Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windows 7 startet nicht mehr (https://www.trojaner-board.de/149133-windows-7-startet-mehr.html)

DanielZ87 03.02.2014 09:13

Windows 7 startet nicht mehr
 
Guten Tag,

mein Notebook startet seit kurzem nicht mehr.
Im Anhang der gewünschte Log.



FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-01-2014
 Ran by SYSTEM on MINWINPC on 31-01-2014 15:03:37
 Running from H:\
 Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
 Internet Explorer Version 9
 Boot Mode: Recovery
 
 The current controlset is ControlSet001
 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
 
 
 
 ==================== Registry (Whitelisted) ==================
 
 HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3011824 2013-01-29] (Synaptics Incorporated)
 HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [3488640 2012-03-14] (Hewlett-Packard Company)
 HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-03-05] (IDT, Inc.)
 HKLM\...\Run: [MfeEpePcMonitor] - "C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe"
 HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-03-01] (Intel Corporation)
 HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [684024 2012-03-07] (PDF Complete Inc)
 HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [319360 2012-03-14] (Hewlett-Packard Company)
 HKLM-x32\...\Run: [] - [x]
 HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-27] (Intel Corporation)
 HKLM-x32\...\Run: [HP HD Webcam Driver_Monitor] - C:\Program Files (x86)\HP HD Webcam Driver\monitor.exe [303480 2012-07-26] ()
 HKLM-x32\...\Run: [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [517456 2010-11-24] (ArcSoft Inc.)
 HKLM-x32\...\Run: [HPConnectionManager] - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184704 2012-03-16] (Hewlett-Packard Development Company, L.P.)
 HKLM-x32\...\Run: [BtTray] - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [364032 2012-08-16] (IVT Corporation)
 HKLM-x32\...\Run: [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12310616 2012-03-22] (Hewlett-Packard)
 HKLM\...\Runonce: [WinSATRestorePower] - powercfg -setactive 8759706d-706b-4c22-b2ec-f91e1ef6ed38
 HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
 Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
 Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
 HKU\Administrator.NOTEBOOK-HELD\...\Run: [DriverScanner] - C:\Program Files (x86)\Uniblue\DriverScanner\Launcher.exe [338808 2012-04-23] (Uniblue Systems Limited)
 HKU\Administrator.NOTEBOOK-HELD\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
 HKU\EDVS\...\Run: [DriverScanner] - C:\Program Files (x86)\Uniblue\DriverScanner\Launcher.exe [338808 2012-04-23] (Uniblue Systems Limited)
 HKU\EDVS\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
 HKU\Stefanie\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
 HKU\Stefanie\...\Run: [WebCake Desktop] - "C:\Users\Stefanie\AppData\Roaming\WebCake\WebCakeDesktop.exe"
 HKU\Stefanie\...\Run: [Browser Infrastructure Helper] - C:\Users\Stefanie\AppData\Local\Smartbar\Application\QuickShare.exe [20248 2013-05-09] (Smartbar)
 HKU\Stefanie\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [183800 2013-05-20] (PC Utilities Pro)
 HKU\Stefanie.NOTEBOOK-HELD\...\Run: [DriverScanner] - C:\Program Files (x86)\Uniblue\DriverScanner\Launcher.exe [338808 2012-04-23] (Uniblue Systems Limited)
 HKU\Stefanie.NOTEBOOK-HELD\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
 HKU\Stefanie.NOTEBOOK-HELD\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.exe [353440 2012-04-16] (Adobe Systems Incorporated)
 HKU\Stefanie.NOTEBOOK-HELD\...\RunOnce: [Application Restart #0] - C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe [158808 2013-07-09] (Microsoft Corporation)
 HKU\Stefanie.NOTEBOOK-HELD\...\RunOnce: [Application Restart #1] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe [12310616 2012-03-22] (Hewlett-Packard)
 HKU\Stefanie.NOTEBOOK-HELD\...\RunOnce: [Application Restart #2] - C:\Program Files\Internet Explorer\iexplore.exe [775256 2013-05-17] (Microsoft Corporation)
 Lsa: [Notification Packages] DPPassFilter scecli
 Startup: C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
 ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
 Startup: C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
 ShortcutTarget: Dropbox.lnk -> C:\Users\Default\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
 
