D C:\Users\Muckl\Desktop\Reparatur 2015-06-30 18:48 - 2015-06-30 18:49 - 00299704 _____ C:\Windows\Minidump\063015-26328-01.dmp 2015-06-30 17:16 - 2015-06-30 17:16 - 00296056 _____ C:\Windows\Minidump\063015-29671-01.dmp 2015-06-30 17:02 - 2015-06-30 17:02 - 00296216 _____ C:\Windows\Minidump\063015-25890-01.dmp 2015-06-25 18:34 - 2015-06-25 18:34 - 00000000 ____D C:\Users\Muckl\Desktop\Alte Firefox-Daten 2015-06-25 18:15 - 2015-06-25 18:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-06-25 18:14 - 2015-07-14 18:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-25 18:08 - 2015-06-25 18:15 - 00000000 ____D C:\Users\Muckl\AppData\Local\Adobe 2015-06-22 18:41 - 2015-06-22 18:41 - 00295176 _____ C:\Windows\Minidump\062215-30953-01.dmp 2015-06-16 19:31 - 2015-06-16 19:31 - 00295560 _____ C:\Windows\Minidump\061615-27718-01.dmp ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 18:53 - 2014-04-18 10:02 - 01411022 _____ C:\Windows\WindowsUpdate.log 2015-07-14 18:37 - 2009-07-14 06:45 - 00035088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-14 18:37 - 2009-07-14 06:45 - 00035088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-14 18:24 - 2014-12-25 09:21 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-14 18:08 - 2014-04-21 16:06 - 00010367 _____ C:\Windows\system32\lvcoinst.log 2015-07-14 18:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-14 18:06 - 2009-07-14 06:51 - 00039848 _____ C:\Windows\setupact.log 2015-07-05 22:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2015-07-05 12:54 - 2014-04-19 18:30 - 00000000 ____D C:\Windows\Minidump 2015-07-05 12:54 - 2014-04-18 17:17 - 230662995 _____ C:\Windows\MEMORY.DMP 2015-07-05 12:54 - 2014-04-18 10:23 - 00000000 ____D C:\Users\Muckl 2015-07-05 11:15 - 2014-04-20 20:45 - 00000000 ____D C:\Users\Muckl\Desktop\10052015Muckl eigene dateien gesamt 2015-07-01 17:11 - 2014-12-14 09:57 - 00000000 __SHD C:\Users\Muckl\AppData\Local\EmieBrowserModeList 2015-07-01 17:11 - 2014-08-16 21:43 - 00000000 __SHD C:\Users\Muckl\AppData\Local\EmieUserList 2015-07-01 17:11 - 2014-08-16 21:43 - 00000000 __SHD C:\Users\Muckl\AppData\Local\EmieSiteList 2015-07-01 16:55 - 2014-04-18 19:55 - 00727080 _____ C:\Windows\system32\perfh007.dat 2015-07-01 16:55 - 2014-04-18 19:55 - 00159084 _____ C:\Windows\system32\perfc007.dat 2015-07-01 16:55 - 2009-07-14 07:13 - 01682674 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-25 18:27 - 2014-04-18 10:42 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-06-25 18:27 - 2014-04-18 10:42 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-22 15:51 - 2014-12-14 11:19 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-22 15:51 - 2014-05-02 18:16 - 00000000 ___SD C:\Windows\system32\CompatTel ==================== Files in the root of some directories ======= 2014-10-07 11:55 - 2014-10-07 11:55 - 0000017 _____ () C:\Users\Muckl\AppData\Local\resmon.resmoncfg Some files in TEMP: ==================== C:\Users\Muckl\AppData\Local\Temp\avgnt.exe C:\Users\Muckl\AppData\Local\Temp\ose00000.exe C:\Users\Muckl\AppData\Local\Temp\ReimagePackage.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed Addition.txt: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015 Ran by Muckl (administrator) on MUCKL-PC on 14-07-2015 18:49:32 Running from C:\Users\Muckl\Desktop\Reparatur Loaded Profiles: Muckl (Available Profiles: Muckl) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe (Nico Mak Computing) C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWXConfigManager.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-660126614-4194368626-223086476-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com HKU\S-1-5-21-660126614-4194368626-223086476-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-25] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-25] (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{8D560065-A93F-4412-8D8A-845E3D0F0415}: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Muckl\AppData\Roaming\Mozilla\Firefox\Profiles\32zh6dju.default-1435249966264 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-06-25] () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-25] () FF Plugin-x32: @kaspersky.com/content_blocker -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-12-25] () FF Plugin-x32: @kaspersky.com/online_banking -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-12-25] () FF Plugin-x32: @kaspersky.com/virtual_keyboard -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-12-25] () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF user.js: detected! => C:\Users\Muckl\AppData\Roaming\Mozilla\Firefox\Profiles\32zh6dju.default-1435249966264\user.js [2015-06-25] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com [2014-12-25] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-12-25] Chrome: ======= CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO) R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7414256 2015-05-19] (Reimage®) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC64.SYS [3491616 2009-06-18] (Realtek Semiconductor Corp.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [457824 2014-02-20] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [141320 2014-12-25] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [243808 2014-04-10] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [793800 2014-12-25] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2014-03-25] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179296 2014-03-26] (Kaspersky Lab ZAO) S3 cpuz134; \??\C:\Users\Muckl\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 18:46 - 2015-07-14 18:50 - 00000000 ____D C:\FRST 2015-07-13 20:00 - 2015-07-13 20:00 - 00000464 _____ C:\Windows\system32\ScannerSettings 2015-07-05 12:59 - 2015-07-14 18:09 - 00003116 _____ C:\Windows\System32\Tasks\WinZip Malware Protector_startup 2015-07-05 12:54 - 2015-07-05 12:54 - 00262144 _____ C:\Windows\Minidump\070515-30500-01.dmp 2015-07-01 18:09 - 2015-07-01 18:09 - 00003434 _____ C:\Windows\System32\Tasks\Reimage Reminder 2015-07-01 18:08 - 2015-07-01 18:08 - 00004274 _____ C:\Windows\System32\Tasks\ReimageUpdater 2015-07-01 18:08 - 2015-07-01 18:08 - 00001901 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk 2015-07-01 18:08 - 2015-07-01 18:08 - 00000000 ____D C:\ProgramData\Reimage Protector 2015-07-01 18:08 - 2015-07-01 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2015-07-01 18:08 - 2015-07-01 18:08 - 00000000 ____D C:\Program Files\Reimage 2015-07-01 18:07 - 2015-07-01 18:09 - 00000165 _____ C:\Windows\Reimage.ini 2015-07-01 18:07 - 2015-07-01 18:09 - 00000000 ____D C:\rei 2015-07-01 18:06 - 2015-07-01 18:06 - 00772016 _____ (Reimage®) C:\Users\Muckl\Downloads\ReimageRepair.exe 2015-07-01 17:38 - 2015-07-01 17:38 - 00000000 ____D C:\Users\Muckl\AppData\Roaming\Nico Mak Computing 2015-07-01 17:26 - 2015-07-01 17:38 - 00001189 _____ C:\Users\Public\Desktop\WinZip Malware Protector.lnk 2015-07-01 17:26 - 2015-07-01 17:38 - 00000000 ____D C:\ProgramData\Nico Mak Computing 2015-07-01 17:26 - 2015-07-01 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector 2015-07-01 17:25 - 2015-07-01 17:38 - 00000000 ____D