|   | AnfängerKK | 17.09.2011 07:30 |  
 . 
GMER Logfile:   Code: 
 GMER 1.0.15.15641 - hxxp://www.gmer.netRootkit scan 2011-09-17 08:23:12
 Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.SBDO
 Running: 6pb4k0u3.exe; Driver: C:\DOKUME~1\Karl\LOKALE~1\Temp\pxrdqpog.sys
 
 
 ---- System - GMER 1.0.15 ----
 
 Code            870FC4D0                                                                                                             pIofCallDriver
 
 ---- Kernel code sections - GMER 1.0.15 ----
 
 .reloc          C:\WINDOWS\system32\drivers\NDIS.sys                                                                                 section is executable [0x856B1200, 0x32DAA, 0xE0000060]
 ?               Combo-Fix.sys                                                                                                        Das System kann die angegebene Datei nicht finden. !
 ?               C:\ComboFix\catchme.sys                                                                                              Das System kann den angegebenen Pfad nicht finden. !
 ?               C:\WINDOWS\system32\Drivers\PROCEXP113.SYS                                                                           Das System kann die angegebene Datei nicht finden. !
 
 ---- User code sections - GMER 1.0.15 ----
 
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!GetSysColor                                                         7E368E78 5 Bytes  JMP 0041C110 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!GetSysColorBrush                                                    7E368EAB 5 Bytes  JMP 0041C180 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!SetScrollInfo                                                       7E369056 7 Bytes  JMP 0041C000 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!GetScrollInfo                                                       7E370DA2 7 Bytes  JMP 0041BF50 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!ShowScrollBar                                                       7E37F2B3 5 Bytes  JMP 0041C0D0 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!GetScrollPos                                                        7E37F6C4 5 Bytes  JMP 0041BF90 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!SetScrollPos                                                        7E37F710 5 Bytes  JMP 0041C040 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!GetScrollRange                                                      7E37F747 5 Bytes  JMP 0041BFC0 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!SetScrollRange                                                      7E37F95B 5 Bytes  JMP 0041C080 C:\WINDOWS\SMINST\Scheduler.exe
 .text           C:\WINDOWS\SMINST\Scheduler.exe[3980] USER32.dll!EnableScrollBar                                                     7E3B7DDD 7 Bytes  JMP 0041BF10 C:\WINDOWS\SMINST\Scheduler.exe
 
 ---- Devices - GMER 1.0.15 ----
 
 Device          \Driver\NDIS \Device\Ndis                                                                                            [856B8984] NDIS.sys[.reloc]
 
 AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                                                                              eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
 
 Device          \Driver\prodrv06 \Device\ProDrv06                                                                                    E22A7C30
 Device          \Driver\iaStor \Device\Ide\iaStor0                                                                                   prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
 Device          \Driver\atapi \Device\Ide\IdePort0                                                                                   prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
 Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                          prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
 Device          \Driver\iaStor \Device\Ide\IAAStorageDevice-0                                                                        prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
 Device          \Driver\prohlp02 \Device\ProHlp02                                                                                    E1964348
 
 ---- Registry - GMER 1.0.15 ----
 
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             2
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             7
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             35
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             4
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             4
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             4
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties@DeviceType             7
 Reg             HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties@DeviceCharacteristics  256
 Reg             HKLM\SYSTEM\CurrentControlSet\Services\MRxDAV\EncryptedDirectories@
 
 ---- Files - GMER 1.0.15 ----
 
 File            C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdndis.sys                                                             (size mismatch) 149123/182528 bytes executable
 File            C:\SwSetup\Btooth\btwdndis.sys                                                                                       (size mismatch) 149123/182528 bytes executable
 File            C:\SwSetup\Btooth\Win32\drivers\btwdndis.sys                                                                         (size mismatch) 149123/182528 bytes executable
 File            C:\SwSetup\Btooth\Win64\drivers\btwdndis.sys                                                                         (size mismatch) 148992/182528 bytes executable
 File            C:\SwSetup\NIS07\GR\Suport64\SymNet\SND_x64\symndis.sys                                                              (size mismatch) 41784/182528 bytes executable
 File            C:\SwSetup\NIS07\GR\Support\SymNet\SymNet\Drivers\symndis.sys                                                        (size mismatch) 35256/182528 bytes executable
 File            C:\SwSetup\NIS07\Suport64\SymNet\SND_x64\symndis.sys                                                                 (size mismatch) 41784/182528 bytes executable
 File            C:\SwSetup\NIS07\Support\SymNet\SymNet\Drivers\symndis.sys                                                           (size mismatch) 35256/182528 bytes executable
 File            C:\WINDOWS\system32\dllcache\ndis.sys                                                                                (size mismatch) 212992/182528 bytes executable
 File            C:\WINDOWS\system32\drivers\ndis.sys                                                                                 (size mismatch) 212992/182528 bytes executable
 
