M1600wner | 19.03.2011 16:31 | GMER wollte nicht also hab ich es weggelassen. OSAM und MBR Check haben ihr Log brav ausgegeben.
OSAM:
OSAM Logfile: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:28:08 on 19.03.2011
OS: Windows Vista Business Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.15
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\System32\APSHook.dll
"AppInit_DLLs" - "Bioscrypt Inc." - C:\Windows\system32\APSHook.dll
[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-3126018047-4160642244-3195430115-1001Core.job" - "Google Inc." - C:\Users\Gamer-Pro\AppData\Local\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-3126018047-4160642244-3195430115-1001UA.job" - "Google Inc." - C:\Users\Gamer-Pro\AppData\Local\Google\Update\GoogleUpdate.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\Windows\system32\drivers\aswFsBlk.sys
"aswMonFlt" (aswMonFlt) - "AVAST Software" - C:\Windows\system32\drivers\aswMonFlt.sys
"aswRdr" (aswRdr) - "AVAST Software" - C:\Windows\system32\drivers\aswRdr.sys
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys
"aswSP" (aswSP) - "AVAST Software" - C:\Windows\system32\drivers\aswSP.sys
"atca5ikv" (atca5ikv) - "Microsoft Corporation" - C:\Windows\system32\drivers\atca5ikv.sys (Hidden registry entry, rootkit activity | File signed by Microsoft)
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys (File found, but it contains no detailed information)
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\Windows\system32\drivers\aswTdi.sys
"AVM Eject" (avmeject) - "AVM Berlin" - C:\Windows\System32\drivers\avmeject.sys
"BDFsDrv" (BDFsDrv) - ? - C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys (File not found)
"BDRsDrv" (BDRsDrv) - ? - C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys (File not found)
"catchme" (catchme) - ? - C:\cofi.exe10029c\catchme.sys (File not found)
"DAMDrv" (DAMDrv) - "Hewlett-Packard Development Company L.P." - C:\Windows\System32\DRIVERS\DAMDrv.sys
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found)
"EagleXNt" (EagleXNt) - ? - C:\Windows\system32\drivers\EagleXNt.sys (File not found)
"eamonm" (eamonm) - ? - C:\Windows\System32\DRIVERS\eamonm.sys (File not found)
"FSLX" (FSLX) - "Altiris, Inc." - C:\Windows\system32\drivers\fslx.sys
"FsUsbExDisk" (FsUsbExDisk) - ? - C:\Windows\system32\FsUsbExDisk.SYS (File found, but it contains no detailed information)
"Hamachi Network Interface" (hamachi) - "LogMeIn, Inc." - C:\Windows\System32\DRIVERS\hamachi.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found)
"ithsgt" (ithsgt) - ? - C:\Windows\System32\DRIVERS\ithsgt.sys (File found, but it contains no detailed information)
"kgldruoc" (kgldruoc) - ? - C:\Users\GAMER-~1\AppData\Local\Temp\kgldruoc.sys (Hidden registry entry, rootkit activity | File not found)
"lilsgt" (lilsgt) - ? - C:\Windows\System32\DRIVERS\lilsgt.sys (File found, but it contains no detailed information)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"SbieDrv" (SbieDrv) - "SANDBOXIE L.T.D" - C:\Program Files\Sandboxie\SbieDrv.sys
"sptd" (sptd) - "Duplex Secure Ltd." - C:\Windows\System32\Drivers\sptd.sys (File is exclusively opened, access blocked)
"VirtualBox USB" (VBoxUSB) - "Oracle Corporation" - C:\Windows\System32\Drivers\VBoxUSB.sys
"vtany" (vtany) - ? - C:\Windows\vtany.sys (File not found)
"xhunter1" (xhunter1) - ? - C:\Windows\xhunter1.sys (File not found)
"xspirit" (xspirit) - ? - C:\Users\GAMER-~1\AppData\Local\Temp\xspirit.sys (File found, but it contains no detailed information)
[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{2C7339CF-2B09-4501-B3F3-F3508C9228ED} "Themes Setup" - "Microsoft Corporation" - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{9462A756-7B47-47BC-8C80-C34B9B80B32B} "BackWeb GA Pluggable Protocol" - "Logitech Inc." - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Program Files\AVAST Software\Avast\ashShell.dll
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{41E300E0-78B6-11ce-849B-444553540000} "Display Effects CPL Extension" - "Microsoft Corporation" - C:\Windows\system32\themeui.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{59850401-6664-101B-B21C-00AA004BA90B} "Microsoft Office Binder Unbind" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office\1031\UNBIND.DLL
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? - (File not found | COM-object registry key not found)
{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension" - ? - C:\Program Files\Unlocker\UnlockerCOM.dll (File found, but it contains no detailed information)
