osam :
Code:
Alles auswählen Aufklappen ATTFilter
Report of OSAM : Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 00:12:05 on 12.07.2011
OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.18
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"BrnStiCp.cpl" - "Brother Industries,Ltd." - C:\Windows\system32\BrnStiCp.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLCFG32.CPL
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"aftcypow" (aftcypow) - ? - C:\Users\CHAOSK~1\AppData\Local\Temp\aftcypow.sys (Hidden registry entry, rootkit activity | File not found)
"catchme" (catchme) - ? - C:\Users\CHAOSK~1\AppData\Local\Temp\catchme.sys (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"FsUsbExDisk" (FsUsbExDisk) - ? - C:\Windows\system32\FsUsbExDisk.SYS (File found, but it contains no detailed information)
"Huawei DataCard USB Modem and USB Serial" (hwdatacard) - ? - C:\Windows\System32\DRIVERS\ewusbmdm.sys (File not found)
"Huawei DataCard USB Serial Port" (ewsercd) - ? - C:\Windows\System32\DRIVERS\ewsercd.sys (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\system32\drivers\IpInIp.sys (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\system32\drivers\NwlnkFlt.sys (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\system32\drivers\NwlnkFwd.sys (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"MBAMSwissArmy" (MBAMSwissArmy) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbamswissarmy.sys
"ntiomin" (ntiomin) - ? - C:\Windows\system32\drivers\ntiomin.sys
"ntiopnp" (ntiopnp) - ? - C:\Windows\system32\drivers\ntiopnp.sys
"Tunebite High-Speed Dubbing" (tbhsd) - "RapidSolution Software AG" - C:\Windows\System32\drivers\tbhsd.sys
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{F2DDE6B2-9684-4A55-86D4-E255E237B77C} "avgsecuritytoolbar" - ? - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll (File not found)
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{0DE76E1C-40C5-4fae-A59A-44EF606A0B02} "AbbyyS2O.S2OShellExtension.1" - "ABBYY (BIT Software)" - C:\Program Files\ABBYY ScanTo Office 1.0\STOShellExtension.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\VISSHE.DLL
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\MLSHEXT.DLL
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
EzCddax extension "{37DDAAA7-7B07-4e1e-8CFF-B46B63AF2925}" - ? - (File not found | COM-object registry key not found)
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{4A62FAC4-1670-430B-8C6B-9C7B53F51798} "GfK Internet-Monitor" - ? - C:\Program Files\GfK Internet-Monitor\Gacela2.dll
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "&RoboForm" - "Siber Systems Inc." - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
<binary data> "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{dcea9ff9-5c31-40ac-9285-9c25ff04b93a} "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
"Ausfüllen" - ? - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
{80A21664-E813-4F79-B965-2058C0F7A84C} "ClsidExtension" - ? - C:\Program Files\GfK Internet-Monitor\Gacela2.dll
"RoboForm" - ? - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
"Speichern" - ? - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "&RoboForm" - "Siber Systems Inc." - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
{dcea9ff9-5c31-40ac-9285-9c25ff04b93a} "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
{AD6E6555-FB2C-47D4-8339-3E2965509877} "TerraTec Home Cinema" - "TerraTec Electronic GmbH" - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{30F9B915-B755-4826-820B-08FBA6BD249D} "Conduit Engine " - "Conduit Ltd." - C:\Program Files\ConduitEngine\prxConduitEngine.dll
{4BEEA052-726D-4A6E-B65D-A6BD07C263F3} "GfK Internet-Monitor" - ? - C:\Program Files\GfK Internet-Monitor\Gacela2.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
{dcea9ff9-5c31-40ac-9285-9c25ff04b93a} "produkttests Toolbar" - "Conduit Ltd." - C:\Program Files\produkttests\prxtbpro0.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" - ? - (File not found | COM-object registry key not found)
{724d43a9-0d85-11d4-9908-00400523e39a} "{724d43a9-0d85-11d4-9908-00400523e39a}" - "Siber Systems Inc." - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Chaoskomet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"AutoStartNPSAgent" - "Samsung Electronics Co., Ltd." - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
"ccleaner" - "Piriform Ltd" - "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
"IncrediMail" - "IncrediMail, Ltd." - C:\Program Files\IncrediMail\bin\IncMail.exe /c
"msnmsgr" - "Microsoft Corporation" - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
"Remote Control Editor" - "Elgato Systems" - "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
"RoboForm" - "Siber Systems" - "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"BCSSync" - "Microsoft Corporation" - "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"BrMfcWnd" - "Brother Industries, Ltd." - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3" - "Brother Industries, Ltd." - C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"GfK-WatchDog" - "GfK" - C:\Program Files\GfKLSPService\GfK-WatchDog.exe /Debug