 ---- EOF - GMER 1.0.15 ----
 --- --- ---    
:Boogie::Boogie::Boogie:   
und hier OSAM 
OSAM Logfile:   Code: 
 Report of OSAM: Autorun Manager v5.0.11926.0hxxp://www.online-solutions.ru/en/
 Saved at 08:49:05 on 17.09.2011
 
 OS: Windows XP Professional Service Pack 2 (Build 2600)
 Default Browser: Mozilla Corporation Firefox 3.6.18
 
 Scanner Settings
 [x] Rootkits detection (hidden registry)
 [x] Rootkits detection (hidden files)
 [x] Retrieve files information
 [x] Check Microsoft signatures
 
 Filters
 [ ] Trusted entries
 [ ] Empty entries
 [x] Hidden registry entries (rootkit activity)
 [x] Exclusively opened files
 [x] Not found files
 [x] Files without detailed information
 [x] Existing files
 [ ] Non-startable services
 [ ] Non-startable drivers
 [x] Active entries
 [x] Disabled entries
 
 
 [Common]
 -----( %SystemRoot%\Tasks )-----
 "AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe
 "GoogleUpdateTaskUserS-1-5-21-3651596109-1865983425-202582196-1008Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\Robert\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
 "GoogleUpdateTaskUserS-1-5-21-3651596109-1865983425-202582196-1008UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\Robert\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
 "RMSchedule.job" - "PC Tools" - C:\Programme\Registry Mechanic\RegMech.exe
 
 [Control Panel Objects]
 -----( %SystemRoot%\system32 )-----
 "accelerometercp.CPL" - "Hewlett-Packard Corporation" - C:\WINDOWS\system32\accelerometercp.CPL
 "btcpl.cpl" - "Broadcom Corporation." - C:\WINDOWS\system32\btcpl.cpl
 "DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\WINDOWS\system32\DivXControlPanelApplet.cpl
 "FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
 "javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
 "Accelerometer" - "Hewlett-Packard Corporation" - C:\WINDOWS\system32\accelerometercp.cpl
 "CognizanceWS" - "Cognizance Corporation" - C:\PROGRA~1\HEWLET~1\IAM\Bin\Settings.dll
 "HPWACpl" - "Hewlett-Packard Development Company, L.P." - C:\Programme\Hewlett-Packard\HP Wireless Assistant\WACntlPnl.cpl
 "Pando" - "Pando Networks" - C:\Programme\Pando Networks\Media Booster\PMB.cpl
 "PTHOST.CPL" - " Hewlett-Packard Development Company, L.P" - C:\Programme\Hewlett-Packard\HP ProtectTools Security Manager\PTHOST.CPL
 "QlbConfig" - " Hewlett-Packard Development Company, L.P." - C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\QlbConfg.cpl
 "QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl
 "SMAX4CP" - "Analog Devices, Inc." - C:\Programme\Analog Devices\SoundMAX\SMax4.cpl
 
 [Drivers]
 -----( HKLM\SYSTEM\CurrentControlSet\Services )-----
 "84071a83" (84071a83) - ? - C:\WINDOWS\System32\drivers\84071a83.sys  (File not found)
 "catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
 "Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
 "cpudrv" (cpudrv) - ? - C:\Programme\SystemRequirementsLab\cpudrv.sys  (File found, but it contains no detailed information)
 "i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
 "InCD File System" (InCDfs) - "Nero AG" - C:\WINDOWS\system32\drivers\InCDfs.sys
 "InCD Reader" (incdrm) - "Nero AG" - C:\WINDOWS\system32\drivers\incdrm.sys
 "InCDPass" (InCDPass) - "Nero AG" - C:\WINDOWS\System32\DRIVERS\InCDPass.sys
 "InCDrec" (InCDrec) - "Nero AG" - C:\WINDOWS\system32\drivers\InCDrec.sys
 "Kaspersky Lab KLMOUFLT" (klmouflt) - ? - C:\WINDOWS\System32\DRIVERS\klmouflt.sys  (File not found)
 "lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
 "MBAMSwissArmy" (MBAMSwissArmy) - "Malwarebytes Corporation" - C:\WINDOWS\system32\drivers\mbamswissarmy.sys
 "mbr" (mbr) - ? - C:\DOKUME~1\Karl\LOKALE~1\Temp\mbr.sys  (Hidden registry entry, rootkit activity | File not found)
 "NDIS-Systemtreiber" (NDIS) - ? - C:\WINDOWS\system32\drivers\NDIS.sys  (File found, but it contains no detailed information)
 "PCAMPR5 NDIS Protocol Driver" (PCAMPR5) - ? - C:\WINDOWS\system32\PCAMPR5.SYS  (File not found)
 "PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
 "PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
 "PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
 "PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
 "PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
 "PLCNDIS5 NDIS Protocol Driver" (PLCNDIS5) - "Intellon, Inc." - C:\WINDOWS\system32\plcndis5.sys
 "PQNTDrv" (PQNTDrv) - "PowerQuest Corporation" - C:\WINDOWS\system32\drivers\PQNTDrv.sys
 "PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\WINDOWS\System32\Drivers\PxHelp20.sys
 "pxrdqpog" (pxrdqpog) - ? - C:\DOKUME~1\Karl\LOKALE~1\Temp\pxrdqpog.sys  (Hidden registry entry, rootkit activity | File not found)
 "Secdrv" (Secdrv) - ? - C:\WINDOWS\System32\DRIVERS\secdrv.sys  (File signed by Microsoft | File found, but it contains no detailed information)
 "Spyware Terminator 2012 Realtime Shield Driver" (sp_rsdrv2) - ? - C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
 "StarForce Protection Environment Driver v6" (prodrv06) - "Protection Technology" - C:\WINDOWS\System32\drivers\prodrv06.sys
 "StarForce Protection Helper Driver" (sfhlp01) - "Protection Technology" - C:\WINDOWS\System32\drivers\sfhlp01.sys
 "StarForce Protection Helper Driver v2" (prohlp02) - "Protection Technology" - C:\WINDOWS\System32\drivers\prohlp02.sys
 "StarForce Protection Synchronization Driver v1" (prosync1) - "Protection Technology" - C:\WINDOWS\System32\drivers\prosync1.sys
 "T-Home Dialerschutz Hooking Treiber" (DFSYS) - ? - C:\Programme\NORTON 360\DFSYS.SYS  (File not found)
 "T-Home Dialerschutz VoIP Service" (SipIMNDI) - "T-Systems International GmbH" - C:\WINDOWS\System32\DRIVERS\SipIMNDI.sys
 "WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
 
 [Explorer]
 -----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
 {10880D85-AAD9-4558-ABDC-2AB1552D831F} "LightScribe Control Panel" - "Hewlett-Packard Company" - "C:\Programme\Gemeinsame Dateien\LightScribe\LSRunOnce.exe"
 {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
 -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
 {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
 -----( HKLM\Software\Classes\Protocols\Filter )-----
 {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
 -----( HKLM\Software\Classes\Protocols\Handler )-----
 {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
 {3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
 {23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - ? - F:\Programme\7-ZIP\7-zip.dll  (File not found)
 {6af09ec9-b429-11d4-a1fb-0090960218cb} "Bluetooth-Umgebung" - "Broadcom Corporation." - C:\WINDOWS\system32\btneighborhood.dll
 {42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll  (File not found)
 {1D2680C9-0E2A-469d-B787-065558BC7D43} "Fusion Cache" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - J:\itunes\iTunesMiniPlayer.dll
 {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -   (File not found | COM-object registry key not found)
 {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\OFFICE11\msohev.dll
 {7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\WINDOWS\system32\btncopy.dll
 {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Programme\Real\RealPlayer\rpshell.dll
 {7F67036B-66F1-411A-AD85-759FB9C5B0DB} "SampleView" - "XSS" - C:\WINDOWS\system32\ShellvRTF.dll
 {950FF917-7A57-46BC-8017-59D9BF474000} "Shell Extension for CDRW" - "Nero AG" - C:\Programme\Ahead\InCD\incdshx.dll
 {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -   (File not found | COM-object registry key not found)
 {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
 {764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -   (File not found | COM-object registry key not found)
 {e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
 {F32C83B9-DF1D-42AD-9741-C52909703957} "STShellHandler" - "Crawler.com" - C:\Programme\Spyware Terminator\STShell.dll
 {2F603045-309F-11CF-9774-0020AFD0CFF6} "Synaptics Control Panel" - ? -   (File not found | COM-object registry key not found)
 {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Web Folders" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\MSONSEXT.DLL
 {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Programme\WinRAR\rarext.dll  (File found, but it contains no detailed information)
 
 [Internet Explorer]
 -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
 {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} "Java Plug-in 1.6.0" - "Sun Microsystems, Inc." - C:\Programme\Java\jre1.6.0\bin\npjpi160.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
 {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
 {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
 {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx / hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} "SysInfo Class" - "Husdawg, LLC" - C:\Programme\SystemRequirementsLab\srldetect_intel_4.4.24.0.dll / hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab
 {5ED80217-570B-4DA9-BF44-BE107C0EC166} "Windows Live Safety Center Base Module" - "Microsoft Corporation" - C:\WINDOWS\Downloaded Program Files\wlscBase.dll / hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
 {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? -   (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
 -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
 "@btrez.dll,-4015" - ? - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
 "ICQ6" - "ICQ, Inc." - H:\Programme\ICQ\ICQ6\ICQ.exe
 "PokerStars.net" - "PokerStars" - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe
 "PPLive" - ? - H:\Video\TV Player\PPLive\PPLive.exe  (File found, but it contains no detailed information)
 {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
 {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 {DF21F1DB-80C6-11D3-9483-B03D0EC10000} "Credential Manager for HP ProtectTools" - "Bioscrypt Inc." - C:\Programme\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
 {326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
 {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
 {E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
 {055FD26D-3A88-4e15-963D-DC8493744B1D} "XTTBPos00 Class" - ? - C:\PROGRA~1\ICQTOO~1\toolbaru.dll  (File not found)
 
 [Logon]
 -----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
 "desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
 "BTTray.lnk" - "Broadcom Corporation." - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
 -----( %UserProfile%\Startmenü\Programme\Autostart )-----
 "desktop.ini" - ? - C:\Dokumente und Einstellungen\Karl\Startmenü\Programme\Autostart\desktop.ini
 -----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
 "LightScribe Control Panel" - "Hewlett-Packard Company" - C:\Programme\Gemeinsame Dateien\LightScribe\LightScribeControlPanel.exe -hidden
 "NBJ" - "Ahead Software AG" - "C:\Programme\Ahead\Nero BackItUp\NBJ.exe"
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
 "AccelerometerSysTrayApplet" - "Hewlett-Packard Corporation" - C:\WINDOWS\system32\AccelerometerSt.exe
 "Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
 "Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 "CognizanceTS" - "Cognizance Corporation" - rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
 "Corel Photo Downloader" - "Corel, Inc." - "C:\Programme\Gemeinsame Dateien\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
 "Cpqset" - ? - C:\Programme\Hewlett-Packard\Default Settings\cpqset.exe  (File found, but it contains no detailed information)
 "DivXUpdate" - ? - "C:\Programme\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
 "Google Desktop Search" - "Google" - "C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" /startup
 "HP Software Update" - "Hewlett-Packard" - C:\Programme\Hp\HP Software Update\HPWuSchd2.exe
 "hpWirelessAssistant" - "Hewlett-Packard Development Company, L.P." - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
 "InCD" - "Nero AG" - C:\Programme\Ahead\InCD\InCD.exe
 "iTunesHelper" - "Apple Inc." - "J:\itunes\iTunesHelper.exe"
 "NeroFilterCheck" - "Ahead Software Gmbh" - C:\WINDOWS\system32\NeroCheck.exe
 "PDF Complete" - "PDF Complete Inc" - "C:\Programme\PDF Complete\pdfsty.exe"
 "PTHOSTTR" - "Hewlett-Packard Development Company, L.P." - C:\Programme\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
 "QlbCtrl" - " Hewlett-Packard Development Company, L.P." - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
 "QuickTime Task" - "Apple Inc." - "C:\Programme\QuickTime\QTTask.exe" -atboottime
 "Recguard" - ? - C:\WINDOWS\Sminst\Recguard.exe
 "Reminder" - ? - C:\WINDOWS\Creator\Remind_XP.exe
 "Scheduler" - ? - C:\WINDOWS\SMINST\Scheduler.exe
 "SpywareTerminatorShield" - "Crawler.com" - C:\Programme\Spyware Terminator\SpywareTerminatorShield.exe
 "SpywareTerminatorUpdater" - "Crawler.com" - C:\Programme\Spyware Terminator\SpywareTerminatorUpdate.exe
 "SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe"
 "TkBellExe" - "RealNetworks, Inc." - "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe"  -osboot
 
