| 
 Moin, 
hier die gewünschten Logfiles.  
GMER - Logfile:   Code: 
 GMER 1.0.15.15530 - hxxp://www.gmer.netRootkit scan 2011-01-31 14:56:18
 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ExcelStor_Technology_J680 rev.V32OA60A
 Running: g2m3e4r.exe; Driver: D:\Temp\uxtdypob.sys
 
 
 ---- System - GMER 1.0.15 ----
 
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwAdjustPrivilegesToken [0xB6FAD5FA]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwClose [0xB6FADEFE]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwConnectPort [0xB6FAED32]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateEvent [0xB6FAF27C]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateFile [0xB6FAE1DA]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateKey [0xB6FAC46A]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateMutant [0xB6FAF162]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateNamedPipeFile [0xB6FAD1E8]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreatePort [0xB6FAF036]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateSection [0xB6FAD390]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateSemaphore [0xB6FAF39C]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateThread [0xB6FADB86]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwCreateWaitablePort [0xB6FAF0CC]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwDebugActiveProcess [0xB6FB0A84]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwDeleteKey [0xB6FACA74]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwDeleteValueKey [0xB6FACE28]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwDeviceIoControlFile [0xB6FAE65C]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwDuplicateObject [0xB6FB1C90]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwEnumerateKey [0xB6FACF74]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwEnumerateValueKey [0xB6FAD00C]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwFsControlFile [0xB6FAE46A]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwLoadDriver [0xB6FB0B76]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwLoadKey [0xB6FAC446]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwLoadKey2 [0xB6FAC458]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwMapViewOfSection [0xB6FB12DE]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwNotifyChangeKey [0xB6FAD138]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenEvent [0xB6FAF312]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenFile [0xB6FADF80]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenKey [0xB6FAC62A]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenMutant [0xB6FAF1F2]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenProcess [0xB6FAD836]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenSection [0xB6FB1078]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenSemaphore [0xB6FAF432]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwOpenThread [0xB6FAD728]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwQueryKey [0xB6FAD0A4]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwQueryMultipleValueKey [0xB6FACCDC]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwQuerySection [0xB6FB1618]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwQueryValueKey [0xB6FAC906]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwQueueApcThread [0xB6FB0F0A]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwRenameKey [0xB6FACB96]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwReplaceKey [0xB6FABE80]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwReplyPort [0xB6FAF796]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwReplyWaitReceivePort [0xB6FAF65C]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwRequestWaitReplyPort [0xB6FB081E]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwRestoreKey [0xB6FAC1F8]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwResumeThread [0xB6FB1B32]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSaveKey [0xB6FABE18]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSecureConnectPort [0xB6FAEA78]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSetContextThread [0xB6FADDA2]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSetInformationToken [0xB6FB00BE]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSetSecurityObject [0xB6FB0D14]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSetSystemInformation [0xB6FB1768]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSetValueKey [0xB6FAC780]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSuspendProcess [0xB6FB185A]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSuspendThread [0xB6FB1994]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwSystemDebugControl [0xB6FB09A8]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwTerminateProcess [0xB6FAD9D2]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwTerminateThread [0xB6FAD932]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwUnmapViewOfSection [0xB6FB14BC]
 SSDT            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  ZwWriteVirtualMemory [0xB6FADABC]
 
 Code            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  FsRtlCheckLockForReadAccess
 Code            \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)  IoIsOperationSynchronous
 
 ---- Kernel code sections - GMER 1.0.15 ----
 
 .text           ntoskrnl.exe!ZwYieldExecution + 1FA                                                    804E4A34 12 Bytes  [76, 0B, FB, B6, 46, C4, FA, ...]
 .text           ntoskrnl.exe!ZwYieldExecution + 376                                                    804E4BB0 16 Bytes  [96, CB, FA, B6, 80, BE, FA, ...]
 .text           ntoskrnl.exe!ZwYieldExecution + 3BE                                                    804E4BF8 4 Bytes  JMP FC4FB6FA
 .text           ntoskrnl.exe!ZwYieldExecution + 46A                                                    804E4CA4 12 Bytes  [5A, 18, FB, B6, 94, 19, FB, ...]
 .text           ntoskrnl.exe!IoIsOperationSynchronous                                                  804EAFAE 5 Bytes  JMP B6FA03C8 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
 .text           ntoskrnl.exe!FsRtlCheckLockForReadAccess                                               804F4593 5 Bytes  JMP B6F9FFEC \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
 
