GMER hat nicht funktioniert. Das Programm ist zweimal abgestürzt und dann habe ich es gelassen.
Hier die Log von OSAM
OSAM Logfile: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 10:47:39 on 09.07.2011
OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.18
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-967124566-3105974339-2490099070-1003Core.job" - "Google Inc." - C:\Users\Mia\AppData\Local\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-967124566-3105974339-2490099070-1003UA.job" - "Google Inc." - C:\Users\Mia\AppData\Local\Google\Update\GoogleUpdate.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"ddbaccpl.cpl" - "DataDesign AG" - C:\Windows\system32\ddbaccpl.cpl
"ddbacctm.cpl" - "DataDesign AG" - C:\Windows\system32\ddbacctm.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\Quicktime Apple\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\cofi28445c\catchme.sys (File not found)
"Hotkey" (Hotkey) - ? - C:\Windows\system32\drivers\Hotkey.sys (File found, but it contains no detailed information)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found)
"IVI ASPI Shell" (Iviaspi) - "InterVideo, Inc." - C:\Windows\System32\drivers\iviaspi.sys
"PDNMp50 NDIS Protocol Driver" (PDNMp50) - "Printing Communications Assoc., Inc. (PCAUSA)" - C:\Windows\system32\drivers\PDNMp50.sys
"PDNSp50 NDIS Protocol Driver" (PDNSp50) - "Printing Communications Assoc., Inc. (PCAUSA)" - C:\Windows\system32\drivers\PDNSp50.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"TAP-Win32 Adapter V8" (tap0801) - "The OpenVPN Project" - C:\Windows\System32\DRIVERS\tap0801.sys
"VMware hcmon" (hcmon) - "VMware, Inc." - C:\Windows\system32\drivers\hcmon.sys
"VMware kbd" (vmkbd) - "VMware, Inc." - C:\Windows\system32\drivers\VMkbd.sys
"VMware Network Application Interface" (VMnetuserif) - "VMware, Inc." - C:\Windows\system32\drivers\vmnetuserif.sys
"VMware vmci" (vmci) - "VMware, Inc." - C:\Windows\system32\Drivers\vmci.sys
"VMware vmx86" (vmx86) - "VMware, Inc." - C:\Windows\system32\Drivers\vmx86.sys
"Vstor2 WS60 Virtual Storage Driver" (vstor2-ws60) - "VMware, Inc." - C:\Program Files\VMware\VMware Player\vstor2-ws60.sys
[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{7D4D6379-F301-4311-BEBA-E26EB0561882} "NeroDigitalColumnHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{B988C8B2-373B-11CF-B6E0-00AA00BBBA9E} "ImageComposer.CompositionPropertyPage" - "Microsoft Corporation" - C:\Program Files\Microsoft Image Composer\SERVER.DLL
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? - (File not found | COM-object registry key not found)
{73B24247-042E-4EF5-ADC2-42F62E6FD654} "MCLiteShellExt Class" - ? - C:\Program Files\ICQLite\ICQLiteShell.dll
{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} "Meine freigegebenen Ordner" - "Microsoft Corporation" - C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} "NeroCoverEdLiveIcons Class" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
{B327765E-D724-4347-8B16-78AE18552FC3} "NeroDigitalIconHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{7F1CF152-04F8-453A-B34C-E609530A9DC8} "NeroDigitalPropSheetHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{DBD8E168-244D-448C-9922-25508950D1DC} "USIShellExt Class" - "Ulead Systems, Inc." - C:\Program Files\Common Files\Ulead Systems\DVD\USIShex.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-1170-17534-22/4 (HTTP value)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} "Java Plug-in 1.6.0_03" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.6.0_05" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_20.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} "MUWebControl Class" - "Microsoft Corporation" - C:\Windows\system32\muweb.dll / hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183949065925
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} "Office Genuine Advantage Validation Tool" - ? - C:\Windows\system32\OGACheckControl.DLL / hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10e.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
{3D3B42C2-11BF-4732-A304-A01384B70D68} "UploadListView Class" - "Google, Inc." - C:\Windows\Downloaded Program Files\UploaderX.dll / hxxp://picasaweb.google.com/s/v/57.11/uploader2.cab
{17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool" - "Microsoft Corporation" - C:\Windows\system32\LegitCheckControl.DLL / hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? - (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-1170-17534-22/4 (HTTP value)
"ICQ Lite" - ? - C:\Program Files\ICQLite\ICQLite.exe (File not found)
"ICQ7.2" - "ICQ, LLC." - C:\Program Files\ICQ\version 7\ICQ7.2\ICQ.exe
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} "FireShot" - ? - C:\Users\Mia\AppData\Roaming\Mozilla\Firefox\Profiles\o2tx0ldy.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.78.dll (File not found)
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
{7E853D72-626A-48EC-A868-BA8D5E23E045} "{7E853D72-626A-48EC-A868-BA8D5E23E045}" - ? - (File not found | COM-object registry key not found)
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Mia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Adobe Gamma Loader.lnk" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Shortcut exists | File exists)
"Adobe Reader - Schnellstart.lnk" - "Adobe Systems Incorporated" - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files\frontpage\Office\OSA9.EXE (Shortcut exists | File exists)
"WinManager.lnk" - ? - C:\Program Files\Fujitsu Siemens\WinManager\WinManager.exe (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" - "Nero AG" - "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"msnmsgr" - "Microsoft Corporation" - "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
"PhonostarAgent" - ? - C:\Program Files\Internetradio phonostar\phonostar\ps_agent.exe
"PhonostarTimer" - ? - C:\Program Files\Internetradio phonostar\phonostar\ps_timer.exe
"swg" - "Google Inc." - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"BrMfcWnd" - "Brother Industries, Ltd." - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3" - "Brother Industries, Ltd." - C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"CtrlVol" - ? - C:\Program Files\Launch Manager\CtrlVol.exe (File not found)
"HotkeyApp" - "Wistron" - "C:\Program Files\Launch Manager\HotkeyApp.exe"
"IAAnotif" - "Intel Corporation" - "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
"LaunchAp" - ? - "C:\Program Files\Launch Manager\LaunchAp.exe"
"LMgrOSD" - "Wistron Corp." - "C:\Program Files\Launch Manager\OSD.exe"
"NeroFilterCheck" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"QuickTime Task" - "Apple Inc." - "C:\Program Files\Quicktime Apple\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"toolbar_eula_launcher" - " " - C:\Program Files\GoogleEULA\EULALauncher.exe
"TVBroadcast" - "ODSoft multimedia" - C:\Program Files\Sceneo\Bonavista\Services\ODSBC\ODSBCApp.exe
"UVS10 Preload" - "Ulead Systems, Inc." - C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
"VMware hqtray" - "VMware, Inc." - "C:\Program Files\VMware\VMware Player\hqtray.exe"
"Wbutton" - ? - "C:\Program Files\Launch Manager\Wbutton.exe"
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe LM Service" (Adobe LM Service) - ? - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"ClipInc 001" (ClipInc001) - ? - c:\Program Files\Radio\Tobit ClipInc\Server\ClipInc-Server.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\ALDI Sued Foto Service\Common\Database\bin\fbserver.exe
"GnabService" (GnabService) - "Empolis GmbH" - c:\program files\common files\gnab\service\servicecontroller.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"Intel(R) Matrix Storage Event Monitor" (IAANTMON) - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
"IviRegMgr" (IviRegMgr) - "InterVideo" - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"NBService" (NBService) - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"OpenVPN Service" (OpenVPNService) - ? - C:\Program Files\Wlan\OpenVPN\bin\openvpnserv.exe (File not found)
"Sceneo PVR Service" (srvcPVR) - "Buhl Data Service GmbH" - C:\Program Files\Sceneo\Bonavista\Services\PVR\PVRService.exe
"Ulead Burning Helper" (UleadBurningHelper) - "Ulead Systems, Inc." - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
"VMware Agent Service" (ufad-ws60) - "VMware, Inc." - C:\Program Files\VMware\VMware Player\vmware-ufad.exe
"VMware Authorization Service" (VMAuthdService) - "VMware, Inc." - C:\Program Files\VMware\VMware Player\vmware-authd.exe
"VMware DHCP Service" (VMnetDHCP) - "VMware, Inc." - C:\Windows\system32\vmnetdhcp.exe
"VMware NAT Service" (VMware NAT Service) - "VMware, Inc." - C:\Windows\system32\vmnat.exe
"WisLMSvc" (WisLMSvc) - "Wistron Corp." - C:\Program Files\Launch Manager\WisLMSvc.exe
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"VMCI sockets DGRAM" - "VMware, Inc." - C:\Program Files\VMware\VMware Player\vsocklib.dll
"VMCI sockets STREAM" - "VMware, Inc." - C:\Program Files\VMware\VMware Player\vsocklib.dll
===[ Logfile end ]=========================================[ Logfile end ]===
--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
Logs von MBRCheck Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: MEDION
BIOS Manufacturer: Phoenix Technologies LTD
System Manufacturer: MEDION
System Product Name: WIM2160
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 163):
0x8241A000 \SystemRoot\system32\ntoskrnl.exe
0x827C5000 \SystemRoot\system32\hal.dll
0x82C09000 \SystemRoot\system32\kdcom.dll
0x82C10000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x82C80000 \SystemRoot\system32\PSHED.dll
0x82C91000 \SystemRoot\system32\BOOTVID.dll
0x82C99000 \SystemRoot\system32\CLFS.SYS
0x82CDA000 \SystemRoot\system32\CI.dll
0x82DBA000 \SystemRoot\system32\drivers\Wdf01000.sys
0x82E36000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x82E43000 \SystemRoot\system32\drivers\acpi.sys
0x82E89000 \SystemRoot\system32\drivers\WMILIB.SYS
0x82E92000 \SystemRoot\system32\drivers\msisadrv.sys
0x82E9A000 \SystemRoot\system32\drivers\pci.sys
0x82EC1000 \SystemRoot\System32\drivers\partmgr.sys
0x82ED0000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x82ED3000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x82EDD000 \SystemRoot\system32\drivers\volmgr.sys
0x82EEC000 \SystemRoot\System32\drivers\volmgrx.sys
0x82F36000 \SystemRoot\system32\drivers\intelide.sys
0x82F3D000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x82F4B000 \SystemRoot\System32\drivers\mountmgr.sys
0x88002000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x880BA000 \SystemRoot\system32\drivers\atapi.sys
0x880C2000 \SystemRoot\system32\drivers\ataport.SYS
0x880E0000 \SystemRoot\system32\drivers\fltmgr.sys
0x88112000 \SystemRoot\system32\drivers\fileinfo.sys
0x88122000 \SystemRoot\System32\Drivers\ksecdd.sys
0x88193000 \SystemRoot\system32\drivers\ndis.sys
0x8829E000 \SystemRoot\system32\drivers\msrpc.sys
0x882C9000 \SystemRoot\system32\drivers\NETIO.SYS
0x88304000 \SystemRoot\System32\drivers\tcpip.sys
0x82F5B000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x88401000 \SystemRoot\System32\Drivers\Ntfs.sys
0x88511000 \SystemRoot\system32\drivers\volsnap.sys
0x8854A000 \SystemRoot\system32\DRIVERS\uagp35.sys
0x8855B000 \SystemRoot\System32\Drivers\spldr.sys
0x88563000 \SystemRoot\System32\Drivers\mup.sys
0x88572000 \SystemRoot\System32\drivers\ecache.sys
0x88599000 \SystemRoot\system32\drivers\disk.sys
0x885AA000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x885CB000 \SystemRoot\system32\drivers\crcdisk.sys
0x88699000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x886A4000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x886AD000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x886BC000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8C808000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8CE33000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8CED3000 \SystemRoot\System32\drivers\watchdog.sys
0x8CEDF000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8CF6C000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x8CF84000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8CF8F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8CFCD000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8CFDC000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8CFEC000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x886C5000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x886DF000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x886ED000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x88701000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8CFFA000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x88752000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x88765000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8C800000 \??\C:\Windows\system32\drivers\VMkbd.sys
0x88770000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8C805000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8879B000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x887A6000 \SystemRoot\system32\drivers\iviaspi.sys
0x887A9000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x887C1000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x82F76000 \SystemRoot\system32\DRIVERS\storport.sys
0x887F0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x82FB7000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x883EE000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x82FCE000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x82FF1000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8D40B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8D41F000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8D434000 \SystemRoot\system32\DRIVERS\tap0801.sys
0x8D43F000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8D44F000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8D451000 \SystemRoot\system32\DRIVERS\ks.sys
0x8D47B000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8D485000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8D492000 \SystemRoot\system32\DRIVERS\vmnetadapter.sys
0x8D495000 \SystemRoot\system32\DRIVERS\VMNET.SYS
0x8D498000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8D4CD000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8D4DE000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8D686000 \SystemRoot\system32\drivers\portcls.sys
0x8D6B3000 \SystemRoot\system32\drivers\drmk.sys
0x8D6D8000 \SystemRoot\system32\DRIVERS\smserial.sys
0x8D7C8000 \SystemRoot\system32\drivers\modem.sys
0x8D7D5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8D7DE000 \SystemRoot\System32\Drivers\Null.SYS
0x8D7E5000 \SystemRoot\System32\Drivers\Beep.SYS
0x8D7F5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8D80B000 \SystemRoot\System32\drivers\vga.sys
0x8D817000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8D838000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8D840000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8D848000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8D853000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8D861000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8D86A000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8D880000 \SystemRoot\system32\DRIVERS\smb.sys
0x8D894000 \SystemRoot\system32\drivers\afd.sys
0x8D8DC000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8D90E000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x8D917000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8D92D000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8D93B000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8D94E000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8D954000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8D990000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8D99A000 \SystemRoot\System32\Drivers\Hotkey.SYS
0x8D99D000 \SystemRoot\System32\Drivers\dfsc.sys
0x8D9B4000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8D9DB000 \SystemRoot\System32\Drivers\fastfat.SYS
0x8DA03000 \SystemRoot\System32\Drivers\UDXTTM6000.sys
0x8DA52000 \SystemRoot\System32\Drivers\BdaSup.SYS
0x8DA55000 \SystemRoot\system32\drivers\UDXTTM6000HID.sys
0x8DA5D000 \SystemRoot\system32\drivers\HIDCLASS.SYS
0x8DA6D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8EC06000 \SystemRoot\system32\DRIVERS\snp2uvc.sys
0x8EDAD000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0x8EDBA000 \SystemRoot\system32\DRIVERS\sncduvc.SYS
0x8EDC1000 \SystemRoot\system32\DRIVERS\RTL8187B.sys
0x8EE0E000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8EE1B000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x924E0000 \SystemRoot\System32\win32k.sys
0x8EED3000 \SystemRoot\System32\drivers\Dxapi.sys
0x8EEDD000 \SystemRoot\system32\DRIVERS\monitor.sys
0x92700000 \SystemRoot\System32\TSDDD.dll
0x92720000 \SystemRoot\System32\cdd.dll
0x8EEEC000 \SystemRoot\system32\drivers\luafv.sys
0x8EF07000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x8EF26000 \SystemRoot\system32\drivers\spsys.sys
0x8EFD6000 \SystemRoot\system32\DRIVERS\vmnetbridge.sys
0x8EFDC000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x8DA76000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8EFEC000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x8DAA0000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8DAB3000 \SystemRoot\system32\drivers\HTTP.sys
0x8DB20000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x8DB3D000 \SystemRoot\system32\DRIVERS\bowser.sys
0x8DB56000 \SystemRoot\System32\drivers\mpsdrv.sys
0x8DB6B000 \SystemRoot\system32\drivers\mrxdav.sys
0x8DB8C000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x8DBAB000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x8DBE4000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x885D4000 \SystemRoot\System32\DRIVERS\srv2.sys
0x885FC000 \SystemRoot\System32\DRIVERS\srv.sys
0x8EFF6000 \??\C:\Windows\system32\drivers\hcmon.sys
0x8864B000 \??\C:\Windows\system32\Drivers\vmci.sys
0xB9C07000 \??\C:\Windows\system32\Drivers\vmx86.sys
0xB9CD7000 \SystemRoot\system32\drivers\peauth.sys