 [Network Providers]
 -----( HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order )-----
 "Credential Manager" - "Cognizance Corporation" - C:\Programme\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
 
 [Print Monitors]
 -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
 "Bluetooth-Druckeranschluss" - "Broadcom Corporation." - C:\WINDOWS\system32\bthcrp.dll
 "Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll
 "PDFC" - "PDF Complete, Inc." - C:\WINDOWS\system32\pdfc_port.dll
 
 [Services]
 -----( HKLM\SYSTEM\CurrentControlSet\Services )-----
 ".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
 "Anmeldesitzungsbroker" (ASBroker) - "Cognizance Corporation" - C:\Programme\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
 "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 "ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
 "Automatisches LiveUpdate - Scheduler" (Automatisches LiveUpdate - Scheduler) - ? - "C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe"  (File not found)
 "Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
 "Canon Camera Access Library 8" (CCALib8) - "Canon Inc." - C:\Programme\Canon\CAL\CALMAIN.exe
 "Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Programme\Bonjour\mDNSResponder.exe
 "FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Programme\Gemeinsame Dateien\MAGIX Services\Database\bin\FABS.exe
 "Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Programme\Gemeinsame Dateien\MAGIX Services\Database\bin\fbserver.exe
 "Google Desktop Manager 5.9.1005.12335" (GoogleDesktopManager-051210-111108) - "Google" - C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe
 "hpqwmiex" (hpqwmiex) - "Hewlett-Packard Development Company, L.P." - C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe
 "InCD Helper" (InCDsrv) - "Nero AG" - C:\Programme\Ahead\InCD\InCDsrv.exe
 "InCD Helper (read only)" (InCDsrvR) - "Nero AG" - C:\Programme\Ahead\InCD\InCDsrv.exe
 "InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
 "iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Programme\iPod\bin\iPodService.exe
 "IviRegMgr" (IviRegMgr) - "InterVideo" - C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe
 "Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
 "LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
 "Lokaler Verbindungskanal" (ASChannel) - "Cognizance Corporation" - C:\Programme\Hewlett-Packard\IAM\Bin\ASChnl.dll
 "Office Source Engine" (ose) - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
 "PC Angel" (PCA) - "SoftThinks" - C:\WINDOWS\SMINST\PCAngel.exe
 "PC Tools Startup and Shutdown Monitor service" (PCToolsSSDMonitorSvc) - "PC Tools" - C:\Programme\Gemeinsame Dateien\PC Tools\sMonitor\StartManSvc.exe
 "PDF Document Manager" (pdfcDispatcher) - "PDF Complete Inc" - C:\Programme\PDF Complete\pdfsvc.exe
 "ProtexisLicensing" (ProtexisLicensing) - ? - C:\WINDOWS\system32\PSIService.exe
 "RoxMediaDB9" (RoxMediaDB9) - "Sonic Solutions" - c:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
 "Spyware Terminator 2012 Realtime Shield Service" (ST2012_Svc) - "Crawler.com" - C:\Programme\Spyware Terminator\st_rsser.exe
 "stllssvr" (stllssvr) - "MicroVision Development, Inc." - c:\Programme\Gemeinsame Dateien\SureThing Shared\stllssvr.exe
 "T-Home Dialerschutz Dienst" (DFSVC) - ? - C:\Programme\NORTON 360\DFInject.exe  (File not found)
 
 [Winlogon]
 -----( HKCU\Control Panel\IOProcs )-----
 "MVB" - ? - mvfs32.dll  (File not found)
 -----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
 {8F51D94E-8B89-4844-B15C-9C049BA0F49F} "DLLName" - "Cognizance Corporation" - C:\Programme\Hewlett-Packard\IAM\Bin\ItVCard.dll
 -----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
 "OneCard" - "Cognizance Corporation" - C:\Programme\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
 
 [Winsock Providers]
 -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
 "mdnsNSP" - "Apple Inc." - C:\Programme\Bonjour\mdnsNSP.dll
 
 ===[ Logfile end ]=========================================[ Logfile end ]===
 --- --- ---  
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]  
:wtf:  
. |