So, hier kommen nun alle 3 Logs nacheinander:
1. GMER Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-03-05 15:52:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HDS728080PLA380 rev.PF2OA6EA
Running: yj052388.exe; Driver: C:\DOKUME~1\Admin\LOKALE~1\Temp\pgtdqpog.sys
---- System - GMER 1.0.15 ----
SSDT 899A83A0 ZwAlertResumeThread
SSDT 89B1B338 ZwAlertThread
SSDT 89C01D28 ZwAllocateVirtualMemory
SSDT 89B4C460 ZwAssignProcessToJobObject
SSDT 898A2DA0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB7075D40]
SSDT 89937268 ZwCreateMutant
SSDT 89004798 ZwCreateSymbolicLinkObject
SSDT 89B616F0 ZwCreateThread
SSDT 89B4C500 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB7075FC0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB7076680]
SSDT 89A5B1E0 ZwDuplicateObject
SSDT 8999AF40 ZwFreeVirtualMemory
SSDT 89936D80 ZwImpersonateAnonymousToken
SSDT 89936E40 ZwImpersonateThread
SSDT 8997CCE8 ZwLoadDriver
SSDT 89B3E5D8 ZwMapViewOfSection
SSDT 8994B0D0 ZwOpenEvent
SSDT 899992D0 ZwOpenProcess
SSDT 898932F8 ZwOpenProcessToken
SSDT 89761270 ZwOpenSection
SSDT 89A61CF8 ZwOpenThread
SSDT 88FB1918 ZwProtectVirtualMemory
SSDT 89A562F8 ZwResumeThread
SSDT 89C122E8 ZwSetContextThread
SSDT 89C06290 ZwSetInformationProcess
SSDT 89AD4458 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB7076910]
SSDT 89761310 ZwSuspendProcess
SSDT 8993B968 ZwSuspendThread
SSDT 899A88A8 ZwTerminateProcess
SSDT 89C12248 ZwTerminateThread
SSDT 89C0F778 ZwUnmapViewOfSection
SSDT 899F5CE8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 1D0 804E283C 4 Bytes [E8, CC, 97, 89]
.text ntoskrnl.exe!_abnormal_termination + 3A0 804E2A0C 4 Bytes [E8, 22, C1, 89]
.text ntoskrnl.exe!_abnormal_termination + 4A0 804E2B0C 4 Bytes [E8, 5C, 9F, 89]
? SYMDS.SYS Das System kann die angegebene Datei nicht finden. !
? SYMEFA.SYS Das System kann die angegebene Datei nicht finden. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8663360, 0x37388D, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [0102316A] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [01021D9E] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA] [01022FA8] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA] [0102316A] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [01022FA8] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [0102316A] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [01021D9E] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [0102316A] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenUserClassesRoot] [0102291F] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [01021D9E] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!RegCreateKeyExA] [01022FA8] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!RegOpenKeyExA] [0102316A] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [01021CCB] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExA] [0102316A] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [010230A2] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCloseKey] [01022F22] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [01023255] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [01021DF7] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [01021D9E] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCDSrv.exe[656] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [01021E11] F:\Nero\Nero 9\InCD\InCDSrv.exe (incdsrv/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0102DC1C] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA] [0102F355] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA] [0102F517] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [0102F44F] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0102DC1C] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0102DC1C] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [0102F355] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [0102F44F] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [0102F517] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0102DCEF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0102DC1C] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [0102F517] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [0102F44F] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenUserClassesRoot] [0102F145] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0102DC1C] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0102DCEF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [0102F44F] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [0102F517] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0102DC1C] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0102DCEF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExA] [0102F517] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCreateKeyExW] [0102F44F] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [0102F44F] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCloseKey] [0102F2CF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [0102F602] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [0102DD48] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [0102DCEF] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
IAT F:\Nero\Nero 9\InCD\InCD.exe[2668] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [0102DD62] F:\Nero\Nero 9\InCD\InCD.exe (InCD/Nero AG)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice tdrpm251.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device Udfs.SYS (UDF File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device ACPI.sys (ACPI-Treiber für NT/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device nvatabus.sys (NVIDIA® nForce(TM) IDE Performance Driver/NVIDIA Corporation)
Device USBSTOR.SYS (USB Mass Storage Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)
Device InCDFs.sys (InCD File System Driver/Nero AG)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- EOF - GMER 1.0.15 ---- 2. OSAM Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 16:24:55 on 05.03.2012
OS: Windows XP Home Edition Service Pack 3 (Build 2600)
Default Browser: Google Inc. Google Chrome 17.0.963.56
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Boot Execute]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager )-----
"BootExecute" - ? - sdnclean.exe (File not found)
[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1177238915-764733703-839522115-1004Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1177238915-764733703-839522115-1004UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1177238915-764733703-839522115-1005Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\Gerhard\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-1177238915-764733703-839522115-1005UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\Gerhard\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"Microsoft_Hardware_Launch_IPoint_exe.job" - "Microsoft Corporation" - C:\Programme\Microsoft IntelliPoint\ipoint.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"bdeadmin.cpl" - ? - C:\WINDOWS\system32\bdeadmin.cpl
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\WINDOWS\system32\DivXControlPanelApplet.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
"pmxusb.cpl" - ? - C:\WINDOWS\system32\pmxusb.cpl (File found, but it contains no detailed information)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Nero BurnRights" - "Nero AG" - F:\Nero\Nero 9\Nero BurnRights\NeroBurnRights_cpl.cpl
"QuickTime" - "Apple Inc." - C:\Programme\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Acronis Snapshots Manager" (snapman) - "Acronis" - C:\WINDOWS\System32\DRIVERS\snapman.sys
"Acronis Try&Decide and Restore Points filter (build 251)" (tdrpman251) - "Acronis" - C:\WINDOWS\System32\DRIVERS\tdrpm251.sys
"afcdp" (afcdp) - "Acronis" - C:\WINDOWS\System32\DRIVERS\afcdp.sys
"ArcSoft Magic-I Visual Effect" (ArcSoftKsUFilter) - "ArcSoft, Inc." - C:\WINDOWS\System32\DRIVERS\ArcSoftKsUFilter.sys
"ASAPIW2K" (ASAPIW2k) - "Pinnacle Systems GmbH" - C:\WINDOWS\System32\drivers\ASAPIW2k.sys
"AVMPORT" (AVMPORT) - "AVM Berlin" - C:\WINDOWS\System32\drivers\avmport.sys
"BHDrvx86" (BHDrvx86) - "Symantec Corporation" - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120215.001\BHDrvx86.sys
"catchme" (catchme) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\catchme.sys (File not found)
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found)
"cpuz132" (cpuz132) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\cpuz132\cpuz132_x32.sys (File not found)
"DSL-Manager Service" (TSMPacket) - "T-Systems" - C:\WINDOWS\System32\DRIVERS\tsmpkt.sys
"dsltestSp5 NDIS Protocol Driver" (dsltestSp5) - "Printing Communications Assoc., Inc. (PCAUSA)" - C:\WINDOWS\System32\Drivers\dsltestSp5.sys
"DXSOFTIO" (DXSOFTIO) - ? - C:\WINDOWS\system32\drivers\DXSOFTIO.sys (File found, but it contains no detailed information)
"EraserUtilRebootDrv" (EraserUtilRebootDrv) - "Symantec Corporation" - C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
"FXDrv32" (FXDrv32) - ? - H:\Windows\FXDrv32.sys (File not found)
"Hauppauge SMS1000-based" (hcw17bda) - ? - C:\WINDOWS\System32\drivers\hcw17bda.sys (File not found)
"HID Infrared Remote Receiver" (RTL2832U_IRHID) - ? - C:\WINDOWS\System32\DRIVERS\RTL2832U_IRHID.sys (File not found)
"i2omgmt" (i2omgmt) - ? - C:\WINDOWS\system32\drivers\i2omgmt.sys (File not found)
"IDSxpx86" (IDSxpx86) - "Symantec Corporation" - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120303.003\IDSxpx86.sys
"Kithara »DOS Enabler« 6" (Kithara-kdos6) - "Kithara Software" - C:\WINDOWS\system32\kdos6.sys
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys (File not found)
"MagicTune" (MagicTune) - ? - C:\WINDOWS\System32\drivers\MTiCtwl.sys (File found, but it contains no detailed information)
"mbamchameleon" (mbamchameleon) - ? - C:\WINDOWS\system32\drivers\mbamchameleon.sys (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\WINDOWS\system32\drivers\mbam.sys
"Microsoft IntelliPoint Features driver" (IPFilter) - "Microsoft Corporation" - C:\WINDOWS\System32\DRIVERS\IPFilter.sys
"MIINPazX NDIS Protocol Driver" (MIINPazX) - "Deutsche Telekom AG, Marmiko IT-Solutions GmbH" - C:\PROGRA~1\GEMEIN~1\MARMIK~1\MInfraIS\MIINPazX.SYS
"NAVENG" (NAVENG) - "Symantec Corporation" - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120304.006\NAVENG.SYS
"NAVEX15" (NAVEX15) - "Symantec Corporation" - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120304.006\NAVEX15.SYS
"Nero InCDPass Driver" (InCDPass) - "Nero AG" - C:\WINDOWS\System32\DRIVERS\InCDPass.sys
"Nero UDF File System Driver" (InCDFs) - "Nero AG" - C:\WINDOWS\System32\DRIVERS\InCDFs.sys
"Nero UDF File System Recognizer Driver" (InCDRec) - "Nero AG" - C:\WINDOWS\System32\DRIVERS\InCDRec.sys
"Norton Internet Security Settings Manager" (ccSet_NIS) - "Symantec Corporation" - C:\WINDOWS\system32\drivers\NIS\1305000.091\ccSetx86.sys
"PADUS ASPI SHELL" (pfc) - "Padus, Inc." - C:\WINDOWS\System32\drivers\pfc.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys (File not found)
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys (File not found)
"pgtdqpog" (pgtdqpog) - ? - C:\DOKUME~1\Admin\LOKALE~1\Temp\pgtdqpog.sys (Hidden registry entry, rootkit activity | File not found)
"PPdus ASPI Shell" (Afc) - "Arcsoft, Inc." - C:\WINDOWS\System32\drivers\Afc.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\WINDOWS\System32\Drivers\PxHelp20.sys
"REALTEK 2832U BDA Driver" (RTL2832UBDA) - ? - C:\WINDOWS\System32\drivers\RTL2832UBDA.sys (File not found)
"REALTEK 2832U USB Driver" (RTL2832UUSB) - ? - C:\WINDOWS\System32\Drivers\RTL2832UUSB.sys (File not found)
"Symantec Data Store" (SymDS) - "Symantec Corporation" - C:\WINDOWS\System32\drivers\NIS\1305000.091\SYMDS.SYS
"Symantec Eraser Control driver" (eeCtrl) - "Symantec Corporation" - C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys
"Symantec Extended File Attributes" (SymEFA) - "Symantec Corporation" - C:\WINDOWS\System32\drivers\NIS\1305000.091\SYMEFA.SYS
"Symantec Iron Driver" (SymIRON) - "Symantec Corporation" - C:\WINDOWS\system32\drivers\NIS\1305000.091\Ironx86.SYS
"Symantec Network Dispatch Driver" (SYMTDI) - "Symantec Corporation" - C:\WINDOWS\System32\Drivers\NIS\1305000.091\SYMTDI.SYS
"Symantec Real Time Storage Protection" (SRTSP) - "Symantec Corporation" - C:\WINDOWS\System32\Drivers\NIS\1305000.091\SRTSP.SYS
"Symantec Real Time Storage Protection (PEL)" (SRTSPX) - "Symantec Corporation" - C:\WINDOWS\system32\drivers\NIS\1305000.091\SRTSPX.SYS
"SymEvent" (SymEvent) - "Symantec Corporation" - C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
"TuneUpUtilitiesDrv" (TuneUpUtilitiesDrv) - "TuneUp Software" - C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys
"USB PC Camera (SNPSTD3)" (SNPSTD3) - ? - C:\WINDOWS\System32\DRIVERS\snpstd3.sys (File not found)
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys (File not found)
[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Programme\7-Zip\7-zip.dll
{4838CD50-7E5D-4811-9B17-C47A85539F28} "TuneUp Disk Space Explorer Shell Extension" - "TuneUp Software" - C:\Programme\TuneUp Utilities 2012\DseShExt-x86.dll
{4858E7D9-8E12-45a3-B6A3-1CD128C9D403} "TuneUp Shredder Shell Extension" - "TuneUp Software" - C:\Programme\TuneUp Utilities 2012\SDShelEx-win32.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR shell extension" - ? - (File not found | COM-object registry key not found)
{E0D79304-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WinZip\WZSHLSTB.DLL
{E0D79305-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WinZip\WZSHLSTB.DLL
{E0D79306-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WinZip\WZSHLSTB.DLL
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{888078C6-70B2-4F88-8EE7-1F50DDEA6120} "CeWe Color AG & Co. OHG Control" - "CeWe Color AG & Co. OHG" - C:\WINDOWS\Downloaded Program Files\ImageUploader6.ocx / https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} "DivXBrowserPlugin Object" - "DivX, LLC" - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll / hxxp://download.divx.com/player/DivXBrowserPlugin.cab
{CAC677B6-4963-4305-9066-0BD135CD9233} "IPSUploader4 Control" - "IP Labs GmbH - Germany" - C:\WINDOWS\Downloaded Program Files\IPSUploader4.ocx / hxxp://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{5AE58FCF-6F6A-49B2-B064-02492C66E3F4} "MUCatalogWebControl Class" - "Microsoft Corporation" - C:\WINDOWS\system32\MicrosoftUpdateCatalogWebControl.dll / hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1234523148772
{ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} "OCXDownloadChecker Control" - "GeoVision" - C:\WINDOWS\DOWNLO~1\OCXDOW~1.OCX / hxxp://stream.d-atv.net/cab/OCXChecker_8000.cab
{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} "Symantec AntiVirus scanner" - "Symantec Corporation" - C:\WINDOWS\Downloaded Program Files\avsniff.dll / hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
{6A344D34-5231-452A-8A57-D064AC9B7862} "Symantec Download Manager" - "Symantec Corporation" - C:\WINDOWS\Downloaded Program Files\symdlmgr.dll / https://webdl.symantec.com/activex/symdlmgr.cab
{644E432F-49D3-41A1-8DD5-E099162EEEC5} "Symantec RuFSI Utility Class" - "Symantec Corporation" - C:\WINDOWS\Downloaded Program Files\rufsi.dll / hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "ClsidExtension" - "Microsoft Corporation" - F:\PROGRA~2\MICROS~2\INetRepl.dll
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "Create Mobile Favorite" - "Microsoft Corporation" - F:\PROGRA~2\MICROS~2\INetRepl.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} "Norton Toolbar" - "Symantec Corporation" - C:\Programme\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Programme\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} "Norton Identity Protection" - "Symantec Corporation" - C:\Programme\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
{6D53EC84-6AAE-4787-AEEE-F4628F01010C} "Norton Vulnerability Protection" - "Symantec Corporation" - C:\Programme\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"desktop.ini" - ? - C:\Dokumente und Einstellungen\Admin\Startmenü\Programme\Autostart\desktop.ini
"DSL-Manager.lnk" - "T-Systems Enterprise Services GmbH" - C:\Programme\DSL-Manager\DslMgr.exe (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"H/PC Connection Agent" - "Microsoft Corporation" - "F:\Programme\Microsoft ActiveSync\wcescomm.exe"
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"InCD" - "Nero AG" - "F:\Nero\Nero 9\InCD\InCD.exe"
"IntelliPoint" - "Microsoft Corporation" - "C:\Programme\Microsoft IntelliPoint\ipoint.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"SetIcon" - "Standard Microsystems Corp." - C:\Program Files\SMSC\Seticon.exe
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"FRITZ!fax Color Monitor" - "AVM Berlin" - C:\WINDOWS\system32\FritzVistaColorMon.dll
"FRITZ!fax Color Port Monitor" - "AVM Berlin GmbH" - C:\WINDOWS\system32\FritzColorPort.dll
"FRITZ!fax Port Monitor" - "AVM Berlin" - C:\WINDOWS\system32\FritzVistaMon.dll
"PDFCreator" - ? - C:\WINDOWS\system32\pdfcmnnt.dll (File found, but it contains no detailed information)
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"Acronis Nonstop Backup service" (afcdpsrv) - "Acronis" - C:\Programme\Gemeinsame Dateien\Acronis\CDP\afcdpsrv.exe
"Acronis Scheduler2 Service" (AcrSch2Svc) - "Acronis" - C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
"Anwendungsverwaltung" (AppMgmt) - ? - C:\WINDOWS\System32\appmgmts.dll (File not found)
"ArcSoft Connect Daemon" (ACDaemon) - ? - C:\Programme\Gemeinsame Dateien\ArcSoft\Connection Service\Bin\ACService.exe (File not found)
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Programme\CyberLink\Shared files\RichVideo.exe
"DSL-Manager" (TDslMgrService) - "T-Systems Enterprise Services GmbH" - F:\Programme\DSL-Manager\DslMgrSvc.exe
"Google Software Updater" (gusvc) - ? - "C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe" (File not found)
"Google Update Service (gupdate1c998fa88134ee4)" (gupdate1c998fa88134ee4) - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"InCD Helper" (InCDSrv) - "Nero AG" - F:\Nero\Nero 9\InCD\InCDSrv.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Nero BackItUp Scheduler 4.0" (Nero BackItUp Scheduler 4.0) - "Nero AG" - C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe
"Nero Registry InCD Service" (NeroRegInCDSrv) - "Nero AG" - F:\Nero\Nero 9\InCD\NBHRegInCDSrv.exe
"Norton Internet Security" (NIS) - "Symantec Corporation" - C:\Programme\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
"StarMoney 8.0 OnlineUpdate" (StarMoney 8.0 OnlineUpdate) - "Star Finanz - Software Entwicklung und Vertriebs GmbH" - F:\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
"TomTomHOMEService" (TomTomHOMEService) - "TomTom" - C:\Programme\TomTom HOME 2\TomTomHOMEService.exe
"TuneUp Utilities Service" (TuneUp.UtilitiesSvc) - "TuneUp Software" - C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
"Windows Presentation Foundation Font Cache 4.0.0.0" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - "Sebastian Stoff" - C:\WINDOWS\system32\Orbitron.scr
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions )-----
{c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" - ? - appmgmts.dll (File not found)
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru 3. aswMBR Code:
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-05 16:30:48
-----------------------------
16:30:48.453 OS Version: Windows 5.1.2600 Service Pack 3
16:30:48.453 Number of processors: 1 586 0x801
16:30:48.453 ComputerName: WS-1 UserName:
16:30:49.796 Initialize success
16:38:13.593 AVAST engine defs: 12030500
16:38:33.421 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:38:33.421 Disk 0 Vendor: HDS728080PLA380 PF2OA6EA Size: 78533MB BusType: 3
16:38:33.421 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000079
16:38:33.421 Disk 1 Vendor: IC35L120AVV207-0 V24OA66A Size: 117800MB BusType: 3
16:38:33.437 Disk 0 MBR read successfully
16:38:33.437 Disk 0 MBR scan
16:38:33.468 Disk 0 Windows XP default MBR code
16:38:33.468 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 78528 MB offset 63
16:38:33.484 Disk 0 scanning sectors +160826715
16:38:33.546 Disk 0 scanning C:\WINDOWS\system32\drivers
16:38:45.890 Service scanning
16:39:07.546 Modules scanning
16:39:14.812 Disk 0 trace - called modules:
16:39:14.828 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
16:39:14.828 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89f1fab8]
16:39:14.828 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\00000078[0x89f55a18]
16:39:14.828 5 ACPI.sys[f75ad620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x89f57d98]
16:39:15.171 AVAST engine scan C:\WINDOWS
16:39:20.609 AVAST engine scan C:\WINDOWS\system32
16:42:25.593 AVAST engine scan C:\WINDOWS\system32\drivers
16:42:47.093 AVAST engine scan C:\Dokumente und Einstellungen\Admin
16:44:21.375 AVAST engine scan C:\Dokumente und Einstellungen\All Users
16:46:41.828 Scan finished successfully
16:47:01.484 Disk 0 MBR has been saved successfully to "C:\Dokumente und Einstellungen\Admin\Desktop\MBR.dat"
16:47:01.500 The log file has been saved successfully to "C:\Dokumente und Einstellungen\Admin\Desktop\aswMBR.txt" Das soll es damit sein. GMER klappte übrigens beim 2. Versuch.
Sonst liefen alle Scans problemlos.
Gruß
Gerhard |