<-IceD@te-> | 31.08.2011 11:13 | Guten Tag,
ich bin mit dem Gmer-Scan durch. Alle Schutzprogramme und Internetverbindung waren aus, WinWall war an, 1 USB-Datenstick war angeschlossen. Nun folgt der OSAM-Scan. Hier das Gmer-Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2011-08-31 11:52:24
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 Maxtor_6K040L0 rev.NAR61HA0
Running: zjqedoxt.exe; Driver: C:\DOKUME~1\GE\LOKALE~1\Temp\pwrdypow.sys
---- System - GMER 1.0.15 ----
SSDT F7BC61A4 ZwClose
SSDT F7BC615E ZwCreateKey
SSDT F7BC61AE ZwCreateSection
SSDT F7BC6154 ZwCreateThread
SSDT F7BC6163 ZwDeleteKey
SSDT F7BC616D ZwDeleteValueKey
SSDT F7BC619F ZwDuplicateObject
SSDT F7BC6172 ZwLoadKey
SSDT F7BC6140 ZwOpenProcess
SSDT F7BC6145 ZwOpenThread
SSDT F7BC617C ZwReplaceKey
SSDT F7BC6177 ZwRestoreKey
SSDT F7BC61B3 ZwSetContextThread
SSDT F7BC6168 ZwSetValueKey
SSDT F7BC614F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6B17360, 0x20469D, 0xE8000020]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs BA2C9400
---- EOF - GMER 1.0.15 ---- Ich habe aktuell noch eine weitere Frage den WurmPC betreffend: Ich habe heut' morgen erstmal defragmentiert, damit die Kiste schneller startet und evtl auch schneller scannt. Dabei kam mir eine Log-Datei unter die Lupe, welche sich einfach nicht defragmentieren lässt. Diese Textdatei ist ca. 16MB groß und besteht aus über 1700 Fragmenten(!). :eek: Ich wollte die Datei auf einen USB-Stick kopieren und dann wieder zurück auf die Platte, aber ich bekam eine Meldung in der Art "Kann nicht kopiert werden - CRC-Prüfsummenfehler". Pfad und Name der Datei sind "C:\Dokumente und Einstellungen\GE\Anwendungsdaten\Haufe\Installer_log\iDesk_log.txt".
Gibt es dazu Hinweise? Muss ich von einem Festplattendefekt ausgehen? Können die Ursachen woanders liegen?
Edit (12:53 Uhr): Womit wir dann beim OSAM-Logfile wären: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 12:48:15 on 31.08.2011
OS: Windows XP Home Edition Service Pack 2 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 6.00.2900.2180
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"alsndmgr.cpl" - ? - C:\WINDOWS\system32\alsndmgr.cpl (File signed by Microsoft | File found, but it contains no detailed information)
"bdeadmin.cpl" - ? - C:\WINDOWS\system32\bdeadmin.cpl
"Firebird2Control.cpl" - "IBPhoenix" - C:\WINDOWS\system32\Firebird2Control.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"jpicpl32.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\jpicpl32.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Avira AntiVir Professional" - "Avira GmbH" - C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgio" (avgio) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys
"AVM KEN CAPI" (ndc) - "AVM Berlin" - C:\WINDOWS\System32\Drivers\ndc.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys (File not found)
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found)
"Huawei DataCard USB Modem and USB Serial" (hwdatacard) - ? - C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys (File not found)
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys (File not found)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\WINDOWS\system32\drivers\mbam.sys
"OVT Scanner" (APL531) - ? - C:\WINDOWS\System32\Drivers\ov550i.sys (File not found)
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys (File not found)
"PPdus ASPI Shell" (Afc) - "Arcsoft, Inc." - C:\WINDOWS\System32\drivers\Afc.sys
"Secdrv" (Secdrv) - ? - C:\WINDOWS\System32\DRIVERS\secdrv.sys (File signed by Microsoft | File found, but it contains no detailed information)
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys (File not found)
[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - ? - C:\Programme\Common\Microsoft Shared\Web Folders\msonsext.dll (File not found)
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - ? - C:\PROGRA~1\Common\MICROS~1\WEBCOM~1\10\OWC10.DLL (File not found)
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - ? - C:\Programme\Common\Microsoft Shared\Help\hxds.dll (File not found)
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - ? - C:\Programme\Common\Microsoft Shared\Information Retrieval\msitss.dll (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler )-----
{438755C2-A8BA-11D1-B96B-00A0C90312E1} "Browseui preloader" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{8C7461EF-2B13-11d2-BE35-3078302C2030} "Component Categories cache daemon" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{01E04581-4EEE-11d0-BFE9-00AA005B4383} "&Adresse" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{7e653215-fa25-46bd-a339-34a2790f3cb7} "Accessible" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{A08C11D2-A228-11d0-825B-00AA005B4383} "Address EditBox" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{91EA3F8B-C99B-11d0-9815-00C04FD91972} "Augmented Shell Folder" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{6413BA2C-B461-11d1-A18A-080036B11A03} "Augmented Shell Folder 2" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{F61FFEC1-754F-11d0-80CA-00AA005B4383} "BandProxy" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll (File not found)
{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} "Custom MRU AutoCompleted List" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{22BF0C20-6DA7-11D0-B373-00A0C9034938} "Download Status" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{1D2680C9-0E2A-469d-B787-065558BC7D43} "Fusion Cache" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "Global Folder Settings" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{DB8DC413-C0AA-11D0-9545-080009B1C2F3} "Hummingbird Neighborhood" - "Hummingbird Ltd." - C:\Programme\Hummingbird\Connectivity\7.11\HostExplorer\Ftp\heshell.dll