C:\Program Files (x86)\WinZip Malware Protector 2015-07-01 17:25 - 2013-03-15 17:10 - 00020480 _____ C:\Windows\system32\wsusnative64.exe 2015-07-01 17:19 - 2015-07-14 18:49 - 00000000 ____D C:\Users\Muckl\Desktop\Reparatur 2015-06-30 18:48 - 2015-06-30 18:49 - 00299704 _____ C:\Windows\Minidump\063015-26328-01.dmp 2015-06-30 17:16 - 2015-06-30 17:16 - 00296056 _____ C:\Windows\Minidump\063015-29671-01.dmp 2015-06-30 17:02 - 2015-06-30 17:02 - 00296216 _____ C:\Windows\Minidump\063015-25890-01.dmp 2015-06-25 18:34 - 2015-06-25 18:34 - 00000000 ____D C:\Users\Muckl\Desktop\Alte Firefox-Daten 2015-06-25 18:15 - 2015-06-25 18:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-06-25 18:14 - 2015-07-14 18:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-25 18:08 - 2015-06-25 18:15 - 00000000 ____D C:\Users\Muckl\AppData\Local\Adobe 2015-06-22 18:41 - 2015-06-22 18:41 - 00295176 _____ C:\Windows\Minidump\062215-30953-01.dmp 2015-06-16 19:31 - 2015-06-16 19:31 - 00295560 _____ C:\Windows\Minidump\061615-27718-01.dmp ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 18:53 - 2014-04-18 10:02 - 01411022 _____ C:\Windows\WindowsUpdate.log 2015-07-14 18:37 - 2009-07-14 06:45 - 00035088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-14 18:37 - 2009-07-14 06:45 - 00035088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-14 18:24 - 2014-12-25 09:21 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-14 18:08 - 2014-04-21 16:06 - 00010367 _____ C:\Windows\system32\lvcoinst.log 2015-07-14 18:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-14 18:06 - 2009-07-14 06:51 - 00039848 _____ C:\Windows\setupact.log 2015-07-05 22:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2015-07-05 12:54 - 2014-04-19 18:30 - 00000000 ____D C:\Windows\Minidump 2015-07-05 12:54 - 2014-04-18 17:17 - 230662995 _____ C:\Windows\MEMORY.DMP 2015-07-05 12:54 - 2014-04-18 10:23 - 00000000 ____D C:\Users\Muckl 2015-07-05 11:15 - 2014-04-20 20:45 - 00000000 ____D C:\Users\Muckl\Desktop\10052015Muckl eigene dateien gesamt 2015-07-01 17:11 - 2014-12-14 09:57 - 00000000 __SHD C:\Users\Muckl\AppData\Local\EmieBrowserModeList 2015-07-01 17:11 - 2014-08-16 21:43 - 00000000 __SHD C:\Users\Muckl\AppData\Local\EmieUserList 2015-07-01 17:11 - 2014-08-16 21:43 - 00000000 __SHD C:\Users\Muckl\AppData\Local\EmieSiteList 2015-07-01 16:55 - 2014-04-18 19:55 - 00727080 _____ C:\Windows\system32\perfh007.dat 2015-07-01 16:55 - 2014-04-18 19:55 - 00159084 _____ C:\Windows\system32\perfc007.dat 2015-07-01 16:55 - 2009-07-14 07:13 - 01682674 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-25 18:27 - 2014-04-18 10:42 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-06-25 18:27 - 2014-04-18 10:42 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-22 15:51 - 2014-12-14 11:19 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-22 15:51 - 2014-05-02 18:16 - 00000000 ___SD C:\Windows\system32\CompatTel ==================== Files in the root of some directories ======= 2014-10-07 11:55 - 2014-10-07 11:55 - 0000017 _____ () C:\Users\Muckl\AppData\Local\resmon.resmoncfg Some files in TEMP: ==================== C:\Users\Muckl\AppData\Local\Temp\avgnt.exe C:\Users\Muckl\AppData\Local\Temp\ose00000.exe C:\Users\Muckl\AppData\Local\Temp\ReimagePackage.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed |
15.07.2015, 09:47 | #4 |
/// the machine /// TB-Ausbilder | Win 7 Browser-Absturz und Bluescreen Du hast zweimal die FRST.txt gepostet, Addition.txt fehlt noch . Und logs bitte immer in Codetags posten. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |