Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Laptop bootet nicht mehr (https://www.trojaner-board.de/143507-laptop-bootet-mehr.html)

khaoz 24.10.2013 10:02

Laptop bootet nicht mehr
 
Hallo zusammen,

folgende Schwierigkeit:

der Laptop eines Freundes von mir fährt nach der Installation von 25 Windows-Updates nicht mehr hoch. Es erscheint beim Booten ein blauer Bildschirm mit diesem Hinweis:

"STOP: C0000135 The program can't start because %hs is missing. Try resintalling the program"

Es handelt sich um ein englisches System. Ich habe das Internet bereits nach Lösungen abgesucht aber bisher hat kein Tip funktioniert. Ich habe jetzt das folgende Logfile erstellt und hoffe, dass hier jemand einen Rat weiss.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-10-2013
Ran by SYSTEM on MININT-FT25GKI on 23-10-2013 20:47:07
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SiSTray] - C:\Program Files\SiS VGA Utilities\SiSTray.exe [552960 2009-11-12] (Silicon Integrated Systems Corporation)
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-01] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1022904 2010-02-23] (Trend Micro Inc.)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-29] (AVAST Software)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.)
HKU\asus\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-10-02] (Google Inc.)
AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL C:\PROGRA~2\MOVIES~1\Datamngr\x64\mgrldr.dll  [22528 2013-09-24] ()
AppInit_DLLs-x32: c:\progra~2\movies~1\datamngr\mgrldr.dll c:\progra~3\wincert\win32c~1.dll [7168 2013-09-22] ()
IMEO\bitguard.exe: [Debugger] tasklist.exe
IMEO\bprotect.exe: [Debugger] tasklist.exe
IMEO\browserdefender.exe: [Debugger] tasklist.exe
IMEO\browserprotect.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll [485376 2013-09-24] () <===== ATTENTION
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll [657920 2013-09-24] () <===== ATTENTION
BootExecute: autocheck autochk * sdnclean64.exe

==================== Services (Whitelisted) =================

S2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] ()
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-29] (AVAST Software)
S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-13] (Microsoft Corporation)
S2 DatamngrCoordinator; C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3419136 2013-09-24] (Bandoo Media Inc.)
S2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [225280 2009-12-22] ()
S4 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation)
S2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.)
S3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2009-09-29] (Trend Micro Inc.)
S3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2009-09-29] (Trend Micro Inc.)
S2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-11-16] (Vodafone)
S2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-03] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-29] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-29] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-29] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-29] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-29] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-29] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-29] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-29] ()
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [250368 2010-04-07] (Huawei Technologies Co., Ltd.)
S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [92032 2007-05-31] (Huawei Technologies Co., Ltd.)
S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 OXSDIDRV_x64; C:\Windows\System32\DRIVERS\OXSDIDRV_x64.sys [51760 2009-09-28] ()
S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X64.sys [31280 2010-05-24] ()
S3 SiS6350; C:\Windows\System32\DRIVERS\SISGRKMD.sys [558080 2009-11-12] (Silicon Integrated Systems Corporation)
S0 SISAGP; C:\Windows\System32\DRIVERS\SISAGPX.sys [67104 2009-08-01] (Silicon Integrated Systems Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-08-12] ()
S2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.)
S1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2009-09-29] (Trend Micro Inc.)
S2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.)
S2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.)
S3 tmlwf;
S3 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST
2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP
2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log
2013-10-08 16:39 - 2013-10-12 05:46 - 00000280 _____ C:\Windows\setupact.log
2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini
2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg
2013-10-06 11:13 - 2013-10-06 11:18 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-06 11:07 - 2013-10-06 11:27 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator
2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys
2013-10-06 11:06 - 2013-10-06 11:09 - 37672592 _____ (Safer-Networking Ltd.                                      ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe
2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com                                                ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2013-10-06 11:01 - 2013-10-12 11:40 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl
2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe
2013-09-25 16:33 - 2013-10-08 15:13 - 00027648 ___SH C:\Users\asus\Downloads\Thumbs.db
2013-09-24 12:47 - 2013-10-12 22:14 - 00000000 ____D C:\ProgramData\Datamngr
2013-09-24 12:47 - 2013-09-24 12:47 - 00000000 ____D C:\Program Files (x86)\Movies Toolbar