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{F9411A21-2B30-4B62-869E-FAFECA394FB3} "WinRezSh" - ? - (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "midicase Toolbar" - "Conduit Ltd." - C:\Program Files\midicase\prxtbmidi.dll
<binary data> "{32099AAC-C132-4136-9E9A-4E364A424E17}" - ? - (File not found | COM-object registry key not found)
<binary data> "{C55BBCD6-41AD-48AD-9953-3609C48EACC7}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} "Office Genuine Advantage Validation Tool" - ? - C:\Windows\system32\OGACheckControl.DLL / hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10i.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
{4944924A-64E4-49C1-AC97-ABA3927262FE} "StWbUsa Control" - "YNK" - C:\Windows\DOWNLO~1\StWbUsa.ocx / hxxp://channel.dontblynk.com/Launcher/StWbUsa.CAB
{17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool" - "Microsoft Corporation" - C:\Windows\system32\LegitCheckControl.DLL / hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "avast! WebRep" - ? - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
{30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine" - "Conduit Ltd." - C:\Program Files\ConduitEngine\prxConduitEngine.dll
{0BF43445-2F28-4351-9252-17FE6E806AA0} "McAfee SiteAdvisor" - ? - (File not found | COM-object registry key not found)
{6d8d66f3-14fc-4736-a096-fac0ea66289c} "midicase Toolbar" - "Conduit Ltd." - C:\Program Files\midicase\prxtbmidi.dll
{29CF293A-1E7D-4069-9E11-E39698D0AF95} "QQ工具栏" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} "avast! WebRep" - ? - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
{3134413B-49B4-425C-98A5-893C1F195601} "BHO_Startup Class" - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
{30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine" - "Conduit Ltd." - C:\Program Files\ConduitEngine\prxConduitEngine.dll
{DF21F1DB-80C6-11D3-9483-B03D0EC10000} "Credential Manager for HP ProtectTools" - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{6d8d66f3-14fc-4736-a096-fac0ea66289c} "midicase Toolbar" - "Conduit Ltd." - C:\Program Files\midicase\prxtbmidi.dll
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Gamer-Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avast" - "AVAST Software" - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"AVMWlanClient" - "AVM Berlin" - C:\Program Files\avmwlanstick\wlangui.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"TrayServer" - "MAGIX AG" - C:\Program Files\MAGIX\Video_deluxe_17_Premium_Download-Version\TrayServer.exe
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PDFC" - "PDF Complete, Inc." - C:\Windows\system32\pdfc_port.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000" (MatSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft Fix it Center\Matsvc.exe
"@%SystemRoot%\System32\shsvcs.dll,-12288" (ShellHWDetection) - "Microsoft Corporation" - C:\Windows\System32\shsvcs.dll
"@%SystemRoot%\System32\shsvcs.dll,-8192" (Themes) - "Microsoft Corporation" - C:\Windows\system32\shsvcs.dll
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"ActivClient Middleware Service" (accoca) - "ActivIdentity" - C:\Program Files\ActivIdentity\ActivClient\accoca.exe
"Akamai NetSession Interface" (Akamai) - ? - c:\program files\common files\akamai\netsession_win_d76cf65.dll (File found, but it contains no detailed information)
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
"AVM WLAN Connection Service" (AVM WLAN Connection Service) - "AVM Berlin" - C:\Program Files\avmwlanstick\WlanNetService.exe
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"File Sanitizer for HP ProtectTools" (HPFSService) - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Acresso Software Inc." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP ProtectTools Gerätesperre/Überwachung" (FLCDLOCK) - "Hewlett-Packard Ltd" - C:\Windows\system32\flcdlock.exe
"HP ProtectTools Service" (HP ProtectTools Service) - "Hewlett-Packard Development Company, L.P" - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
"hpqwmiex" (hpqwmiex) - "Hewlett-Packard Development Company, L.P." - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"Intel(R) Active Management Technology Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files\Intel\AMT\LMS.exe
"Intel(R) Active Management Technology User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
"LogMeIn Hamachi 2.0 Tunneling Engine" (Hamachi2Svc) - "LogMeIn Inc." - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