 ==================== Services (Whitelisted) =================
 
 S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
 S2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1578496 2012-08-14] (IVT Corporation)
 S3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-08-14] (IVT Corporation)
 S2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [493904 2012-03-15] (DigitalPersona, Inc.)
 S3 FLCDLOCK; c:\windows\SysWOW64\flcdlock.exe [477056 2012-01-31] (Hewlett-Packard Company)
 S2 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-17] (Hewlett-Packard)
 S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [365440 2012-03-14] (Hewlett-Packard Company)
 S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-28] ()
 S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-28] (Intel Corporation)
 S2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1327104 2012-03-22] ()
 S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134584 2012-03-07] (PDF Complete Inc)
 S2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [498352 2012-04-05] (ArcSoft, Inc.)
 S2 BBSvc; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [x]
 S3 BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [x]
 
 ==================== Drivers (Whitelisted) ====================
 
 S3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [42816 2012-02-03] (ArcSoft, Inc.)
 S3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23104 2011-08-13] (Ralink Corporation)
 S3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [51776 2012-04-03] (Ralink Corporation)
 S3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48320 2012-03-05] (Ralink Corporation)
 S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [64312 2012-01-31] (Hewlett-Packard Company)
 S0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [93640 2012-03-22] (McAfee, Inc.)
 S0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158792 2012-03-22] (McAfee, Inc.)
 S3 rtbth; C:\Windows\System32\DRIVERS\rtbth.sys [685152 2012-06-14] (Ralink Technology, Corp.)
 S3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1062008 2012-08-02] (Sunplus)
 S5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34880 2011-08-13] (Ralink Corporation.)
 S5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [34880 2011-08-13] (Ralink Corporation.)
 
 ==================== NetSvcs (Whitelisted) ===================
 
 
 ==================== One Month Created Files and Folders ========
 
 2014-01-27 18:00 - 2014-01-27 18:00 - 02078208 _____ (Farbar) C:\FRST64.exe
 2014-01-27 16:58 - 2014-01-27 17:05 - 00000000 ____D C:\FRST
 2014-01-27 13:49 - 2014-01-27 16:16 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
 2014-01-24 18:18 - 2014-01-24 18:18 - 190626716 _____ C:\Windows\MEMORY.DMP
 2014-01-24 17:38 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\System32\IEUDINIT.EXE
 2014-01-24 17:20 - 2014-01-24 17:38 - 00016162 _____ C:\Windows\IE11_main.log
 2014-01-24 14:59 - 2014-01-24 15:00 - 00266030 _____ C:\Windows\msxml4-KB2758694-enu.LOG
 2014-01-24 14:55 - 2014-01-24 14:55 - 00000000 ____D C:\Windows\System32\MRT
 2014-01-20 18:58 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\System32\scavengeui.dll
 
