| M1600wner |  19.03.2011 16:31 |        GMER wollte nicht also hab ich es weggelassen. OSAM und MBR Check haben ihr Log brav ausgegeben. 
OSAM: 
OSAM Logfile:   Code:  
 Report of OSAM: Autorun Manager v5.0.11926.0 
hxxp://www.online-solutions.ru/en/ 
Saved at 16:28:08 on 19.03.2011   
OS: Windows Vista Business Edition Service Pack 2 (Build 6002), 32-bit 
Default Browser: Mozilla Corporation Firefox 3.6.15   
Scanner Settings 
[x] Rootkits detection (hidden registry) 
[x] Rootkits detection (hidden files) 
[x] Retrieve files information 
[x] Check Microsoft signatures   
Filters 
[ ] Trusted entries 
[ ] Empty entries 
[x] Hidden registry entries (rootkit activity) 
[x] Exclusively opened files 
[x] Not found files 
[x] Files without detailed information 
[x] Existing files 
[ ] Non-startable services 
[ ] Non-startable drivers 
[x] Active entries 
[x] Disabled entries     
[AppInit DLLs] 
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )----- 
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll 
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll 
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll 
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll 
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\system32\APSHook.dll   
[Common] 
-----( %SystemRoot%\Tasks )----- 
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe 
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe 
"GoogleUpdateTaskUserS-1-5-21-3126018047-4160642244-3195430115-1001Core.job" - "Google Inc." - C:\Users\Gamer-Pro\AppData\Local\Google\Update\GoogleUpdate.exe 
"GoogleUpdateTaskUserS-1-5-21-3126018047-4160642244-3195430115-1001UA.job" - "Google Inc." - C:\Users\Gamer-Pro\AppData\Local\Google\Update\GoogleUpdate.exe   
[Control Panel Objects] 
-----( %SystemRoot%\system32 )----- 
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl 
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )----- 
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl 
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl   
[Drivers] 
-----( HKLM\SYSTEM\CurrentControlSet\Services )----- 
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\Windows\system32\drivers\aswFsBlk.sys 
"aswMonFlt" (aswMonFlt) - "AVAST Software" - C:\Windows\system32\drivers\aswMonFlt.sys 
"aswRdr" (aswRdr) - "AVAST Software" - C:\Windows\system32\drivers\aswRdr.sys 
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys 
"aswSP" (aswSP) - "AVAST Software" - C:\Windows\system32\drivers\aswSP.sys 
"atca5ikv" (atca5ikv) - "Microsoft Corporation" - C:\Windows\system32\drivers\atca5ikv.sys  (Hidden registry entry, rootkit activity | File signed by Microsoft) 
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information) 
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\Windows\system32\drivers\aswTdi.sys 
"AVM Eject" (avmeject) - "AVM Berlin" - C:\Windows\System32\drivers\avmeject.sys 
"BDFsDrv" (BDFsDrv) - ? - C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys  (File not found) 
"BDRsDrv" (BDRsDrv) - ? - C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys  (File not found) 
"catchme" (catchme) - ? - C:\cofi.exe10029c\catchme.sys  (File not found) 
"DAMDrv" (DAMDrv) - "Hewlett-Packard Development Company L.P." - C:\Windows\System32\DRIVERS\DAMDrv.sys 
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys  (File not found) 
"EagleXNt" (EagleXNt) - ? - C:\Windows\system32\drivers\EagleXNt.sys  (File not found) 
"eamonm" (eamonm) - ? - C:\Windows\System32\DRIVERS\eamonm.sys  (File not found) 
"FSLX" (FSLX) - "Altiris, Inc." - C:\Windows\system32\drivers\fslx.sys 
"FsUsbExDisk" (FsUsbExDisk) - ? - C:\Windows\system32\FsUsbExDisk.SYS  (File found, but it contains no detailed information) 
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys 
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found) 
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found) 
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found) 