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"UCam_Menu" - "CyberLink Corp." - "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
"VirtualCloneDrive" - "Elaborate Bytes AG" - "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Nitro PDF Port Monitor" - "Nitro PDF Software" - C:\Windows\system32\nitrolocalmon2.dll
"PCL hpz3l5mu" - "Hewlett-Packard Company" - C:\Windows\system32\hpz3l5mu.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Program Files\Nero\Update\NASvc.exe,-200" (NAUpdate) - "Nero AG" - C:\Program Files\Nero\Update\NASvc.exe
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
"FsUsbExService" (FsUsbExService) - "Teruten" - C:\Windows\system32\FsUsbExService.Exe
"GfK-Reporting-Service" (GfK-Reporting-Service) - ? - C:\Program Files\GfK Internet-Monitor\GfK-Reporting.exe
"GfK-Update-Service" (GfK-Update-Service) - ? - C:\Program Files\GfK Internet-Monitor\GfK-Updater.exe
"GfkLSPService" (GfkLSPService) - "nurago GmbH" - C:\Program Files\GfKLSPService\GfKLSPService.exe
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NitroPDFReaderDriverCreatorReadSpool2" (NitroReaderDriverReadSpool2) - "Nitro PDF Software" - C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"Rezip" (Rezip) - ? - C:\Windows\SYSTEM32\Rezip.exe
"ServiceLayer" (ServiceLayer) - "Nokia." - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
"Sony Ericsson PCCompanion" (Sony Ericsson PCCompanion) - "Avanquest Software" - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
"SQL Server (MSSMLBIZ)" (MSSQL$MSSMLBIZ) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
"SQL Server-Browser" (SQLBrowser) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
"TeamViewer 4" (TeamViewer4) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - ? - C:\Windows\SHEBA_~1.SCR (File not found)
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"GacelaLSP" - "nurago GmbH" - C:\Windows\system32\GfKLSPService.DLL
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
MBR:
Code:
Alles auswählen Aufklappen ATTFilter
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
BIOS Manufacturer: Phoenix Technologies Ltd.
System Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
System Product Name: R520/R522/R620
Logical Drives Mask: 0x000000b4
Kernel Drivers (total 153):
0x8241E000 \SystemRoot\system32\ntoskrnl.exe
0x827C9000 \SystemRoot\system32\hal.dll
0x8A001000 \SystemRoot\system32\kdcom.dll
0x8A008000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8A078000 \SystemRoot\system32\PSHED.dll
0x8A089000 \SystemRoot\system32\BOOTVID.dll
0x8A091000 \SystemRoot\system32\CLFS.SYS
0x8A0D2000 \SystemRoot\system32\CI.dll
0x8A1B2000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8A22E000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8A23B000 \SystemRoot\system32\drivers\acpi.sys
0x8A281000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8A28A000 \SystemRoot\system32\drivers\msisadrv.sys
0x8A292000 \SystemRoot\system32\drivers\pci.sys
0x8A2B9000 \SystemRoot\System32\drivers\partmgr.sys
0x8A2C8000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8A2CB000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8A2D5000 \SystemRoot\system32\drivers\volmgr.sys
0x8A2E4000 \SystemRoot\System32\drivers\volmgrx.sys
0x8A32E000 \SystemRoot\System32\drivers\mountmgr.sys
0x8A401000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x8A4DC000 \SystemRoot\system32\drivers\atapi.sys
0x8A4E4000 \SystemRoot\system32\drivers\ataport.SYS
0x8A502000 \SystemRoot\system32\drivers\msahci.sys
0x8A50C000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8A51A000 \SystemRoot\system32\drivers\fltmgr.sys
0x8A54C000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A55C000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8A5CD000 \SystemRoot\system32\drivers\ndis.sys
0x8A6D8000 \SystemRoot\system32\drivers\msrpc.sys
0x8A703000 \SystemRoot\system32\drivers\NETIO.SYS
0x8A809000 \SystemRoot\System32\drivers\tcpip.sys
0x8A8F3000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8A90E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8AA1E000 \SystemRoot\system32\drivers\volsnap.sys
0x8AA57000 \SystemRoot\System32\Drivers\spldr.sys
0x8AA5F000 \SystemRoot\System32\Drivers\mup.sys
0x8AA6E000 \SystemRoot\System32\drivers\ecache.sys
0x8AA95000 \SystemRoot\system32\drivers\disk.sys
0x8AAA6000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8AAC7000 \SystemRoot\system32\drivers\crcdisk.sys
0x8ABB8000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8ABC3000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8EC03000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x8F085000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8F125000 \SystemRoot\System32\drivers\watchdog.sys
0x8F131000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F1BE000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8F1C9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8F207000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8F216000 \SystemRoot\system32\DRIVERS\athr.sys