"Logon Session Broker" (ASBroker) - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
"Lokaler Verbindungskanal" (ASChannel) - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\AsChnl.dll
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"McAfee Application Installer Cleanup (0065941272830566)" (0065941272830566mcinstcleanup) - ? - C:\Users\GAMER-~1\AppData\Local\Temp\006594~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service (File not found)
"McAfee-Dienst zum Schutz vor Viren und Spyware" (myAgtSvc) - ? - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe /ServiceStart (File not found)
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des
"PDF Document Manager" (pdfcDispatcher) - "PDF Complete Inc" - C:\Program Files\PDF Complete\pdfsvc.exe
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe (File found, but it contains no detailed information)
"Process Monitor" (LVPrcSrv) - "Logitech Inc." - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
"Sandboxie Service" (SbieSvc) - "SANDBOXIE L.T.D" - C:\Program Files\Sandboxie\SbieSvc.exe
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"TeamViewer 6" (TeamViewer6) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
[Winlogon]
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
{8F51D94E-8B89-4844-B15C-9C049BA0F49F} "DLLName" - "Bioscrypt Inc." - C:\Program Files\Hewlett-Packard\IAM\Bin\ItVCard.dll
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"DeviceNP" - "Hewlett-Packard Limited" - C:\Windows\system32\DeviceNP.dll
===[ Logfile end ]=========================================[ Logfile end ]=== --- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]
MBR: Zitat:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Business Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Hewlett-Packard
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Compaq dc7900 Small Form Factor
Logical Drives Mask: 0x0000003c
Kernel Drivers (total 155):
0x82435000 \SystemRoot\system32\ntkrnlpa.exe
0x82402000 \SystemRoot\system32\hal.dll
0x80409000 \SystemRoot\system32\kdcom.dll
0x80410000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80480000 \SystemRoot\system32\PSHED.dll
0x80491000 \SystemRoot\system32\BOOTVID.dll
0x80499000 \SystemRoot\system32\CLFS.SYS
0x804DA000 \SystemRoot\system32\CI.dll
0x8060B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8067C000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8068A000 \SystemRoot\System32\Drivers\spea.sys
0x8077D000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x80786000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x807AC000 \SystemRoot\system32\drivers\acpi.sys
0x807F2000 \SystemRoot\system32\drivers\msisadrv.sys
0x805BA000 \SystemRoot\system32\drivers\pci.sys
0x805E1000 \SystemRoot\System32\drivers\partmgr.sys
0x805F0000 \SystemRoot\system32\drivers\volmgr.sys
0x82A05000 \SystemRoot\System32\drivers\volmgrx.sys
0x82A4F000 \SystemRoot\system32\drivers\pciide.sys
0x82A56000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x82A64000 \SystemRoot\System32\drivers\mountmgr.sys
0x82A74000 \SystemRoot\system32\drivers\iastor.sys
0x82B4D000 \SystemRoot\system32\drivers\atapi.sys
0x82B55000 \SystemRoot\system32\drivers\ataport.SYS
0x82B73000 \SystemRoot\system32\drivers\fltmgr.sys
0x82BA5000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B806000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B877000 \SystemRoot\system32\drivers\ndis.sys
0x8B982000 \SystemRoot\system32\drivers\msrpc.sys
0x8B9AD000 \SystemRoot\system32\drivers\NETIO.SYS
0x8BA0B000 \SystemRoot\System32\drivers\tcpip.sys
0x8BAF8000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8BC0E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8BD1E000 \SystemRoot\system32\drivers\volsnap.sys
0x8BD57000 \SystemRoot\System32\Drivers\spldr.sys
0x8BD5F000 \SystemRoot\System32\Drivers\mup.sys
0x8BD6E000 \SystemRoot\System32\drivers\ecache.sys
0x8BD95000 \SystemRoot\system32\drivers\disk.sys
0x8BDA6000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8BDC7000 \SystemRoot\system32\drivers\crcdisk.sys
0x8BDDD000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8BDE8000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x90001000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x9091E000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x909BE000 \SystemRoot\System32\drivers\watchdog.sys
0x909CA000 \SystemRoot\system32\DRIVERS\HECI.sys
0x909D4000 \SystemRoot\system32\DRIVERS\serial.sys
0x909EE000 \SystemRoot\system32\DRIVERS\serenum.sys
0x82BB5000 \SystemRoot\system32\DRIVERS\e1k6032.sys
0x8BDF1000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8FA00000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8FA3E000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8FA4D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8FADA000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8FAED000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8FAF8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8FB03000 \SystemRoot\system32\DRIVERS\fdc.sys
0x8FB0E000 \SystemRoot\system32\drivers\tpm.sys
0x8FB1C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8FB34000 \SystemRoot\System32\Drivers\atca5ikv.SYS
0x8FB6D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8FB7C000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8FB85000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8FBB4000 \SystemRoot\system32\DRIVERS\storport.sys
0x8FBF5000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8B9E8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8BC00000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x90C06000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x90C29000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x90C38000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x90C4C000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x90C61000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0x90CEA000 \SystemRoot\system32\DRIVERS\termdd.sys
0x90CFA000 \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys
0x90D14000 \SystemRoot\system32\DRIVERS\swenum.sys
0x90D16000 \SystemRoot\system32\DRIVERS\ks.sys
0x90D40000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x90D4A000 \SystemRoot\system32\DRIVERS\umbus.sys
0x90D57000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x90D8C000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x90E0D000 \SystemRoot\system32\drivers\ADIHdAud.sys
0x90E6F000 \SystemRoot\system32\drivers\portcls.sys
0x90E9C000 \SystemRoot\system32\drivers\drmk.sys
0x90EC1000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x90F1F000 \SystemRoot\system32\DRIVERS\fwlanusb.sys
0x90F60000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x90F62000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x90F6B000 \SystemRoot\System32\Drivers\Null.SYS
0x90F72000 \SystemRoot\System32\Drivers\Beep.SYS
0x90F82000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x90F89000 \SystemRoot\System32\drivers\vga.sys
0x90F95000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x90FB6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x90FBE000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90FC6000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90FD1000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90FDF000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x90FE8000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90E00000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x90DA8000 \SystemRoot\system32\DRIVERS\smb.sys
0x90DBC000 \SystemRoot\System32\DRIVERS\netbt.sys
0x91402000 \SystemRoot\system32\drivers\afd.sys
0x9144A000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x9144F000 \SystemRoot\system32\DRIVERS\pacer.sys
0x91465000 \SystemRoot\system32\DRIVERS\netbios.sys
0x91473000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x91486000 \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys
0x9148F000 \SystemRoot\system32\DRIVERS\VBoxDrv.sys
0x914B1000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x914ED000 \SystemRoot\system32\drivers\nsiproxy.sys
0x914F7000 \??\C:\Windows\system32\drivers\fslx.sys
0x91526000 \SystemRoot\system32\drivers\csc.sys
0x91581000 \SystemRoot\System32\Drivers\dfsc.sys
0x91598000 \SystemRoot\System32\Drivers\aswSP.SYS
0x915E0000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8BB13000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x9A010000 \SystemRoot\System32\win32k.sys
0x915ED000 \SystemRoot\System32\drivers\Dxapi.sys
0x90DEE000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9A230000 \SystemRoot\System32\TSDDD.dll
0x9A250000 \SystemRoot\System32\cdd.dll
0x9A260000 \SystemRoot\System32\ATMFD.DLL
0xACE05000 \SystemRoot\system32\drivers\luafv.sys
0xACE20000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0xACE58000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0xACE5B000 \SystemRoot\system32\drivers\spsys.sys
0xACF0B000 \??\C:\Program Files\Sandboxie\SbieDrv.sys