0xB9DB5000 \SystemRoot\System32\Drivers\secdrv.SYS
0xB9DBF000 \SystemRoot\System32\drivers\tcpipreg.sys
0xB9DCB000 \??\C:\Windows\system32\drivers\vmnetuserif.sys
0xB9DD0000 \??\C:\Program Files\VMware\VMware Player\vstor2-ws60.sys
0xB9DD4000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x77400000 \Windows\System32\ntdll.dll
Processes (total 89):
0 System Idle Process
4 System
480 C:\Windows\System32\smss.exe
628 csrss.exe
672 C:\Windows\System32\wininit.exe
680 csrss.exe
716 C:\Windows\System32\services.exe
744 C:\Windows\System32\lsass.exe
752 C:\Windows\System32\lsm.exe
824 C:\Windows\System32\winlogon.exe
936 C:\Windows\System32\svchost.exe
1004 C:\Windows\System32\svchost.exe
1044 C:\Windows\System32\svchost.exe
1136 C:\Windows\System32\svchost.exe
1196 C:\Windows\System32\svchost.exe
1224 C:\Windows\System32\svchost.exe
1292 C:\Windows\System32\audiodg.exe
1324 C:\Windows\System32\SLsvc.exe
1368 C:\Windows\System32\svchost.exe
1572 C:\Windows\System32\svchost.exe
1796 C:\Windows\System32\spoolsv.exe
1820 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1832 C:\Windows\System32\svchost.exe
1348 C:\Windows\System32\dwm.exe
1568 C:\Windows\System32\taskeng.exe
1588 C:\Windows\explorer.exe
920 C:\Windows\System32\taskeng.exe
2056 C:\Windows\RtHDVCpl.exe
2064 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2116 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
2148 C:\Program Files\Launch Manager\LaunchAp.exe
2164 C:\Program Files\Launch Manager\HotkeyApp.exe
2188 C:\Program Files\Launch Manager\OSD.exe
2196 C:\Program Files\Launch Manager\WButton.exe
2208 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2304 C:\Windows\System32\hkcmd.exe
2312 C:\Windows\System32\igfxpers.exe
2328 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
2360 C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
2376 C:\Program Files\VMware\VMware Player\hqtray.exe
2388 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2412 C:\Program Files\Windows Sidebar\sidebar.exe
2420 C:\Windows\System32\igfxsrvc.exe
2428 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
2452 C:\Windows\ehome\ehtray.exe
2508 C:\Program Files\MSN Messenger\msnmsgr.exe
2540 C:\Program Files\Internetradio phonostar\phonostar\ps_agent.exe
2568 C:\Program Files\Internetradio phonostar\phonostar\ps_timer.exe
2600 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
2664 C:\Program Files\Fujitsu Siemens\WinManager\WinManager.exe
2740 C:\Windows\ehome\ehmsas.exe
2988 C:\Program Files\Windows Sidebar\sidebar.exe
3100 C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
3204 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
3252 C:\Program Files\radio\Tobit ClipInc\Server\ClipInc-Server.exe
3276 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
3320 C:\Program Files\Common Files\Gnab\Service\ServiceController.exe
3452 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
3464 C:\Program Files\Medion\MEDIONbox\Program\GCS.exe
3496 C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
3520 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
3576 C:\Windows\System32\svchost.exe
3620 C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe
3740 C:\Windows\System32\svchost.exe
3800 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
3972 C:\Windows\System32\vmnat.exe
3992 C:\Windows\System32\svchost.exe
4044 C:\Windows\System32\SearchIndexer.exe
472 C:\Program Files\VMware\VMware Player\vmware-authd.exe
1556 C:\Windows\System32\vmnetdhcp.exe
2900 C:\Program Files\Launch Manager\WisLMSvc.exe
736 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
3188 WmiPrvSE.exe
3556 C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
5708 C:\Windows\System32\wbem\unsecapp.exe
6052 C:\Program Files\Windows Mail\WinMail.exe
4412 C:\Windows\System32\svchost.exe
4492 C:\Program Files\Windows Media Player\wmpnscfg.exe
4240 C:\Program Files\Windows Media Player\wmpnetwk.exe
4956 C:\Program Files\Mozilla Firefox\firefox.exe
5204 C:\Program Files\Mozilla Firefox\plugin-container.exe
3596 C:\Windows\System32\wuauclt.exe
5852 C:\Users\Mia\Desktop\osam.exe
3348 C:\Users\Mia\Desktop\osam_autorun_manager_5_0_portable\osam.exe
5208 C:\Program Files\notepad++\notepad++.exe
1172 C:\Windows\System32\SearchProtocolHost.exe
2876 C:\Windows\System32\SearchFilterHost.exe
5228 C:\Users\Mia\Desktop\MBRCheck.exe
4108 C:\Windows\System32\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000001d`bfc6da00 (FAT32)
PhysicalDrive0 Model Number: WDCWD1600BEVS-22RST0, Rev: 04.01G04
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done!
|