{3028902F-6374-48b2-8DC6-9725E775B926} "IE Microsoft AutoComplete" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{30D02401-6A81-11d0-8274-00C04FD5AE38} "IE Search Band" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{169A0691-8DF9-11d1-A1C4-00C04FD75D13} "In-pane search" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? - (File not found | COM-object registry key not found)
{7BA4C742-9E81-11CF-99D3-00AA004AE837} "Microsoft BrowserBand" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{00BB2764-6A77-11D0-A535-00C04FD7D062} "Microsoft History AutoComplete List" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{5E6AB780-7743-11CF-A12B-00AA004AE837} "Microsoft Internet Toolbar" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{00BB2765-6A77-11D0-A535-00C04FD7D062} "Microsoft Multiple AutoComplete List Container" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office10\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - ? - C:\PROGRA~1\Common\MICROS~1\OFFICE12\msoshext.dll (File not found)
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - ? - C:\PROGRA~1\Common\MICROS~1\OFFICE12\msoshext.dll (File not found)
{03C036F1-A186-11D0-824A-00AA005B4383} "Microsoft Shell Folder AutoComplete List" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{6756A641-DE71-11d0-831B-00AA005B4383} "MRU AutoComplete List" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{AF4F6510-F982-11d0-8595-00AA004CD6D8} "Registry Tree Options Utility" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{ECD4FC4E-521C-11D0-B792-00A0C90312E1} "Shell Band Site Menu" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{ECD4FC4C-521C-11D0-B792-00A0C90312E1} "Shell DeskBar" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} "Shell DeskBarApp" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\shlext.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{00BB2763-6A77-11D0-A535-00C04FD7D062} "Shell Microsoft AutoComplete" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{ECD4FC4D-521C-11D0-B792-00A0C90312E1} "Shell Rebar BandSite" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{21569614-B795-46b1-85F4-E737A8DC09AD} "Shell Search Band" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? - (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
{acf35015-526e-4230-9596-becbe19f0ac9} "Track Popup Bar" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{7376D660-C583-11d0-A3A5-00C04FD706EC} "TridentImageExtractor" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{DD313E04-FEFF-11d1-8ECD-0000F87A470C} "User Assist" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{07798131-AF23-11d1-9111-00A0C98BA67D} "Web Search" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - ? - C:\Programme\Common\Microsoft Shared\Web Folders\msonsext.dll (File not found)
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{21569614-B795-46B1-85F4-E737A8DC09AD} "Shell Search Band" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "&Adresse" - ? - C:\WINDOWS\system32\browseui.dll (File found, but it contains no detailed information)
<binary data> "ITBarLayout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.5.0_06" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\npjpi150_06.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} "Java Plug-in 1.5.0_06" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\npjpi150_06.dll / hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? - (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "AcroIEHlprObj Class" - "Adobe Systems Incorporated" - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Programme\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\GE\Startmenü\Programme\Autostart\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"swg" - "Google Inc." - "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avgnt" - "Avira GmbH" - "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - C:\Programme\MalwarebytesAM\mbamgui.exe /starttray
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"starter4g" - "4G Systems GmbH & Co. KG" - C:\WINDOWS\starter4g.exe
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"Anwendungsverwaltung" (AppMgmt) - ? - C:\WINDOWS\System32\appmgmts.dll (File not found)
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir MailGuard" (AntiVirMailService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avmailc.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\sched.exe
"Avira AntiVir WebGuard" (AntiVirWebService) - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE
"AVM KEN Klient" (KEN Client Service) - "AVM Berlin" - C:\Programme\KEN!\KENCLI.EXE
"Firebird Guardian - DefaultInstance" (FirebirdGuardianDefaultInstance) - "The Firebird Project" - C:\Programme\Firebird\Firebird_1_5\bin\fbguard.exe
"Firebird Server - DefaultInstance" (FirebirdServerDefaultInstance) - "The Firebird Project" - C:\Programme\Firebird\Firebird_1_5\bin\fbserver.exe
"Google Updater Service" (gusvc) - "Google" - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
"InstallDriver Table Manager" (IDriverT) - ? - "C:\Programme\Common\InstallShield\Driver\1050\Intel 32\IDriverT.exe" (File not found)
"Machine Debug Manager" (MDM) - ? - "C:\Programme\Common\Microsoft Shared\VS7Debug\mdm.exe" (File not found)
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Programme\MalwarebytesAM\mbamservice.exe
"WTGService" (WTGService) - ? - C:\Programme\XSManager\WTGService.exe (File found, but it contains no detailed information)
"XS Stick Service" (XS Stick Service) - "4G Systems GmbH & Co. KG" - C:\WINDOWS\service4g.exe
[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
{c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" - ? - appmgmts.dll (File not found)
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"AVSDA" - "Avira GmbH" - C:\Programme\Avira\AntiVir Desktop\avsda.dll
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Edit 2 (12:58 Uhr): Avira AntiVir Professional hat übrigens keine einzige Meldung wegen OSAM gebracht... Falls das interessant ist!?!
MfG
Icy |