"ithsgt" (ithsgt) - ? - C:\Windows\System32\DRIVERS\ithsgt.sys  (File found, but it contains no detailed information) 
"kgldruoc" (kgldruoc) - ? - C:\Users\GAMER-~1\AppData\Local\Temp\kgldruoc.sys  (Hidden registry entry, rootkit activity | File not found) 
"lilsgt" (lilsgt) - ? - C:\Windows\System32\DRIVERS\lilsgt.sys  (File found, but it contains no detailed information) 
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information) 
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys 
"SbieDrv" (SbieDrv) - "SANDBOXIE L.T.D" - C:\Program Files\Sandboxie\SbieDrv.sys 
"sptd" (sptd) - "Duplex Secure Ltd." - C:\Windows\System32\Drivers\sptd.sys  (File is exclusively opened, access blocked) 
"VirtualBox USB" (VBoxUSB) - "Oracle Corporation" - C:\Windows\System32\Drivers\VBoxUSB.sys 
"vtany" (vtany) - ? - C:\Windows\vtany.sys  (File not found) 
"xhunter1" (xhunter1) - ? - C:\Windows\xhunter1.sys  (File not found) 
"xspirit" (xspirit) - ? - C:\Users\GAMER-~1\AppData\Local\Temp\xspirit.sys  (File found, but it contains no detailed information)   
[Explorer] 
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- 
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL 
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )----- 
{2C7339CF-2B09-4501-B3F3-F3508C9228ED} "Themes Setup" - "Microsoft Corporation" - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
-----( HKLM\Software\Classes\Protocols\Handler )----- 
{9462A756-7B47-47BC-8C80-C34B9B80B32B} "BackWeb GA Pluggable Protocol" - "Logitech Inc." - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll 
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL 
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL 
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL 
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )----- 
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? -   (File not found | COM-object registry key not found) 
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )----- 
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found) 
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found) 
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found) 
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Program Files\AVAST Software\Avast\ashShell.dll 
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found) 
{41E300E0-78B6-11ce-849B-444553540000} "Display Effects CPL Extension" - "Microsoft Corporation" - C:\Windows\system32\themeui.dll 
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found) 
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -   (File not found | COM-object registry key not found) 
{59850401-6664-101B-B21C-00AA004BA90B} "Microsoft Office Binder Unbind" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office\1031\UNBIND.DLL 
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll 
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found) 
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found) 
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -   (File not found | COM-object registry key not found) 
{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension" - ? - C:\Program Files\Unlocker\UnlockerCOM.dll  (File found, but it contains no detailed information) 
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe 
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe 
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll 
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll 
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll 
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe 
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll 
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found) 
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll 
{F9411A21-2B30-4B62-869E-FAFECA394FB3} "WinRezSh" - ? -   (File not found | COM-object registry key not found) 
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe   
[Internet Explorer] 
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )----- 
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found) 
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found) 
<binary data> "midicase Toolbar" - "Conduit Ltd." - C:\Program Files\midicase\prxtbmidi.dll 
<binary data> "{32099AAC-C132-4136-9E9A-4E364A424E17}" - ? -   (File not found | COM-object registry key not found) 
<binary data> "{C55BBCD6-41AD-48AD-9953-3609C48EACC7}" - ? -   (File not found | COM-object registry key not found) 
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )----- 
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab 
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab 
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab 
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} "Office Genuine Advantage Validation Tool" - ? - C:\Windows\system32\OGACheckControl.DLL / hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab 
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10i.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab 
{4944924A-64E4-49C1-AC97-ABA3927262FE} "StWbUsa Control" - "YNK" - C:\Windows\DOWNLO~1\StWbUsa.ocx / hxxp://channel.dontblynk.com/Launcher/StWbUsa.CAB 
{17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool" - "Microsoft Corporation" - C:\Windows\system32\LegitCheckControl.DLL / hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab 
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )----- 
<binary data> "avast! WebRep" - ? - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll 
{30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine" - "Conduit Ltd." - C:\Program Files\ConduitEngine\prxConduitEngine.dll 
{0BF43445-2F28-4351-9252-17FE6E806AA0} "McAfee SiteAdvisor" - ? -   (File not found | COM-object registry key not found) 
{6d8d66f3-14fc-4736-a096-fac0ea66289c} "midicase Toolbar" - "Conduit Ltd." - C:\Program Files\midicase\prxtbmidi.dll 
{29CF293A-1E7D-4069-9E11-E39698D0AF95} "QQ工具栏" - ? -   (File not found | COM-object registry key not found) 
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )----- 
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} "avast! WebRep" - ? - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll 
{3134413B-49B4-425C-98A5-893C1F195601} "BHO_Startup Class" - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll 
{30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine" - "Conduit Ltd." - C:\Program Files\ConduitEngine\prxConduitEngine.dll 
{DF21F1DB-80C6-11D3-9483-B03D0EC10000} "Credential Manager for HP ProtectTools" - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll 
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll 
{6d8d66f3-14fc-4736-a096-fac0ea66289c} "midicase Toolbar" - "Conduit Ltd." - C:\Program Files\midicase\prxtbmidi.dll 
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll 
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll   
[Logon] 
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )----- 
"desktop.ini" - ? - C:\Users\Gamer-Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini 
-----( %SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup )----- 
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini 
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )----- 
"avast" - "AVAST Software" - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui 
"AVMWlanClient" - "AVM Berlin" - C:\Program Files\avmwlanstick\wlangui.exe 
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" 
"TrayServer" - "MAGIX AG" - C:\Program Files\MAGIX\Video_deluxe_17_Premium_Download-Version\TrayServer.exe   
[Print Monitors] 
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )----- 
"PDFC" - "PDF Complete, Inc." - C:\Windows\system32\pdfc_port.dll   
[Services] 
-----( HKLM\SYSTEM\CurrentControlSet\Services )----- 
"@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000" (MatSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Fix it Center\Matsvc.exe 
"@%SystemRoot%\System32\shsvcs.dll,-12288" (ShellHWDetection) - "Microsoft Corporation" - C:\Windows\System32\shsvcs.dll 
"@%SystemRoot%\System32\shsvcs.dll,-8192" (Themes) - "Microsoft Corporation" - C:\Windows\system32\shsvcs.dll 
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 
"ActivClient Middleware Service" (accoca) - "ActivIdentity" - C:\Program Files\ActivIdentity\ActivClient\accoca.exe 
"Akamai NetSession Interface" (Akamai) - ? - c:\program files\common files\akamai\netsession_win_d76cf65.dll  (File found, but it contains no detailed information) 
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Program Files\AVAST Software\Avast\AvastSvc.exe 
"AVM WLAN Connection Service" (AVM WLAN Connection Service) - "AVM Berlin" - C:\Program Files\avmwlanstick\WlanNetService.exe 
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe 
"File Sanitizer for HP ProtectTools" (HPFSService) - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe 
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe 
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Acresso Software Inc." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe 
"HP ProtectTools Gerätesperre/Überwachung" (FLCDLOCK) - "Hewlett-Packard Ltd" - C:\Windows\system32\flcdlock.exe 
"HP ProtectTools Service" (HP ProtectTools Service) - "Hewlett-Packard Development Company, L.P" - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe 
"hpqwmiex" (hpqwmiex) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe 
"Intel(R) Active Management Technology Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files\Intel\AMT\LMS.exe 
"Intel(R) Active Management Technology User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe 
"LogMeIn Hamachi 2.0 Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe 
"Logon Session Broker" (ASBroker) - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll 
"Lokaler Verbindungskanal" (ASChannel) - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\AsChnl.dll 
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 
"McAfee Application Installer Cleanup (0065941272830566)" (0065941272830566mcinstcleanup) - ? - C:\Users\GAMER-~1\AppData\Local\Temp\006594~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service  (File not found) 
"McAfee-Dienst zum Schutz vor Viren und Spyware" (myAgtSvc) - ? - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe /ServiceStart  (File not found) 
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 
"nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des 
"PDF Document Manager" (pdfcDispatcher) - "PDF Complete Inc" - C:\Program Files\PDF Complete\pdfsvc.exe 
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File found, but it contains no detailed information) 
"Process Monitor" (LVPrcSrv) - "Logitech Inc." - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe 
"Sandboxie Service" (SbieSvc) - "SANDBOXIE L.T.D" - C:\Program Files\Sandboxie\SbieSvc.exe 
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe 
"TeamViewer 6" (TeamViewer6) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe 
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE   
[Winlogon] 
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )----- 
{8F51D94E-8B89-4844-B15C-9C049BA0F49F} "DLLName" - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\ItVCard.dll 
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )----- 
"DeviceNP" - "Hewlett-Packard Limited" - C:\Windows\system32\DeviceNP.dll   
===[ Logfile end ]=========================================[ Logfile end ]===   --- --- ---  
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]  
MBR:    Zitat:      
			
				MBRCheck, version 1.2.3 
(c) 2010, AD   
Command-line:			 
Windows Version:		Windows Vista Business Edition 
Windows Information:		Service Pack 2 (build 6002), 32-bit 
Base Board Manufacturer:	Hewlett-Packard 
BIOS Manufacturer:		Hewlett-Packard 
System Manufacturer:		Hewlett-Packard 
System Product Name:		HP Compaq dc7900 Small Form Factor 
Logical Drives Mask:		0x0000003c   
Kernel Drivers (total 155): 
  0x82435000 \SystemRoot\system32\ntkrnlpa.exe 
  0x82402000 \SystemRoot\system32\hal.dll 
  0x80409000 \SystemRoot\system32\kdcom.dll 
  0x80410000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 
  0x80480000 \SystemRoot\system32\PSHED.dll 
  0x80491000 \SystemRoot\system32\BOOTVID.dll 
  0x80499000 \SystemRoot\system32\CLFS.SYS 
  0x804DA000 \SystemRoot\system32\CI.dll 
  0x8060B000 \SystemRoot\system32\drivers\Wdf01000.sys 
  0x8067C000 \SystemRoot\system32\drivers\WDFLDR.SYS 
  0x8068A000 \SystemRoot\System32\Drivers\spea.sys 
  0x8077D000 \SystemRoot\System32\Drivers\WMILIB.SYS 
  0x80786000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 
  0x807AC000 \SystemRoot\system32\drivers\acpi.sys 
  0x807F2000 \SystemRoot\system32\drivers\msisadrv.sys 
  0x805BA000 \SystemRoot\system32\drivers\pci.sys 
  0x805E1000 \SystemRoot\System32\drivers\partmgr.sys 
  0x805F0000 \SystemRoot\system32\drivers\volmgr.sys 
  0x82A05000 \SystemRoot\System32\drivers\volmgrx.sys 
  0x82A4F000 \SystemRoot\system32\drivers\pciide.sys 
  0x82A56000 \SystemRoot\system32\drivers\PCIIDEX.SYS 
  0x82A64000 \SystemRoot\System32\drivers\mountmgr.sys 
  0x82A74000 \SystemRoot\system32\drivers\iastor.sys 
  0x82B4D000 \SystemRoot\system32\drivers\atapi.sys 
  0x82B55000 \SystemRoot\system32\drivers\ataport.SYS 
  0x82B73000 \SystemRoot\system32\drivers\fltmgr.sys 
  0x82BA5000 \SystemRoot\system32\drivers\fileinfo.sys 
  0x8B806000 \SystemRoot\System32\Drivers\ksecdd.sys 
  0x8B877000 \SystemRoot\system32\drivers\ndis.sys 
  0x8B982000 \SystemRoot\system32\drivers\msrpc.sys 
  0x8B9AD000 \SystemRoot\system32\drivers\NETIO.SYS 
  0x8BA0B000 \SystemRoot\System32\drivers\tcpip.sys 
  0x8BAF8000 \SystemRoot\System32\drivers\fwpkclnt.sys 
  0x8BC0E000 \SystemRoot\System32\Drivers\Ntfs.sys 
  0x8BD1E000 \SystemRoot\system32\drivers\volsnap.sys 
  0x8BD57000 \SystemRoot\System32\Drivers\spldr.sys 
  0x8BD5F000 \SystemRoot\System32\Drivers\mup.sys 
  0x8BD6E000 \SystemRoot\System32\drivers\ecache.sys 
  0x8BD95000 \SystemRoot\system32\drivers\disk.sys 
  0x8BDA6000 \SystemRoot\system32\drivers\CLASSPNP.SYS 
  0x8BDC7000 \SystemRoot\system32\drivers\crcdisk.sys 
  0x8BDDD000 \SystemRoot\system32\DRIVERS\tunnel.sys 
  0x8BDE8000 \SystemRoot\system32\DRIVERS\tunmp.sys 
  0x90001000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 
  0x9091E000 \SystemRoot\System32\drivers\dxgkrnl.sys 
  0x909BE000 \SystemRoot\System32\drivers\watchdog.sys 
  0x909CA000 \SystemRoot\system32\DRIVERS\HECI.sys 
  0x909D4000 \SystemRoot\system32\DRIVERS\serial.sys 
  0x909EE000 \SystemRoot\system32\DRIVERS\serenum.sys 
  0x82BB5000 \SystemRoot\system32\DRIVERS\e1k6032.sys 
  0x8BDF1000 \SystemRoot\system32\DRIVERS\usbuhci.sys 
  0x8FA00000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 
  0x8FA3E000 \SystemRoot\system32\DRIVERS\usbehci.sys 
  0x8FA4D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 
  0x8FADA000 \SystemRoot\system32\DRIVERS\i8042prt.sys 
  0x8FAED000 \SystemRoot\system32\DRIVERS\mouclass.sys 
  0x8FAF8000 \SystemRoot\system32\DRIVERS\kbdclass.sys 
  0x8FB03000 \SystemRoot\system32\DRIVERS\fdc.sys 
  0x8FB0E000 \SystemRoot\system32\drivers\tpm.sys 
  0x8FB1C000 \SystemRoot\system32\DRIVERS\cdrom.sys 
  0x8FB34000 \SystemRoot\System32\Drivers\atca5ikv.SYS 
  0x8FB6D000 \SystemRoot\system32\DRIVERS\intelppm.sys 
  0x8FB7C000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 
  0x8FB85000 \SystemRoot\system32\DRIVERS\msiscsi.sys 
  0x8FBB4000 \SystemRoot\system32\DRIVERS\storport.sys 
  0x8FBF5000 \SystemRoot\system32\DRIVERS\TDI.SYS 
  0x8B9E8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 
  0x8BC00000 \SystemRoot\system32\DRIVERS\ndistapi.sys 
  0x90C06000 \SystemRoot\system32\DRIVERS\ndiswan.sys 
  0x90C29000 \SystemRoot\system32\DRIVERS\raspppoe.sys 
  0x90C38000 \SystemRoot\system32\DRIVERS\raspptp.sys 
  0x90C4C000 \SystemRoot\system32\DRIVERS\rassstp.sys 
  0x90C61000 \SystemRoot\system32\DRIVERS\rdpdr.sys 
  0x90CEA000 \SystemRoot\system32\DRIVERS\termdd.sys 
  0x90CFA000 \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys 
  0x90D14000 \SystemRoot\system32\DRIVERS\swenum.sys 
  0x90D16000 \SystemRoot\system32\DRIVERS\ks.sys 
  0x90D40000 \SystemRoot\system32\DRIVERS\mssmbios.sys 
  0x90D4A000 \SystemRoot\system32\DRIVERS\umbus.sys 
  0x90D57000 \SystemRoot\system32\DRIVERS\usbhub.sys 
  0x90D8C000 \SystemRoot\System32\Drivers\NDProxy.SYS 
  0x90E0D000 \SystemRoot\system32\drivers\ADIHdAud.sys 
  0x90E6F000 \SystemRoot\system32\drivers\portcls.sys 
  0x90E9C000 \SystemRoot\system32\drivers\drmk.sys 
  0x90EC1000 \SystemRoot\System32\Drivers\aswSnx.SYS 
  0x90F1F000 \SystemRoot\system32\DRIVERS\fwlanusb.sys 
  0x90F60000 \SystemRoot\system32\DRIVERS\USBD.SYS 
  0x90F62000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 
  0x90F6B000 \SystemRoot\System32\Drivers\Null.SYS 
  0x90F72000 \SystemRoot\System32\Drivers\Beep.SYS 
  0x90F82000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 
  0x90F89000 \SystemRoot\System32\drivers\vga.sys 
  0x90F95000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 
  0x90FB6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 
  0x90FBE000 \SystemRoot\system32\drivers\rdpencdd.sys 
  0x90FC6000 \SystemRoot\System32\Drivers\Msfs.SYS 
  0x90FD1000 \SystemRoot\System32\Drivers\Npfs.SYS 
  0x90FDF000 \SystemRoot\System32\DRIVERS\rasacd.sys 
  0x90FE8000 \SystemRoot\system32\DRIVERS\tdx.sys 
  0x90E00000 \SystemRoot\System32\Drivers\aswTdi.SYS 
  0x90DA8000 \SystemRoot\system32\DRIVERS\smb.sys 
  0x90DBC000 \SystemRoot\System32\DRIVERS\netbt.sys 
  0x91402000 \SystemRoot\system32\drivers\afd.sys 
  0x9144A000 \SystemRoot\System32\Drivers\aswRdr.SYS 
  0x9144F000 \SystemRoot\system32\DRIVERS\pacer.sys 
  0x91465000 \SystemRoot\system32\DRIVERS\netbios.sys 
  0x91473000 \SystemRoot\system32\DRIVERS\wanarp.sys 
  0x91486000 \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys 
  0x9148F000 \SystemRoot\system32\DRIVERS\VBoxDrv.sys 
  0x914B1000 \SystemRoot\system32\DRIVERS\rdbss.sys 
  0x914ED000 \SystemRoot\system32\drivers\nsiproxy.sys 
  0x914F7000 \??\C:\Windows\system32\drivers\fslx.sys 
  0x91526000 \SystemRoot\system32\drivers\csc.sys 
  0x91581000 \SystemRoot\System32\Drivers\dfsc.sys 
  0x91598000 \SystemRoot\System32\Drivers\aswSP.SYS 
  0x915E0000 \SystemRoot\System32\Drivers\crashdmp.sys 
  0x8BB13000 \SystemRoot\System32\Drivers\dump_iaStor.sys 
  0x9A010000 \SystemRoot\System32\win32k.sys 
  0x915ED000 \SystemRoot\System32\drivers\Dxapi.sys 
  0x90DEE000 \SystemRoot\system32\DRIVERS\monitor.sys 
  0x9A230000 \SystemRoot\System32\TSDDD.dll 
  0x9A250000 \SystemRoot\System32\cdd.dll 
  0x9A260000 \SystemRoot\System32\ATMFD.DLL 
  0xACE05000 \SystemRoot\system32\drivers\luafv.sys 
  0xACE20000 \??\C:\Windows\system32\drivers\aswMonFlt.sys 
  0xACE58000 \SystemRoot\System32\Drivers\aswFsBlk.SYS 
  0xACE5B000 \SystemRoot\system32\drivers\spsys.sys 
  0xACF0B000 \??\C:\Program Files\Sandboxie\SbieDrv.sys 
  0xACF2C000 \SystemRoot\system32\DRIVERS\lltdio.sys 
  0xACF3C000 \SystemRoot\system32\DRIVERS\nwifi.sys 
  0xACF66000 \SystemRoot\system32\DRIVERS\ndisuio.sys 
  0xACF70000 \SystemRoot\system32\DRIVERS\rspndr.sys 
  0xACF83000 \SystemRoot\system32\drivers\HTTP.sys 
  0xB1004000 \SystemRoot\System32\DRIVERS\srvnet.sys 
  0xB1021000 \SystemRoot\system32\DRIVERS\bowser.sys 
  0xB103A000 \SystemRoot\System32\drivers\mpsdrv.sys 
  0xB104F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 
  0xB106E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 
  0xB10A7000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 
  0xB10BF000 \SystemRoot\System32\DRIVERS\srv2.sys 
  0xB10E7000 \SystemRoot\System32\DRIVERS\srv.sys 
  0xB1135000 \SystemRoot\system32\DRIVERS\atksgt.sys 
  0xB1178000 \SystemRoot\system32\DRIVERS\ithsgt.sys 
  0xB11A0000 \SystemRoot\system32\DRIVERS\lilsgt.sys 
  0xB11A3000 \SystemRoot\system32\DRIVERS\lirsgt.sys 
  0xB260C000 \SystemRoot\system32\drivers\peauth.sys 
  0xB26EA000 \SystemRoot\System32\Drivers\secdrv.SYS 
  0xB26F4000 \SystemRoot\System32\drivers\tcpipreg.sys 
  0xB2700000 \SystemRoot\system32\Drivers\LVPr2Mon.sys 
  0xB2705000 \SystemRoot\system32\DRIVERS\cdfs.sys 
  0xB271B000 \??\C:\Windows\system32\drivers\mbam.sys 
  0xB271F000 \??\C:\Users\GAMER-~1\AppData\Local\Temp\xspirit.sys 
  0xB27AE000 \??\C:\Users\GAMER-~1\AppData\Local\Temp\kgldruoc.sys 
  0x77C20000 \Windows\System32\ntdll.dll 
  0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll   
Processes (total 65): 
       0 System Idle Process 
       4 System 
     600 C:\Windows\System32\smss.exe 
     668 csrss.exe 
     712 C:\Windows\System32\wininit.exe 
     724 csrss.exe 
     756 C:\Windows\System32\services.exe 
     772 C:\Windows\System32\lsass.exe 
     796 C:\Windows\System32\winlogon.exe 
     816 C:\Windows\System32\lsm.exe 
     996 C:\Windows\System32\svchost.exe 
    1052 C:\Windows\System32\svchost.exe 
    1080 C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe 
    1120 C:\Windows\System32\svchost.exe 
    1248 C:\Windows\System32\svchost.exe 
    1284 C:\Windows\System32\svchost.exe 
    1324 C:\Windows\System32\svchost.exe 
    1416 C:\Windows\System32\audiodg.exe 
    1448 C:\Windows\System32\svchost.exe 
    1508 C:\Windows\System32\SLsvc.exe 
    1588 C:\Windows\System32\svchost.exe 
    1704 C:\Program Files\Sandboxie\SbieSvc.exe 
    1824 C:\Windows\System32\svchost.exe 
    1948 C:\Program Files\AVAST Software\Avast\AvastSvc.exe 
    1336 C:\Windows\System32\taskeng.exe 
    1408 C:\Windows\System32\spoolsv.exe 
    1676 C:\Windows\System32\svchost.exe 
    2136 C:\Program Files\ActivIdentity\ActivClient\accoca.exe 
    2168 C:\Windows\System32\AEADISRV.EXE 
    2220 C:\Windows\System32\svchost.exe 
    2240 C:\Program Files\ActivIdentity\ActivClient\acevents.exe 
    2248 C:\Program Files\avmwlanstick\WLanNetService.exe 
    2376 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe 
    2524 C:\Program Files\LogMeIn Hamachi\hamachi-2.exe 
    2552 C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe 
    2616 C:\Program Files\Intel\AMT\LMS.exe 
    2640 C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe 
    2680 C:\Program Files\PDF Complete\pdfsvc.exe 
    2724 C:\Windows\System32\PnkBstrA.exe 
    2784 C:\Windows\System32\svchost.exe 
    2812 C:\Windows\System32\svchost.exe 
    2924 C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe 
    2944 C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe 
    3000 C:\Windows\System32\svchost.exe 
    3028 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 
    3324 C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe 
    3336 WmiPrvSE.exe 
    3660 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 
    3816 C:\Windows\System32\taskeng.exe 
    2624 C:\Windows\System32\dwm.exe 
    2856 C:\Windows\explorer.exe 
    3600 C:\Program Files\Analog Devices\Core\smax4pnp.exe 
    2420 C:\Program Files\Windows Media Player\wmpnscfg.exe 
    1716 C:\Program Files\avmwlanstick\WLanGUI.exe 
    1236 C:\Program Files\Common Files\Java\Java Update\jusched.exe 
    2892 C:\Program Files\Windows Media Player\wmpnetwk.exe 
    4428 C:\Windows\System32\svchost.exe 
    5092 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 
    4196 C:\Program Files\Mozilla Firefox\firefox.exe 
    4284 WmiPrvSE.exe 
    4800 C:\Program Files\Mozilla Firefox\plugin-container.exe 
    5008 dllhost.exe 
    4052 dllhost.exe 
    5460 C:\Users\Gamer-Pro\Downloads\MBRCheck.exe 
    4472 C:\Windows\System32\conime.exe   
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000  (NTFS) 
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000039`bba00000  (NTFS)   
PhysicalDrive0 Model Number: ST3250310AS, Rev: 3.AHC      
      Size  Device Name          MBR Status 
  -------------------------------------------- 
    232 GB  \\.\PhysicalDrive0   Unknown MBR code 
            SHA1: C494D0E68EC43BD90D507D7433A09349C3E569C8     
Found non-standard or infected MBR. 
Enter 'Y' and hit ENTER for more options, or 'N' to exit:    
Done!
			
			   |          |