 ==================== One Month Modified Files and Folders =======
 
 2014-01-27 18:00 - 2014-01-27 18:00 - 02078208 _____ (Farbar) C:\FRST64.exe
 2014-01-27 17:05 - 2014-01-27 16:58 - 00000000 ____D C:\FRST
 2014-01-27 16:58 - 2013-07-09 15:06 - 00000000 ____D C:\users\Administrator.NOTEBOOK-HELD
 2014-01-27 16:58 - 2013-06-07 10:35 - 00000000 ____D C:\users\Stefanie.NOTEBOOK-HELD
 2014-01-27 16:58 - 2013-06-06 08:31 - 00000000 ____D C:\users\Stefanie
 2014-01-27 16:58 - 2013-06-06 08:28 - 00000000 ____D C:\users\administrator
 2014-01-27 16:58 - 2013-06-05 14:00 - 00000000 ____D C:\users\EDVS
 2014-01-27 16:16 - 2014-01-27 13:49 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
 2014-01-27 12:42 - 2010-11-21 04:47 - 00065798 _____ C:\Windows\PFRO.log
 2014-01-24 18:18 - 2014-01-24 18:18 - 190626716 _____ C:\Windows\MEMORY.DMP
 2014-01-24 18:04 - 2012-04-16 04:45 - 00000000 ____D C:\Program Files\Windows Journal
 2014-01-24 18:03 - 2012-12-15 12:58 - 00004524 _____ C:\Windows\SysWOW64\LOCALSERVICE.INI
 2014-01-24 18:03 - 2012-08-16 02:46 - 00000787 _____ C:\Windows\SysWOW64\bscs.ini
 2014-01-24 18:03 - 2012-04-16 06:20 - 00000000 ____D C:\ProgramData\PDFC
 2014-01-24 18:02 - 2009-07-14 05:51 - 00072565 _____ C:\Windows\setupact.log
 2014-01-24 17:58 - 2012-12-15 12:16 - 01426249 _____ C:\Windows\WindowsUpdate.log
 2014-01-24 17:57 - 2013-06-11 17:13 - 00000000 ____D C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Roaming\Skype
 2014-01-24 17:38 - 2014-01-24 17:20 - 00016162 _____ C:\Windows\IE11_main.log
 2014-01-24 17:14 - 2012-12-15 12:58 - 00000043 _____ C:\Windows\SysWOW64\LOCALDEVICE.INI
 2014-01-24 15:20 - 2012-04-16 04:59 - 00740374 _____ C:\Windows\System32\perfh013.dat
 2014-01-24 15:20 - 2012-04-16 04:59 - 00156954 _____ C:\Windows\System32\perfc013.dat
 2014-01-24 15:20 - 2012-04-16 04:56 - 00737196 _____ C:\Windows\System32\perfh010.dat
 2014-01-24 15:20 - 2012-04-16 04:56 - 00150826 _____ C:\Windows\System32\perfc010.dat
 2014-01-24 15:20 - 2012-04-16 04:53 - 00715338 _____ C:\Windows\System32\perfh007.dat
 2014-01-24 15:20 - 2012-04-16 04:53 - 00153990 _____ C:\Windows\System32\perfc007.dat
 2014-01-24 15:20 - 2012-04-16 04:49 - 00742660 _____ C:\Windows\System32\perfh00C.dat
 2014-01-24 15:20 - 2012-04-16 04:49 - 00153330 _____ C:\Windows\System32\perfc00C.dat
 2014-01-24 15:20 - 2009-07-14 06:13 - 04370294 _____ C:\Windows\System32\PerfStringBackup.INI
 2014-01-24 15:15 - 2012-04-16 06:10 - 04254446 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
 2014-01-24 15:00 - 2014-01-24 14:59 - 00266030 _____ C:\Windows\msxml4-KB2758694-enu.LOG
 2014-01-24 14:59 - 2013-06-06 19:43 - 00000000 ____D C:\Users\Stefanie\AppData\Roaming\WebCake
 2014-01-24 14:58 - 2013-07-17 15:58 - 00000000 ____D C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Roaming\Dropbox
 2014-01-24 14:58 - 2013-07-17 15:55 - 00000000 ___RD C:\Users\Stefanie.NOTEBOOK-HELD\Desktop\Dropbox
 2014-01-24 14:56 - 2009-07-14 05:45 - 00031312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 2014-01-24 14:56 - 2009-07-14 05:45 - 00031312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 2014-01-24 14:55 - 2014-01-24 14:55 - 00000000 ____D C:\Windows\System32\MRT
 2014-01-24 14:50 - 2013-06-09 16:47 - 00028283 _____ C:\ProgramData\lxeascan.log
 2014-01-17 12:19 - 2013-06-06 08:26 - 00057748 __RSH C:\ProgramData\ntuser.pol
 2014-01-17 10:27 - 2013-07-17 16:01 - 00001030 _____ C:\Users\Stefanie.NOTEBOOK-HELD\Desktop\Dropbox.lnk
 2014-01-17 10:23 - 2013-06-06 08:24 - 00000136 _____ C:\Windows\System32\config\netlogon.ftl
 2014-01-14 21:08 - 2013-06-05 16:42 - 01249423 _____ C:\Windows\SysWOW64\sig.bin
 2014-01-14 21:08 - 2013-06-05 16:42 - 00060360 _____ C:\Windows\SysWOW64\nmp.map
 2014-01-06 16:20 - 2013-06-05 15:12 - 86054176 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
 2014-01-06 15:21 - 2013-08-04 17:46 - 00000000 ____D C:\Users\Stefanie.NOTEBOOK-HELD\Documents\My Kindle Content
 2014-01-04 10:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
 