0x8F305000 \SystemRoot\system32\DRIVERS\yk60x86.sys
0x8F355000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8F359000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8F36C000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F377000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8F3A7000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F3A9000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8F3B4000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8F3CC000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8ABCC000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8A73E000 \SystemRoot\system32\DRIVERS\storport.sys
0x8F3DB000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8F3E6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8A77F000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8A78A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8A7AD000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8A7BC000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8A7D0000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8A7E5000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8A33E000 \SystemRoot\system32\DRIVERS\VClone.sys
0x8A34A000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x8F3FD000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8A370000 \SystemRoot\system32\DRIVERS\ks.sys
0x8A7F5000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8A39A000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8A3A7000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8A3DC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x9080D000 \SystemRoot\system32\drivers\HdAudio.sys
0x9084C000 \SystemRoot\system32\drivers\portcls.sys
0x90879000 \SystemRoot\system32\drivers\drmk.sys
0x9089E000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x90AD5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x90ADE000 \SystemRoot\System32\Drivers\Null.SYS
0x90AE5000 \SystemRoot\System32\Drivers\Beep.SYS
0x90AF5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x90AFC000 \SystemRoot\System32\drivers\vga.sys
0x90B08000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x90B29000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x90B31000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90B39000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90B44000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90B52000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x90B5B000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90B71000 \SystemRoot\system32\DRIVERS\smb.sys
0x90B85000 \SystemRoot\System32\DRIVERS\netbt.sys
0x90BB7000 \SystemRoot\system32\drivers\afd.sys
0x90800000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x90409000 \SystemRoot\system32\DRIVERS\pacer.sys
0x9041F000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9042D000 \SystemRoot\System32\Drivers\ntiomin.SYS
0x90430000 \SystemRoot\System32\Drivers\ntiopnp.SYS
0x90438000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x9044B000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90487000 \SystemRoot\system32\drivers\nsiproxy.sys
0x90491000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
0x9049B000 \SystemRoot\System32\Drivers\dfsc.sys
0x904B2000 \SystemRoot\System32\Drivers\VMC326.sys
0x904ED000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x904FA000 \SystemRoot\System32\Drivers\bthport.sys
0x9057A000 \SystemRoot\system32\DRIVERS\KMWDFILTER.sys
0x90583000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x9058C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x9059C000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x905A4000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x905CD000 \SystemRoot\system32\DRIVERS\BthEnum.sys
0x905D7000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x905F1000 \SystemRoot\system32\drivers\btwavdt.sys
0x90662000 \SystemRoot\system32\drivers\btwaudio.sys
0x906E2000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
0x906EC000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0x906EF000 \SystemRoot\System32\Drivers\crashdmp.sys
0x906FC000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x9CC00000 \SystemRoot\System32\win32k.sys
0x907D7000 \SystemRoot\System32\drivers\Dxapi.sys
0x907E1000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9CE20000 \SystemRoot\System32\TSDDD.dll
0x9CE40000 \SystemRoot\System32\cdd.dll
0x8AAD0000 \SystemRoot\system32\drivers\luafv.sys
0x907F0000 \SystemRoot\system32\DRIVERS\kmdfmemio.sys
0x8AAEB000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x8AAFB000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8AB25000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x8AB2F000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x81C0B000 \SystemRoot\system32\drivers\spsys.sys
0x81CBB000 \SystemRoot\system32\drivers\HTTP.sys
0x81D28000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x81D45000 \SystemRoot\system32\DRIVERS\bowser.sys