0xACF2C000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xACF3C000 \SystemRoot\system32\DRIVERS\nwifi.sys
0xACF66000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xACF70000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xACF83000 \SystemRoot\system32\drivers\HTTP.sys
0xB1004000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xB1021000 \SystemRoot\system32\DRIVERS\bowser.sys
0xB103A000 \SystemRoot\System32\drivers\mpsdrv.sys
0xB104F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xB106E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xB10A7000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xB10BF000 \SystemRoot\System32\DRIVERS\srv2.sys
0xB10E7000 \SystemRoot\System32\DRIVERS\srv.sys
0xB1135000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xB1178000 \SystemRoot\system32\DRIVERS\ithsgt.sys
0xB11A0000 \SystemRoot\system32\DRIVERS\lilsgt.sys
0xB11A3000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xB260C000 \SystemRoot\system32\drivers\peauth.sys
0xB26EA000 \SystemRoot\System32\Drivers\secdrv.SYS
0xB26F4000 \SystemRoot\System32\drivers\tcpipreg.sys
0xB2700000 \SystemRoot\system32\Drivers\LVPr2Mon.sys
0xB2705000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xB271B000 \??\C:\Windows\system32\drivers\mbam.sys
0xB271F000 \??\C:\Users\GAMER-~1\AppData\Local\Temp\xspirit.sys
0xB27AE000 \??\C:\Users\GAMER-~1\AppData\Local\Temp\kgldruoc.sys
0x77C20000 \Windows\System32\ntdll.dll
0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll
Processes (total 65):
0 System Idle Process
4 System
600 C:\Windows\System32\smss.exe
668 csrss.exe
712 C:\Windows\System32\wininit.exe
724 csrss.exe
756 C:\Windows\System32\services.exe
772 C:\Windows\System32\lsass.exe
796 C:\Windows\System32\winlogon.exe
816 C:\Windows\System32\lsm.exe
996 C:\Windows\System32\svchost.exe
1052 C:\Windows\System32\svchost.exe
1080 C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
1120 C:\Windows\System32\svchost.exe
1248 C:\Windows\System32\svchost.exe
1284 C:\Windows\System32\svchost.exe
1324 C:\Windows\System32\svchost.exe
1416 C:\Windows\System32\audiodg.exe
1448 C:\Windows\System32\svchost.exe
1508 C:\Windows\System32\SLsvc.exe
1588 C:\Windows\System32\svchost.exe
1704 C:\Program Files\Sandboxie\SbieSvc.exe
1824 C:\Windows\System32\svchost.exe
1948 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1336 C:\Windows\System32\taskeng.exe
1408 C:\Windows\System32\spoolsv.exe
1676 C:\Windows\System32\svchost.exe
2136 C:\Program Files\ActivIdentity\ActivClient\accoca.exe
2168 C:\Windows\System32\AEADISRV.EXE
2220 C:\Windows\System32\svchost.exe
2240 C:\Program Files\ActivIdentity\ActivClient\acevents.exe
2248 C:\Program Files\avmwlanstick\WLanNetService.exe
2376 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
2524 C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
2552 C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
2616 C:\Program Files\Intel\AMT\LMS.exe
2640 C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
2680 C:\Program Files\PDF Complete\pdfsvc.exe
2724 C:\Windows\System32\PnkBstrA.exe
2784 C:\Windows\System32\svchost.exe
2812 C:\Windows\System32\svchost.exe
2924 C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
2944 C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
3000 C:\Windows\System32\svchost.exe
3028 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
3324 C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
3336 WmiPrvSE.exe
3660 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
3816 C:\Windows\System32\taskeng.exe
2624 C:\Windows\System32\dwm.exe
2856 C:\Windows\explorer.exe
3600 C:\Program Files\Analog Devices\Core\smax4pnp.exe
2420 C:\Program Files\Windows Media Player\wmpnscfg.exe
1716 C:\Program Files\avmwlanstick\WLanGUI.exe
1236 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2892 C:\Program Files\Windows Media Player\wmpnetwk.exe
4428 C:\Windows\System32\svchost.exe
5092 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
4196 C:\Program Files\Mozilla Firefox\firefox.exe
4284 WmiPrvSE.exe
4800 C:\Program Files\Mozilla Firefox\plugin-container.exe
5008 dllhost.exe
4052 dllhost.exe
5460 C:\Users\Gamer-Pro\Downloads\MBRCheck.exe
4472 C:\Windows\System32\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000039`bba00000 (NTFS)
PhysicalDrive0 Model Number: ST3250310AS, Rev: 3.AHC
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: C494D0E68EC43BD90D507D7433A09349C3E569C8
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
| |