==================== One Month Modified Files and Folders =======

2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST
2013-10-12 22:14 - 2013-09-24 12:47 - 00000000 ____D C:\ProgramData\Datamngr
2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-12 22:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-10-12 22:12 - 2011-09-26 17:43 - 00000000 ____D C:\users\asus
2013-10-12 22:12 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP
2013-10-12 12:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\tracing
2013-10-12 11:55 - 2013-08-08 18:02 - 00000000 ____D C:\Windows\System32\MRT
2013-10-12 11:46 - 2013-06-25 08:03 - 01240442 _____ C:\Windows\WindowsUpdate.log
2013-10-12 11:40 - 2013-10-06 11:01 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl
2013-10-12 11:38 - 2013-05-24 04:24 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-12 11:15 - 2011-10-02 15:28 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-12 06:57 - 2011-10-02 15:28 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-12 05:46 - 2013-10-08 16:39 - 00000280 _____ C:\Windows\setupact.log
2013-10-12 05:46 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-10 03:10 - 2009-07-13 21:13 - 00726444 _____ C:\Windows\System32\PerfStringBackup.INI
2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log
2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-08 15:13 - 2013-09-25 16:33 - 00027648 ___SH C:\Users\asus\Downloads\Thumbs.db
2013-10-08 05:25 - 2011-10-04 14:37 - 00002145 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-06 11:27 - 2013-10-06 11:07 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator
2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini
2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg
2013-10-06 11:21 - 2012-10-11 06:51 - 00000000 ____D C:\Windows\Minidump
2013-10-06 11:18 - 2013-10-06 11:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-06 11:09 - 2013-10-06 11:06 - 37672592 _____ (Safer-Networking Ltd.                                      ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe
2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys
2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com                                                ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe
2013-10-06 08:37 - 2012-10-23 06:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-06 01:17 - 2012-10-23 06:50 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-03 16:20 - 2011-09-30 04:12 - 00000000 ____D C:\Users\asus\AppData\Roaming\Microgaming
2013-10-02 12:13 - 2009-07-28 22:03 - 00000000 ____D C:\Windows\Panther
2013-10-02 12:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-10-01 15:09 - 2011-10-02 15:28 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-01 15:09 - 2011-10-02 15:28 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-09-24 12:47 - 2013-09-24 12:47 - 00000000 ____D C:\Program Files (x86)\Movies Toolbar
2013-09-24 12:47 - 2013-05-27 15:37 - 00000000 ____D C:\ProgramData\Wincert
2013-09-24 12:47 - 2013-05-27 15:36 - 00000000 ____D C:\Program Files (x86)\Search Results Toolbar

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1013183496-1763523383-1214035250-1000\$53710660ac42bd14fc9048f6c21d0c4f

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$53710660ac42bd14fc9048f6c21d0c4f

Files to move or delete:
====================
C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll
C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll


==================== Known DLLs (Whitelisted) ================

C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION!
C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION!

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 24%
Total physical RAM: 1919.34 MB
Available physical RAM: 1442.74 MB
Total Pagefile: 1919.34 MB
Available Pagefile: 1430.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:58.22 GB) (Free:14.38 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:158.06 GB) (Free:157.74 GB) NTFS
Drive f: (INTENSO USB) (Removable) (Total:14.53 GB) (Free:14.53 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 1674CEE9)
Partition 1: (Not Active) - (Size=17 GB) - (Type=1C)
Partition 2: (Active) - (Size=58 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=158 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 15 GB) (Disk ID: C7B3A61F)
Partition 1: (Active) - (Size=15 GB) - (Type=0C)


LastRegBack: 2013-08-20 15:42

==================== End Of Log ============================

--- --- ---

schrauber 24.10.2013 12:05

Systemwiederherstellung schon versucht?

khaoz 24.10.2013 14:27

Ja, funktioniert aber leider nicht. "Repair mode" bringt auch nichts.

schrauber 25.10.2013 08:50

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

LastRegBack: 2013-08-20 15:42
Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

khaoz 25.10.2013 12:38

Alles wie beschrieben gemacht. Habe danach versucht den Laptop hochzufahren aber es erscheint nach wie vor die gleiche Fehlermeldung. (Dachte durch die erfolgreichen Kopien in der Registry wäre das Problem behoben aber zu früh gefreut). Anbei die Fixlogdatei:

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-10-2013
Ran by SYSTEM at 2013-10-25 10:53:21 Run:2
Running from F:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
LastRegBack: 2013-08-20 15:42
       
*****************

DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.

