![]() |
|
Log-Analyse und Auswertung: Windows 7 grauer Bildschirm, lässt sich nicht mehr startenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Windows 7 grauer Bildschirm, lässt sich nicht mehr starten Hallo, ich habe ein großes Problem. Mein Rechner lässt sich nicht mehr hochfahren. Nach dem Windows Logo kommt ein grauer Bildschirm, wo nur noch die Maus bewegt werden kann. Im abgesicherten Modus funktioniert alles soweit. Im abgesichertem Modus mit Netzwerktreibern erscheint wieder der graue Bildschirm. Ich habe die Festplatte ausgebaut gehabt und über einen anderen Rechner mit Malwarebytes überprüft. Es wurde nichts festgestellt. Das Problem besteht seit Ende September bzw. Anfang Oktober. Ich habe schon mal ein "Farbar Recovery Scan Tool" Log erstellt. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-11-2014 Ran by SYSTEM on MININT-53G79QQ on 07-11-2014 07:12:34 Running from J:\ Platform: Windows 7 Enterprise Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12632168 2011-07-21] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-13] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Onboard] => C:\Program Files\Western Digital\WD SmartWare\WDSmartWare.exe [3164536 2013-06-19] (Western Digital Technologies, Inc.) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [516928 2013-02-15] (Acronis) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG) HKLM-x32\...\Run: [G Data ASM] => C:\Program Files (x86)\G Data\InternetSecurity\DelayLoader\AutorunDelayLoader.exe [431224 2013-12-19] (G Data Software AG) HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5524336 2013-06-19] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694072 2013-10-15] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [6421592 2014-03-06] (Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1105848 2013-01-10] (Acronis) HKLM\...\RunOnce: [RPMKickstart] => C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.) HKLM-x32\...\RunOnce: [DES2] => C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2.exe [359024 2011-03-08] () HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe, Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\????\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\????\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174296 2014-03-04] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2014-03-04] (NVIDIA Corporation) Startup: C:\Users\????\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk ShortcutTarget: FRITZ!DSL Startcenter.lnk -> C:\Users\????\AppData\Roaming\Microsoft\Installer\{2D5D9603-22CF-4B99-83F6-0CD20330F62E}\Icon8CF9C550.exe () BootExecute: autocheck autochk * sdnclean64.exe ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG) S2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG) S2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2723400 2014-03-25] (G Data Software AG) S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [240112 2010-11-23] (CyberLink) S2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [57344 2011-08-22] () S2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [8704 2012-04-05] (Microsoft) S3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG) S3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG) S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [919040 2014-05-17] (AnchorFree Inc.) S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2014-05-17] () S2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [430344 2014-05-16] () S2 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [88888 2009-07-28] (AVM Berlin) S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) S2 NitroReaderDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [216080 2012-08-15] (Nitro PDF Software) S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation) S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) S2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) S2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-06-19] (Western Digital Technologies, Inc.) S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-11-20] (Western Digital Technologies, Inc.) S2 Freemake Improver; "C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-05-22] (G Data Software AG) S1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-05-22] (G Data Software AG) S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [68608 2014-05-22] (G Data Software AG) S1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-05-22] (G Data Software AG) S1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-05-22] (G Data Software) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2012-04-15] () S1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-05-22] (G Data Software AG) S1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2014-05-17] (AnchorFree Inc.) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation) S2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-04-14] (Duplex Secure Ltd.) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) S0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2014-07-07] (Acronis International GmbH) S0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2014-07-07] (Acronis) S1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [102664 2014-01-23] () S1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [25992 2014-01-23] () S1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [700680 2014-01-23] () S0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2014-07-07] (Acronis International GmbH) S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X] S0 rqhptuq; System32\drivers\vcmycfw.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-07 07:12 - 2014-11-07 07:12 - 00000000 ____D () C:\FRST 2014-10-31 14:26 - 2014-10-31 14:26 - 00262144 _____ () C:\Windows\Minidump\103114-12807-01.dmp 2014-10-31 14:16 - 2014-10-31 14:16 - 00262144 _____ () C:\Windows\Minidump\103114-11590-01.dmp 2014-10-31 14:11 - 2014-10-31 14:11 - 00262144 _____ () C:\Windows\Minidump\103114-10561-01.dmp 2014-10-31 13:56 - 2014-10-31 13:56 - 00262144 _____ () C:\Windows\Minidump\103114-10358-01.dmp 2014-10-31 09:53 - 2014-10-31 09:53 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-31 09:53 - 2014-10-31 09:53 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-31 09:53 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys 2014-10-31 09:53 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys 2014-10-31 09:53 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2014-10-31 09:52 - 2014-10-31 09:59 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys 2014-10-18 16:38 - 2014-10-18 16:38 - 00000000 ____D () C:\Program Files\HitmanPro 2014-10-18 16:37 - 2014-10-18 16:40 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-10-18 16:37 - 2014-10-18 16:37 - 00262144 _____ () C:\Windows\Minidump\101814-10873-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-07 07:05 - 2014-04-25 19:58 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-11-07 07:05 - 2009-07-14 05:51 - 00049878 _____ () C:\Windows\setupact.log 2014-10-31 14:30 - 2012-03-21 15:41 - 00000000 ____D () C:\Users\????\AppData\Roaming\vlc 2014-10-31 14:26 - 2013-02-11 22:43 - 00000000 ____D () C:\Windows\Minidump 2014-10-31 14:11 - 2010-11-21 04:47 - 00025314 _____ () C:\Windows\PFRO.log 2014-10-31 09:53 - 2010-11-21 07:22 - 00696832 _____ () C:\Windows\System32\perfh007.dat 2014-10-31 09:53 - 2010-11-21 07:22 - 00148128 _____ () C:\Windows\System32\perfc007.dat 2014-10-31 09:53 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\System32\PerfStringBackup.INI 2014-10-31 09:44 - 2014-10-04 15:38 - 00000108 ___RH () C:\Users\????\Desktop\Stinger.opt 2014-10-31 09:44 - 2014-10-04 15:38 - 00000000 ____D () C:\Program Files (x86)\stinger 2014-10-31 09:35 - 2012-03-21 13:17 - 00564967 _____ () C:\Users\????\DesktopStCenter.txt 2014-10-31 09:35 - 2012-03-07 20:23 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-10-31 09:33 - 2014-06-16 12:00 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat 2014-10-31 09:16 - 2012-04-10 16:21 - 00000000 ____D () C:\ProgramData\Temp Files to move or delete: ==================== Some content of TEMP: ==================== C:\Users\????\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\????\AppData\Local\Temp\ose00000.exe ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2014-08-29 09:13:05 Restore point made on: 2014-09-05 11:49:55 Restore point made on: 2014-09-13 16:22:08 Restore point made on: 2014-09-21 19:41:40 Restore point made on: 2014-09-29 18:18:08 ==================== Memory info =========================== Percentage of memory in use: 7% Total physical RAM: 16301.11 MB Available physical RAM: 15079.73 MB Total Pagefile: 16299.31 MB Available Pagefile: 15091.14 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:5.98 GB) NTFS Drive j: (HITMANPRO) (Removable) (Total:29.39 GB) (Free:29.27 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 16EEF423) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS) ======================================================== Disk: 5 (Size: 29.5 GB) (Disk ID: CAD9A6B3) Partition 1: (Active) - (Size=29.4 GB) - (Type=0B) LastRegBack: 2014-09-26 18:02 ==================== End Of Log ============================ Danke Geändert von WMX (07.11.2014 um 16:49 Uhr) |
Themen zu Windows 7 grauer Bildschirm, lässt sich nicht mehr starten |
.dll, bildschirm, desktop, dsl, explorer, fehlercode 0x81000006, fehlercode 0xc0000417, fehlercode windows, grauer bildschirm, home, hotspot, mobogenie, mobogenie entfernen, netzwerk, nvbackend, nvidia, registry, rundll, security, services.exe, starten, svchost.exe, temp, trojaner, windows, winlogon.exe |