 ---- Kernel IAT/EAT - GMER 1.0.15 ----
 
 IAT             \SystemRoot\system32\DRIVERS\ipsec.sys[ntoskrnl.exe!IoCreateDevice]                    [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[ntoskrnl.exe!IoCreateDevice]                    [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject]                [F7051D50] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\ipnat.sys[ntoskrnl.exe!IoCreateDevice]                    [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\netbt.sys[ntoskrnl.exe!IoCreateDevice]                    [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject]                [F7051D50] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateDevice]                      [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\netbios.sys[ntoskrnl.exe!IoCreateDevice]                  [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IoCreateDevice]                    [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\System32\Drivers\Fips.SYS[ntoskrnl.exe!IoCreateDevice]                     [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\System32\Drivers\Cdfs.SYS[ntoskrnl.exe!IoCreateDevice]                     [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[ntoskrnl.exe!IoCreateDevice]                  [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\rspndr.sys[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\mrxdav.sys[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\System32\Drivers\ParVdm.SYS[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateDevice]                      [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\drivers\wdmaud.sys[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\drivers\sysaudio.sys[ntoskrnl.exe!IoCreateDevice]                 [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\System32\Drivers\HTTP.sys[ntoskrnl.exe!IoCreateDevice]                     [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 IAT             \SystemRoot\system32\drivers\kmixer.sys[ntoskrnl.exe!IoCreateDevice]                   [F7051C00] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 
 ---- Devices - GMER 1.0.15 ----
 
 AttachedDevice  \Driver\Tcpip \Device\Ip                                                               kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 AttachedDevice  \Driver\Tcpip \Device\Tcp                                                              kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 AttachedDevice  \Driver\Tcpip \Device\Udp                                                              kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 AttachedDevice  \Driver\Tcpip \Device\RawIp                                                            kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
 
 ---- EOF - GMER 1.0.15 ----
 OSAM - Logfile:   Code: 
 Report of OSAM: Autorun Manager v5.0.11926.0hxxp://www.online-solutions.ru/en/
 Saved at 15:08:14 on 31.01.2011
 
 OS: Windows XP Professional Service Pack 3 (Build 2600)
 Default Browser: Mozilla Corporation Firefox 3.6.13
 
 Scanner Settings
 [x] Rootkits detection (hidden registry)
 [x] Rootkits detection (hidden files)
 [x] Retrieve files information
 [x] Check Microsoft signatures
 
 Filters
 [ ] Trusted entries
 [ ] Empty entries
 [x] Hidden registry entries (rootkit activity)
 [x] Exclusively opened files
 [x] Not found files
 [x] Files without detailed information
 [x] Existing files
 [ ] Non-startable services
 [ ] Non-startable drivers
 [x] Active entries
 [x] Disabled entries
 
 
 [Common]
 -----( %SystemRoot%\Tasks )-----
 "AppleSoftwareUpdate.job" - "Apple Inc." - D:\Programme\Apple Software Update\SoftwareUpdate.exe
 
 [Control Panel Objects]
 -----( %SystemRoot%\system32 )-----
 "infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
 "javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
 "wuaucpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\wuaucpl.cpl
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
 "QuickTime" - "Apple Inc." - D:\Programme\QuickTime\QTSystem\QuickTime.cpl
 
 [Drivers]
 -----( HKLM\SYSTEM\CurrentControlSet\Services )-----
 "Aspi32" (Aspi32) - "Adaptec" - C:\WINDOWS\system32\drivers\Aspi32.sys
 "catchme" (catchme) - ? - D:\Temp\catchme.sys  (File not found)
 "Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys  (File not found)
 "Crash Dump Driver" (DumpDrv) - ? - C:\WINDOWS\system32\drivers\DumpDrv.sys  (File not found)
 "i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys  (File not found)
 "lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys  (File not found)
 "PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys  (File not found)
 "PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys  (File not found)
 "PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys  (File not found)
 "PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys  (File not found)
 "PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys  (File not found)
 "StarOpen" (StarOpen) - ? - C:\WINDOWS\system32\drivers\StarOpen.sys  (File found, but it contains no detailed information)
 "TCP/IP-Protokolltreiber" (Tcpip) - "Microsoft Corporation" - C:\WINDOWS\System32\DRIVERS\tcpip.sys
 "uxtdypob" (uxtdypob) - ? - D:\Temp\uxtdypob.sys  (Hidden registry entry, rootkit activity | File not found)
 "WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys  (File not found)
 
 [Explorer]
 -----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
 {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
 -----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
 {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - D:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
 -----( HKLM\Software\Classes\Protocols\Filter )-----
 {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
 {807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - D:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
 -----( HKLM\Software\Classes\Protocols\Handler )-----
 {32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - D:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
 {23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - D:\Programme\7-Zip\7-zip.dll
 {5F327514-6C5E-4d60-8F16-D07FA08A78ED} "Auto Update Property Sheet Extension" - "Microsoft Corporation" - C:\WINDOWS\system32\wuaucpl.cpl
 {42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll  (File not found)
 {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - D:\Programme\iTunes\iTunesMiniPlayer.dll
 {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? -   (File not found | COM-object registry key not found)
 {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - D:\Programme\Microsoft Office\OFFICE11\msohev.dll
 {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - D:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
 {00020D75-0000-0000-C000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - D:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL
 {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - D:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll
 {0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - D:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL
 {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -   (File not found | COM-object registry key not found)
 {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
 {764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? -   (File not found | COM-object registry key not found)
 {e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - C:\WINDOWS\system32\dfshim.dll
 {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - D:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
 
 [Internet Explorer]
 -----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
 <binary data> "ITBarLayout" - ? -   (File not found | COM-object registry key not found)
 -----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
 {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_16" - "Sun Microsystems, Inc." - D:\Programme\Java\jre6\bin\npjpi160_16.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
 {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} "Java Plug-in 1.6.0_16" - "Sun Microsystems, Inc." - D:\Programme\Java\jre6\bin\npjpi160_16.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_16" - "Sun Microsystems, Inc." - D:\Programme\Java\jre6\bin\npjpi160_16.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
 -----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
 {4248FE82-7FCB-46AC-B270-339F08212110} "&Virtuelle Tastatur" - "Kaspersky Lab ZAO" - D:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
 {CCF151D8-D089-449F-A5A4-D9909053F20F} "Li&nks untersuchen" - "Kaspersky Lab ZAO" - D:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
 {FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
 {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - D:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
 {E33CF602-D945-461A-83F0-819F76A199F8} "FilterBHO Class" - "Kaspersky Lab ZAO" - D:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
 {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} "IEVkbdBHO Class" - "Kaspersky Lab ZAO" - D:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
 {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - D:\Programme\Java\jre6\bin\jp2ssv.dll
 {E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - D:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
 
 [Logon]
 -----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
 "desktop.ini" - ? - D:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
 -----( %UserProfile%\Startmenü\Programme\Autostart )-----
 "desktop.ini" - ? - D:\Dokumente und Einstellungen\Speedy\Startmenü\Programme\Autostart\desktop.ini
 -----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
 "Adobe ARM" - "Adobe Systems Incorporated" - "D:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
 "Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "D:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
 "avp" - "Kaspersky Lab ZAO" - "D:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
 "FreePDF Assistant" - "shbox.de" - D:\Programme\FreePDF_XP\fpassist.exe
 "iTunesHelper" - "Apple Inc." - "D:\Programme\iTunes\iTunesHelper.exe"
 "QuickTime Task" - "Apple Inc." - "D:\Programme\QuickTime\QTTask.exe" -atboottime
 
 [Print Monitors]
 -----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
 "Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\WINDOWS\system32\mdimon.dll
 "Redirected Port" - ? - C:\WINDOWS\system32\redmonnt.dll  (File found, but it contains no detailed information)
 
 [Services]
 -----( HKLM\SYSTEM\CurrentControlSet\Services )-----
 ".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
 "Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - D:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 "ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
 "Automatische Updates" (wuauserv) - "Microsoft Corporation" - C:\WINDOWS\system32\wuauserv.dll
 "Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - D:\Programme\Bonjour\mDNSResponder.exe
 "iPod-Dienst" (iPod Service) - "Apple Inc." - D:\Programme\iPod\bin\iPodService.exe
 "Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - D:\Programme\Java\jre6\bin\jqs.exe
 "Kaspersky Anti-Virus Service" (AVP) - "Kaspersky Lab ZAO" - D:\Programme\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
 "NMSAccess" (NMSAccess) - ? - D:\Programme\CDBurnerXP\NMSAccessU.exe  (File found, but it contains no detailed information)
 "Office Source Engine" (ose) - "Microsoft Corporation" - D:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE
 "Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
 "Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
 
 [Winlogon]
 -----( HKCU\Control Panel\IOProcs )-----
 "MVB" - ? - mvfs32.dll  (File not found)
 -----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
 "klogon" - "Kaspersky Lab ZAO" - C:\WINDOWS\system32\klogon.dll
 
 [Winsock Providers]
 -----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
 "mdnsNSP" - "Apple Inc." - D:\Programme\Bonjour\mdnsNSP.dll
 
 ===[ Logfile end ]=========================================[ Logfile end ]===
 MBRCheck -Logfile:   Code: 
 MBRCheck, version 1.2.3(c) 2010, AD
 
 Command-line:
 Windows Version:                Windows XP Professional
 Windows Information:                Service Pack 3 (build 2600)
 Logical Drives Mask:                0x0000003c
 
 Kernel Drivers (total 120):
 0x804D7000 \WINDOWS\system32\ntoskrnl.exe
 0x80700000 \WINDOWS\system32\hal.dll
 0xF7C0C000 \WINDOWS\system32\KDCOM.DLL
 0xF7B1C000 \WINDOWS\system32\BOOTVID.dll
 0xF76BC000 ACPI.sys
 0xF7C0E000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
 0xF76AB000 pci.sys
 0xF770C000 isapnp.sys
 0xF7CD4000 pciide.sys
 0xF798C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
 0xF771C000 MountMgr.sys
 0xF768C000 ftdisk.sys
 0xF7C10000 dmload.sys
 0xF7666000 dmio.sys
 0xF7994000 PartMgr.sys
 0xF772C000 VolSnap.sys
 0xF764E000 atapi.sys
 0xF773C000 disk.sys
 0xF774C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
 0xF762E000 fltMgr.sys
 0xF761C000 sr.sys
 0xF7605000 KSecDD.sys
 0xF7578000 Ntfs.sys
 0xF754B000 NDIS.sys
 0xF775C000 uagp35.sys
 0xF7531000 Mup.sys
 0xF700F000 kl1.sys
 0xF77CC000 \SystemRoot\system32\DRIVERS\intelppm.sys
 0xF6F00000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
 0xF6EEC000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
 0xF6ED8000 \SystemRoot\system32\DRIVERS\parport.sys
 0xF77DC000 \SystemRoot\system32\DRIVERS\serial.sys
 0xF7BA8000 \SystemRoot\system32\DRIVERS\serenum.sys
 0xF77EC000 \SystemRoot\system32\DRIVERS\i8042prt.sys
 0xF79DC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
 0xF77FC000 \SystemRoot\system32\DRIVERS\klmouflt.sys
 0xF79E4000 \SystemRoot\system32\DRIVERS\mouclass.sys
 0xF7BAC000 \SystemRoot\system32\DRIVERS\gameenum.sys
 0xF780C000 \SystemRoot\system32\DRIVERS\cdrom.sys
 0xF781C000 \SystemRoot\system32\DRIVERS\redbook.sys
 0xF6E93000 \SystemRoot\system32\DRIVERS\ks.sys
 0xF79EC000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
 0xF782C000 \SystemRoot\system32\DRIVERS\imapi.sys
 0xF6E05000 \SystemRoot\system32\drivers\smwdm.sys
 0xF6DE1000 \SystemRoot\system32\drivers\portcls.sys
 0xF783C000 \SystemRoot\system32\drivers\drmk.sys
 0xF7C18000 \SystemRoot\system32\drivers\aeaudio.sys
 0xF79F4000 \SystemRoot\system32\DRIVERS\usbohci.sys
 0xF6DBD000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
 0xF79FC000 \SystemRoot\system32\DRIVERS\usbehci.sys
 0xF7A04000 \SystemRoot\system32\DRIVERS\sisnic.sys
 0xF784C000 \SystemRoot\system32\DRIVERS\klim5.sys
 0xF7D0A000 \SystemRoot\system32\DRIVERS\audstub.sys
 0xF7C1A000 \SystemRoot\System32\Drivers\RootMdm.sys
 0xF7A0C000 \SystemRoot\System32\Drivers\Modem.SYS
 0xF785C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
 0xF7BBC000 \SystemRoot\system32\DRIVERS\ndistapi.sys
 0xF6DA6000 \SystemRoot\system32\DRIVERS\ndiswan.sys
 0xF786C000 \SystemRoot\system32\DRIVERS\raspppoe.sys
 0xF787C000 \SystemRoot\system32\DRIVERS\raspptp.sys
 0xF7A14000 \SystemRoot\system32\DRIVERS\TDI.SYS
 0xF6D94000 \SystemRoot\system32\DRIVERS\psched.sys
 0xF788C000 \SystemRoot\system32\DRIVERS\msgpc.sys
 0xF7A1C000 \SystemRoot\system32\DRIVERS\ptilink.sys
 0xF7A24000 \SystemRoot\system32\DRIVERS\raspti.sys
 0xF7A2C000 \SystemRoot\system32\DRIVERS\RimSerial.sys
 0xF6CC4000 \SystemRoot\system32\DRIVERS\rdpdr.sys
 0xF789C000 \SystemRoot\system32\DRIVERS\termdd.sys
 0xF7C1C000 \SystemRoot\system32\DRIVERS\swenum.sys
 0xF6C3E000 \SystemRoot\system32\DRIVERS\update.sys
 0xF7BD8000 \SystemRoot\system32\DRIVERS\mssmbios.sys
 0xF78AC000 \SystemRoot\System32\Drivers\NDProxy.SYS
 0xF78FC000 \SystemRoot\system32\DRIVERS\usbhub.sys
 0xF7C20000 \SystemRoot\system32\DRIVERS\USBD.SYS
 0xB6F81000 \SystemRoot\system32\DRIVERS\klif.sys
 0xF6FEB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
 0xF7D8B000 \SystemRoot\System32\Drivers\Null.SYS
 0xF7C22000 \SystemRoot\System32\Drivers\Beep.SYS
 0xF7A4C000 \SystemRoot\System32\drivers\vga.sys
 0xF7C24000 \SystemRoot\System32\Drivers\mnmdd.SYS
 0xF7C26000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
 0xF7A54000 \SystemRoot\System32\Drivers\Msfs.SYS
 0xF7A5C000 \SystemRoot\System32\Drivers\Npfs.SYS
 0xF6FE7000 \SystemRoot\system32\DRIVERS\rasacd.sys
 0xF7A64000 \SystemRoot\system32\DRIVERS\kl2.sys
 0xB6F26000 \SystemRoot\system32\DRIVERS\ipsec.sys
 0xB6ECD000 \SystemRoot\system32\DRIVERS\tcpip.sys
 0xB6EA7000 \SystemRoot\system32\DRIVERS\ipnat.sys
 0xB6E7F000 \SystemRoot\system32\DRIVERS\netbt.sys
 0xF790C000 \SystemRoot\system32\DRIVERS\wanarp.sys
 0xB6E5D000 \SystemRoot\System32\drivers\afd.sys
 0xF791C000 \SystemRoot\system32\DRIVERS\netbios.sys
 0xB6E0A000 \SystemRoot\system32\DRIVERS\rdbss.sys
 0xB6D9A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
 0xF792C000 \SystemRoot\System32\Drivers\Fips.SYS
 0xF6CA8000 \SystemRoot\System32\Drivers\Aspi32.SYS
 0xF797C000 \SystemRoot\System32\Drivers\Cdfs.SYS
 0xB6CE2000 \SystemRoot\System32\Drivers\dump_atapi.sys
 0xF7C34000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
 0xBF800000 \SystemRoot\System32\win32k.sys
 0xF6C16000 \SystemRoot\System32\drivers\Dxapi.sys
 0xF7A74000 \SystemRoot\System32\watchdog.sys
 0xBF9C6000 \SystemRoot\System32\drivers\dxg.sys
 0xF7E0B000 \SystemRoot\System32\drivers\dxgthk.sys
 0xBF9D8000 \SystemRoot\System32\ati2dvag.dll
 0xBFA0E000 \SystemRoot\System32\ati2cqag.dll
 0xBFA46000 \SystemRoot\System32\ati3duag.dll
 0xBFC14000 \SystemRoot\System32\ativvaxx.dll
 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
 0xB6BD6000 \SystemRoot\system32\DRIVERS\ndisuio.sys
 0xB6CFA000 \SystemRoot\system32\DRIVERS\rspndr.sys
 0xB6946000 \SystemRoot\system32\DRIVERS\mrxdav.sys
 0xF7CA0000 \SystemRoot\System32\Drivers\ParVdm.SYS
 0xB68A4000 \SystemRoot\system32\DRIVERS\srv.sys
 0xB638F000 \SystemRoot\system32\drivers\wdmaud.sys
 0xB69CA000 \SystemRoot\system32\drivers\sysaudio.sys
 0xB60C8000 \SystemRoot\System32\Drivers\HTTP.sys
 0xB5F85000 \SystemRoot\system32\drivers\kmixer.sys
 0xB5E55000 \??\D:\Temp\uxtdypob.sys
 0x7C910000 \WINDOWS\system32\ntdll.dll
 