0x81D5E000 \SystemRoot\System32\drivers\mpsdrv.sys
0x81D73000 \SystemRoot\system32\drivers\mrxdav.sys
0x81D94000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x81DB3000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x81DEC000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x81E04000 \SystemRoot\System32\DRIVERS\srv2.sys
0x81E2C000 \SystemRoot\System32\DRIVERS\srv.sys
0x81E93000 \SystemRoot\system32\drivers\peauth.sys
0x81F71000 \SystemRoot\System32\Drivers\secdrv.SYS
0x81F7B000 \SystemRoot\System32\drivers\tcpipreg.sys
0x81F87000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x81F9F000 \??\C:\Windows\system32\FsUsbExDisk.SYS
0x81FA8000 \??\C:\Windows\system32\drivers\mbam.sys
0x81FAC000 \??\C:\Users\CHAOSK~1\AppData\Local\Temp\aftcypow.sys
0x77510000 \Windows\System32\ntdll.dll
Processes (total 84):
0 System Idle Process
4 SYSTEM
528 C:\Windows\System32\smss.exe
596 csrss.exe
652 C:\Windows\System32\wininit.exe
672 csrss.exe
704 C:\Windows\System32\services.exe
720 C:\Windows\System32\lsass.exe
732 C:\Windows\System32\lsm.exe
864 C:\Windows\System32\svchost.exe
928 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\Ati2evxx.exe
1036 C:\Windows\System32\svchost.exe
1064 C:\Windows\System32\svchost.exe
1092 C:\Windows\System32\svchost.exe
1160 C:\Windows\System32\audiodg.exe
1176 C:\Windows\System32\svchost.exe
1192 C:\Windows\System32\SLsvc.exe
1244 C:\Windows\System32\winlogon.exe
1296 C:\Windows\System32\svchost.exe
1436 C:\Windows\System32\svchost.exe
1476 C:\Windows\System32\svchost.exe
1776 C:\Windows\System32\spoolsv.exe
1784 C:\Windows\System32\taskeng.exe
1816 C:\Windows\System32\svchost.exe
2016 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
2032 C:\Windows\System32\agrsmsvc.exe
236 C:\Windows\System32\svchost.exe
304 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
456 C:\Windows\System32\FsUsbExService.Exe
780 C:\Program Files\GfK Internet-Monitor\GfK-Reporting.exe
664 C:\Program Files\GfK Internet-Monitor\GfK-Updater.exe
1888 C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
2188 C:\Program Files\Nero\Update\NASvc.exe
2208 C:\Windows\System32\svchost.exe
2236 C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe
2312 C:\Windows\System32\svchost.exe
2348 C:\Windows\System32\svchost.exe
2396 C:\Windows\System32\Ati2evxx.exe
2420 C:\Windows\System32\Rezip.exe
2488 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
2512 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2588 C:\Windows\System32\svchost.exe
2680 C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
2712 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2904 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
3428 C:\Windows\System32\dwm.exe
3460 C:\Windows\explorer.exe
3588 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
3600 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3676 C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
3692 C:\Program Files\GfKLSPService\GfK-WatchDog.exe
3700 C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
3716 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3724 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
3732 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
3740 C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
3764 C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
3772 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
3780 C:\Program Files\Windows Media Player\wmpnscfg.exe
3796 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
3916 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
2392 C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
1288 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
3368 C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
1680 C:\Windows\System32\taskeng.exe
3828 C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
1344 C:\Windows\System32\taskeng.exe
3092 C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
2804 C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
4120 C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
4408 WmiPrvSE.exe
4900 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
5808 C:\Program Files\Windows Media Player\wmpnetwk.exe
6052 C:\Windows\System32\svchost.exe
4184 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
3444 C:\Program Files\GfKLSPService\GfKLSPService.exe
2132 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
7112 C:\Program Files\Mozilla Firefox\firefox.exe
7160 C:\Program Files\Mozilla Firefox\plugin-container.exe
5340 dllhost.exe
5848 dllhost.exe
6636 C:\Users\Chaoskomet\Desktop\MBRCheck.exe
7656 C:\Windows\System32\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`40100000 (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000026`c5a00000 (NTFS)
PhysicalDrive0 Model Number: SAMSUNGHM320II, Rev: 2AC101C4
Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 90AE6712C96E547F52E3EBE382852AA331FA41FC
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
nun bin ich ja mal gepsannt wie es weiter geht.