 Files to move or delete:
 ====================
 C:\Windows\Tasks\{64389CA3-722E-4C9F-AF8F-CDEB4A911985}.job
 
 
 Some content of TEMP:
 ====================
 C:\Users\administrator\AppData\Local\Temp\ApplnchConfig.exe
 C:\Users\Administrator.NOTEBOOK-HELD\AppData\Local\Temp\OfficeSetup.exe
 C:\Users\Administrator.NOTEBOOK-HELD\AppData\Local\Temp\setup32.exe
 C:\Users\Stefanie\AppData\Local\Temp\ApplnchConfig.exe
 C:\Users\Stefanie\AppData\Local\Temp\SkypeSetup.exe
 C:\Users\Stefanie\AppData\Local\Temp\SmartbarExeInstaller.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\26040-92350-windows-media-player.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\ei5jympl.dll
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\instloffer.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\OfficeSetup.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\Setup.X86.de-DE_HomeBusinessRetail_96146be7-e6f6-4b5c-a9d3-3e6002794de2_TX_DB_ (1).exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\Setup.X86.de-DE_HomeBusinessRetail_96146be7-e6f6-4b5c-a9d3-3e6002794de2_TX_DB_.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\setup32.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\SkypeSetup.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\WajamC.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\wajam_download.exe
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\xzj3pcww.dll
 C:\Users\Stefanie.NOTEBOOK-HELD\AppData\Local\Temp\_is845E.exe
 
 
 ==================== Known DLLs (Whitelisted) ================
 
 C:\Windows\System32\advapi32.dll IS MISSING <==== ATTENTION!
 C:\Windows\SysWOW64\advapi32.dll IS MISSING <==== ATTENTION!
 C:\Windows\System32\gdi32.dll IS MISSING <==== ATTENTION!
 C:\Windows\System32\SHELL32.dll IS MISSING <==== ATTENTION!
 
 ==================== Bamital & volsnap Check =================
 
 C:\Windows\System32\winlogon.exe => MD5 is legit
 C:\Windows\System32\wininit.exe => MD5 is legit
 C:\Windows\SysWOW64\wininit.exe => MD5 is legit
 C:\Windows\explorer.exe => MD5 is legit
 C:\Windows\SysWOW64\explorer.exe => MD5 is legit
 C:\Windows\System32\svchost.exe => MD5 is legit
 C:\Windows\SysWOW64\svchost.exe => MD5 is legit
 C:\Windows\System32\services.exe => MD5 is legit
 C:\Windows\System32\User32.dll => MD5 is legit
 C:\Windows\SysWOW64\User32.dll => MD5 is legit
 C:\Windows\System32\userinit.exe => MD5 is legit
 C:\Windows\SysWOW64\userinit.exe => MD5 is legit
 C:\Windows\System32\rpcss.dll => MD5 is legit
 C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 ==================== EXE ASSOCIATION =====================
 
 HKLM\...\.exe: exefile => OK
 HKLM\...\exefile\DefaultIcon: %1 => OK
 HKLM\...\exefile\open\command: "%1" %* => OK
 
 ==================== Restore Points =========================
 
 Restore point made on: 2013-10-26 02:27:33
 Restore point made on: 2013-11-23 18:56:54
 Restore point made on: 2013-11-23 18:57:54
 Restore point made on: 2013-11-23 18:59:44
 Restore point made on: 2013-11-23 19:00:31
 Restore point made on: 2013-11-23 19:02:13
 Restore point made on: 2013-12-22 11:42:50
 Restore point made on: 2014-01-04 10:32:42
 Restore point made on: 2014-01-20 18:57:42
 Restore point made on: 2014-01-24 14:53:43
 