 Processes (total 26):
 0 System Idle Process
 4 System
 716 C:\WINDOWS\system32\smss.exe
 764 csrss.exe
 788 C:\WINDOWS\system32\winlogon.exe
 832 C:\WINDOWS\system32\services.exe
 844 C:\WINDOWS\system32\lsass.exe
 996 C:\WINDOWS\system32\svchost.exe
 1116 svchost.exe
 1156 C:\WINDOWS\system32\svchost.exe
 1300 svchost.exe
 1328 svchost.exe
 1500 C:\WINDOWS\system32\BRSVC01A.EXE
 1524 C:\WINDOWS\system32\BRSS01A.EXE
 1536 C:\WINDOWS\system32\spoolsv.exe
 1596 svchost.exe
 1632 D:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 1684 D:\Programme\Bonjour\mDNSResponder.exe
 1744 D:\Programme\CDBurnerXP\NMSAccessU.exe
 484 alg.exe
 2436 C:\WINDOWS\system32\wscntfy.exe
 2452 C:\WINDOWS\explorer.exe
 2540 D:\Programme\FreePDF_XP\fpassist.exe
 2564 D:\Programme\iTunes\iTunesHelper.exe
 2880 D:\Programme\iPod\bin\iPodService.exe
 1772 D:\Dokumente und Einstellungen\Speedy\Desktop\MBRCheck.exe
 
 \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00  (NTFS)
 \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000005`0092e600  (NTFS)
 
 PhysicalDrive0 Model Number: ExcelStorTechnologyJ680, Rev: V32OA60A
 
 Size  Device Name          MBR Status
 --------------------------------------------
 76 GB  \\.\PhysicalDrive0   Windows XP MBR code detected
 SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11
 
 
 Done!
 Ist es dir eigentlich lieber den Code zu posten oder ist es auch ok die Logs als Text-File anzuhängen, wie ich es anfangs gemacht habe?  
Grüsse |