==== End of Fixlog ====


schrauber 26.10.2013 12:02

Poste nochmal ein frisches FRST log aus der Recovery bitte.

khaoz 30.10.2013 10:26

Voila:
FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-10-2013
Ran by SYSTEM on MININT-9F9PQQS on 30-10-2013 07:20:57
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SiSTray] - C:\Program Files\SiS VGA Utilities\SiSTray.exe [552960 2009-11-12] (Silicon Integrated Systems Corporation)
HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-01] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1022904 2010-02-23] (Trend Micro Inc.)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-29] (AVAST Software)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.)
HKLM-x32\...\Run: [DATAMNGR] - C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~2.EXE
HKU\asus\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-10-02] (Google Inc.)
AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll  [97280 2009-07-13] ()
AppInit_DLLs-x32: C:\PROGRA~3\Wincert\WIN32C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\mgrldr.dll  [ ] ()
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\apcrtldr.dll <===== ATTENTION

==================== Services (Whitelisted) =================

S2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] ()
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-29] (AVAST Software)
S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-13] (Microsoft Corporation)
S2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [225280 2009-12-22] ()
S4 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation)
S2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.)
S3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2009-09-29] (Trend Micro Inc.)
S3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2009-09-29] (Trend Micro Inc.)
S2 VMCService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-11-16] (Vodafone)
S2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-03] (Microsoft Corporation)
S2 DatamngrCoordinator; C:\Program Files (x86)\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe [x]

==================== Drivers (Whitelisted) ====================

S2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-29] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-29] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-29] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-29] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-29] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-29] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-29] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-29] ()
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [250368 2010-04-07] (Huawei Technologies Co., Ltd.)
S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [92032 2007-05-31] (Huawei Technologies Co., Ltd.)
S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 OXSDIDRV_x64; C:\Windows\System32\DRIVERS\OXSDIDRV_x64.sys [51760 2009-09-28] ()
S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X64.sys [31280 2010-05-24] ()
S3 SiS6350; C:\Windows\System32\DRIVERS\SISGRKMD.sys [558080 2009-11-12] (Silicon Integrated Systems Corporation)
S0 SISAGP; C:\Windows\System32\DRIVERS\SISAGPX.sys [67104 2009-08-01] (Silicon Integrated Systems Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-08-12] ()
S2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.)
S1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2009-09-29] (Trend Micro Inc.)
S2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.)
S2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.)
S3 tmlwf;
S3 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-25 10:53 - 2013-10-25 10:53 - 00000000 ____D C:\Windows\System32\config\HiveBackup
2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST
2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP
2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log
2013-10-08 16:39 - 2013-10-12 05:46 - 00000280 _____ C:\Windows\setupact.log
2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini
2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg
2013-10-06 11:13 - 2013-10-06 11:18 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-06 11:07 - 2013-10-06 11:27 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator
2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys
2013-10-06 11:06 - 2013-10-06 11:09 - 37672592 _____ (Safer-Networking Ltd.                                      ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe
2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com                                                ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2013-10-06 11:01 - 2013-10-12 11:40 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl
2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe

==================== One Month Modified Files and Folders =======

2013-10-25 10:53 - 2013-10-25 10:53 - 00000000 ____D C:\Windows\System32\config\HiveBackup
2013-10-23 20:47 - 2013-10-23 20:47 - 00000000 ____D C:\FRST
2013-10-12 22:14 - 2013-09-24 12:47 - 00000000 ____D C:\ProgramData\Datamngr
2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-12 22:14 - 2013-03-14 06:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-12 22:13 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-10-12 22:12 - 2011-09-26 17:43 - 00000000 ____D C:\users\asus
2013-10-12 22:12 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-10-12 13:15 - 2013-10-12 13:15 - 312605433 _____ C:\Windows\MEMORY.DMP
2013-10-12 12:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\tracing
2013-10-12 11:57 - 2013-08-08 18:02 - 00000000 ____D C:\Windows\System32\MRT
2013-10-12 11:46 - 2013-06-25 08:03 - 01240442 _____ C:\Windows\WindowsUpdate.log
2013-10-12 11:40 - 2013-10-06 11:01 - 00003166 _____ C:\Windows\System32\Tasks\P4GIntlCtrl
2013-10-12 11:38 - 2013-05-24 04:24 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-12 11:15 - 2011-10-02 15:28 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-12 06:57 - 2011-10-02 15:28 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-12 05:57 - 2009-07-13 20:45 - 00010240 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-12 05:46 - 2013-10-08 16:39 - 00000280 _____ C:\Windows\setupact.log
2013-10-12 05:46 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-10 03:10 - 2009-07-13 21:13 - 00726444 _____ C:\Windows\System32\PerfStringBackup.INI
2013-10-09 18:21 - 2013-10-09 18:21 - 00000644 _____ C:\Windows\PFRO.log
2013-10-08 16:39 - 2013-10-08 16:39 - 00000000 _____ C:\Windows\setuperr.log
2013-10-08 15:13 - 2013-09-25 16:33 - 00027648 ___SH C:\Users\asus\Downloads\Thumbs.db
2013-10-08 05:25 - 2011-10-04 14:37 - 00002145 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-06 11:27 - 2013-10-06 11:07 - 00000000 ____D C:\Program Files (x86)\Spyware Terminator
2013-10-06 11:23 - 2013-10-06 11:23 - 00000085 _____ C:\Windows\wininit.ini
2013-10-06 11:22 - 2013-10-06 11:22 - 00036872 _____ C:\Users\asus\Documents\cc_20131006_202226.reg
2013-10-06 11:21 - 2012-10-11 06:51 - 00000000 ____D C:\Windows\Minidump
2013-10-06 11:18 - 2013-10-06 11:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-06 11:13 - 2013-10-06 11:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-06 11:09 - 2013-10-06 11:06 - 37672592 _____ (Safer-Networking Ltd.                                      ) C:\Users\asus\Downloads\spybotsd-2.1.21-SR2.exe
2013-10-06 11:07 - 2013-10-06 11:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\System32\Drivers\stflt.sys
2013-10-06 11:06 - 2013-10-06 11:06 - 05049344 _____ (Crawler.com                                                ) C:\Users\asus\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2013-10-06 08:48 - 2013-10-06 08:48 - 00347424 _____ (Microsoft Corporation) C:\Users\asus\Downloads\MicrosoftFixit.Devices.Run.exe
2013-10-06 08:37 - 2012-10-23 06:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-06 01:17 - 2012-10-23 06:50 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-03 16:20 - 2011-09-30 04:12 - 00000000 ____D C:\Users\asus\AppData\Roaming\Microgaming
2013-10-02 12:13 - 2009-07-28 22:03 - 00000000 ____D C:\Windows\Panther
2013-10-02 12:10 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-10-01 15:09 - 2011-10-02 15:28 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-01 15:09 - 2011-10-02 15:28 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1013183496-1763523383-1214035250-1000\$53710660ac42bd14fc9048f6c21d0c4f

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$53710660ac42bd14fc9048f6c21d0c4f

==================== Known DLLs (Whitelisted) ================

C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION!
C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION!

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 23%
Total physical RAM: 1919.34 MB
Available physical RAM: 1459.75 MB
Total Pagefile: 1919.34 MB
Available Pagefile: 1446.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:58.22 GB) (Free:14.3 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:158.06 GB) (Free:157.74 GB) NTFS
Drive f: (INTENSO USB) (Removable) (Total:14.53 GB) (Free:14.53 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 1674CEE9)
Partition 1: (Not Active) - (Size=17 GB) - (Type=1C)
Partition 2: (Active) - (Size=58 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=158 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 15 GB) (Disk ID: C7B3A61F)
Partition 1: (Active) - (Size=15 GB) - (Type=0C)


LastRegBack: 2013-08-20 15:42

==================== End Of Log ============================

--- --- ---

schrauber 30.10.2013 14:42

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll  [97280 2009-07-13] ()
AppInit_DLLs-x32: C:\PROGRA~3\Wincert\WIN32C~1.DLL C:\PROGRA~2\SEARCH~1\Datamngr\mgrldr.dll  [ ] ()
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\Run: [UfSeAgnt.exe] - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [1022904 2010-02-23] (Trend Micro Inc.)
S2 DatamngrCoordinator; C:\Program Files (x86)\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe [x]
2013-10-12 22:14 - 2013-09-24 12:47 - 00000000 ____D C:\ProgramData\Datamngr
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1013183496-1763523383-1214035250-1000\$53710660ac42bd14fc9048f6c21d0c4f

ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$53710660ac42bd14fc9048f6c21d0c4f

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.




Dann nochmal FRST öffnen, in das Suchfeld

LPK.dll

eintippen und Search klicken.


Alle Zeitangaben in WEZ +1. Es ist jetzt 18:13 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129