 ==================== Memory info ===========================
 
 Percentage of memory in use: 20%
 Total physical RAM: 3976.57 MB
 Available physical RAM: 3147.29 MB
 Total Pagefile: 3974.77 MB
 Available Pagefile: 3195.92 MB
 Total Virtual: 8192 MB
 Available Virtual: 8191.88 MB
 
 ==================== Drives ================================
 
 Drive c: () (Fixed) (Total:442.31 GB) (Free:364.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 Drive e: (HP_RECOVERY) (Fixed) (Total:21.16 GB) (Free:3.26 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 Drive f: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.97 GB) FAT32
 Drive h: () (Removable) (Total:7.51 GB) (Free:2.09 GB) FAT32
 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
 Drive y: (WIN7PE) (Removable) (Total:14.84 GB) (Free:14.55 GB) FAT32
 
 ==================== MBR & Partition Table ==================
 
 ========================================================
 Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 61D8E20C)
 Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
 Partition 2: (Not Active) - (Size=442 GB) - (Type=07 NTFS)
 Partition 3: (Not Active) - (Size=21 GB) - (Type=07 NTFS)
 Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)
 
 ========================================================
 Disk: 1 (MBR Code: Windows 7 or 8) (Size: 15 GB) (Disk ID: 00000000)
 Partition 1: (Active) - (Size=15 GB) - (Type=0C)
 
 ========================================================
 Disk: 2 (Size: 8 GB) (Disk ID: 04DD5721)
 Partition 1: (Active) - (Size=8 GB) - (Type=0C)
 
 
 LastRegBack: 2013-06-05 14:29
 
 ==================== End Of Log ============================

--- --- ---

schrauber 03.02.2014 10:03

Hi,

seit wann? Was genau passiert wenn Du normal starten willst?

DanielZ87 03.02.2014 14:30

Gerät ist von einer Kundin und ich möchte es ungern Platt machen.

Sie sagt er ging einfach aus und jetzt kommt ein BSOD mit c0000135 The programm can't start because %hs...... Try reinstalling the programm to fix this problem.


Danke

Kann mir keiner helfen :(?

schrauber 04.02.2014 09:52

Zitat:

Gerät ist von einer Kundin
Du wirst bezahlt dafür und lässt die hier für Lau helfen? :wtf:

Das ist kein Malwareproblem. Geht einer der Safe Modes? Mehrere Benutzerkonten da? Wann kommt die Meldung? Nach POST, vor oder nach der Benutzeranmeldung?

DanielZ87 04.02.2014 10:02

Ich möchte der Kundin helfen wir betreuen dort bei Ihrem Chef das Netzwerk...und wie gesagt möchte ihn nicht einfach Platt machen...


Es kommt noch Windows wird geladen, und dann kommt der BSOD mit anschließendem Neustart.
Komme nicht in den Abgesicherten....habe mir einen Windows7 PE Stick erstellt um FRST auszuführen.

Danke

schrauber 05.02.2014 08:19

Zitat:

und dann kommt der BSOD
Diese Info hast du bis jetzt unterschlagen ;)

welcher BSOD, welcher Text? Über den Stick mal bitte in der Eingabeaufforderung in den Minidump Ordner gehen und den letzten Dump sichern, zippen und hier anhängen.

DanielZ87 05.02.2014 08:33

Leider gibt es keinen Ordner Minidump :(

zur Info: hier das gleiche Problem hxxp://www.trojaner-board.de/143507-laptop-bootet-mehr.html

schrauber 06.02.2014 08:14

Nur weil die Kiste auch nicht bootet heisst das nicht es ist das gleiche Problem, abgesehen davon dass dieses Thema nie beendet wurde.


Welcher Bluescreen? C:\Windows\Minidump ist nicht vorhanden?

DanielZ87 06.02.2014 08:27

Der Thread davor hat den gleichen BSOD....nicht nur ein "er bootet nicht mehr"...

Minidump ist / war nicht vorhanden...habe die Kiste Platt gemacht..

Somit hat sich die Sache erledigt, danke trotzdem.

schrauber 07.02.2014 07:55

ok.


Alle Zeitangaben in WEZ +1. Es ist jetzt 11:57 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19