Hallo Arne, so jetz hab' ich glaub' ich alles abgearbeitet.
anbei Log von GMER: Code:
GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-06-04 11:15:26
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-1 Hitachi_HTS725016A9A362 rev.PCBOC70E
Running: gmer.exe; Driver: C:\Users\admin\AppData\Local\Temp\ugdiafow.sys
---- System - GMER 1.0.15 ----
SSDT 91701350 ZwAlertResumeThread
SSDT 91701690 ZwAlertThread
SSDT 917FF7F0 ZwAllocateVirtualMemory
SSDT 879C1070 ZwAlpcConnectPort
SSDT 91901778 ZwAssignProcessToJobObject
SSDT 91901D20 ZwCreateMutant
SSDT 91901498 ZwCreateSymbolicLinkObject
SSDT 87FDFD68 ZwCreateThread
SSDT 91901858 ZwDebugActiveProcess
SSDT 917FF9C0 ZwDuplicateObject
SSDT 91782E70 ZwFreeVirtualMemory
SSDT 91701190 ZwImpersonateAnonymousToken
SSDT 91701270 ZwImpersonateThread
SSDT 879C1108 ZwLoadDriver
SSDT 91782D70 ZwMapViewOfSection
SSDT 91901C40 ZwOpenEvent
SSDT 87F89B90 ZwOpenProcess
SSDT 917FF8E0 ZwOpenProcessToken
SSDT 91901A80 ZwOpenSection
SSDT 87F89AA0 ZwOpenThread
SSDT 91901688 ZwProtectVirtualMemory
SSDT 91982C40 ZwResumeThread
SSDT 91982EE0 ZwSetContextThread
SSDT 91982FC0 ZwSetInformationProcess
SSDT 91901938 ZwSetSystemInformation
SSDT 91901B60 ZwSuspendProcess
SSDT 91982D20 ZwSuspendThread
SSDT 87FDFE68 ZwTerminateProcess
SSDT 91982E00 ZwTerminateThread
SSDT 91782C90 ZwUnmapViewOfSection
SSDT 91782F60 ZwWriteVirtualMemory
SSDT 91901588 ZwCreateThreadEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 820C18A0 8 Bytes [50, 13, 70, 91, 90, 16, 70, ...] {PUSH EAX; ADC ESI, [EAX-0x6f]; NOP ; PUSH SS; JO 0xffffffffffffff99}
.text ntkrnlpa.exe!KeSetEvent + 131 820C18B4 4 Bytes [F0, F7, 7F, 91]
.text ntkrnlpa.exe!KeSetEvent + 13D 820C18C0 4 Bytes [70, 10, 9C, 87]
.text ntkrnlpa.exe!KeSetEvent + 191 820C1914 4 Bytes [78, 17, 90, 91] {JS 0x19; NOP ; XCHG ECX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 1F5 820C1978 4 Bytes [20, 1D, 90, 91]
.text ...
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8D60F380, 0x3590D2, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [742D7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7432A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [742DBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [742CF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [742D75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [742CE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74308395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [742DDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [742CFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [742CFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [742C71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7435CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [742FC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [742CD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [742C6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [742C687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3656] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [742D2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT-Dateisystemtreiber/Microsoft Corporation)
AttachedDevice tdrpm273.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device pci.sys (NT-Plug & Play PCI-Enumerator/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
Device volmgr.sys (Volume Manager Driver/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
Device usbhub.sys (Default Hub Driver for USB/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0021864665a1
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0021864665a1 (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\NCW\ncwmh.db-journal 0 bytes
---- EOF - GMER 1.0.15 ---- und noch das Log von OSAM: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 11:19:50 on 04.06.2011
OS: Windows Vista Business Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Microsoft Corporation Internet Explorer 9.00.8112.16421
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"Norton Internet Security - admin - Vollständiger Systemscan.job" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\navw32.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"ASFConfig.cpl" - "Broadcom Corporation" - C:\Windows\system32\ASFConfig.cpl
"BACSCPL.cpl" - ? - C:\Windows\system32\BACSCPL.cpl
"DMdm32.cpl" - ? - C:\Windows\system32\DMdm32.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.cpl
"nView.cpl" - "NVIDIA Corporation" - C:\Windows\system32\nView.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"CinePlayer DVD Decoder Options" - "Sonic Solutions" - C:\Program Files\Sonic\CinePlayer Decoder Pack\cmdvdpak.cpl
"PROSet Tools" - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\iproset.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Acronis Snapshots Manager" (snapman) - "Acronis" - C:\Windows\System32\DRIVERS\snapman.sys
"Acronis True Image FS Filter" (tifsfilter) - "Acronis" - C:\Windows\System32\DRIVERS\tifsfilt.sys
"Acronis Try&Decide and Restore Points filter (build 273)" (tdrpman273) - "Acronis" - C:\Windows\System32\DRIVERS\tdrpm273.sys
"afcdp" (afcdp) - "Acronis" - C:\Windows\System32\DRIVERS\afcdp.sys
"BASFND" (BASFND) - "Broadcom Corporation" - C:\Program Files\Broadcom\ASFIPMon\BASFND.sys
"BHDrvx86" (BHDrvx86) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20110518.001\BHDrvx86.sys
"catchme" (catchme) - ? - C:\Users\admin\AppData\Local\Temp\catchme.sys (File not found)
"EraserUtilDrv11110" (EraserUtilDrv11110) - ? - C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11110.sys (File not found)
"EraserUtilRebootDrv" (EraserUtilRebootDrv) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
"IDSVix86" (IDSVix86) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20110602.001\IDSvix86.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found)
"NAVENG" (NAVENG) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110603.002\NAVENG.SYS
"NAVEX15" (NAVEX15) - "Symantec Corporation" - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110603.002\NAVEX15.SYS
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"Symantec Data Store" (SymDS) - "Symantec Corporation" - C:\Windows\System32\drivers\NIS\1206000.01D\SYMDS.SYS
"Symantec Eraser Control driver" (eeCtrl) - "Symantec Corporation" - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
"Symantec Extended File Attributes" (SymEFA) - "Symantec Corporation" - C:\Windows\System32\drivers\NIS\1206000.01D\SYMEFA.SYS
"Symantec Iron Driver" (SymIRON) - "Symantec Corporation" - C:\Windows\system32\drivers\NIS\1206000.01D\Ironx86.SYS
"Symantec Real Time Storage Protection" (SRTSP) - "Symantec Corporation" - C:\Windows\System32\Drivers\NIS\1206000.01D\SRTSP.SYS
"Symantec Real Time Storage Protection (PEL)" (SRTSPX) - "Symantec Corporation" - C:\Windows\system32\drivers\NIS\1206000.01D\SRTSPX.SYS
"Symantec Vista Network Dispatch Driver" (SYMTDIv) - "Symantec Corporation" - C:\Windows\System32\Drivers\NIS\1206000.01D\SYMTDIV.SYS
"SymEvent" (SymEvent) - "Symantec Corporation" - C:\Windows\system32\Drivers\SYMEVENT.SYS
"ugdiafow" (ugdiafow) - ? - C:\Users\admin\AppData\Local\Temp\ugdiafow.sys (Hidden registry entry, rootkit activity | File not found)
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{C539A15B-3AF9-4c92-B771-50CB78F5C751} "Acronis Secure Zone" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\tishell.dll
{C539A15A-3AF9-4c92-B771-50CB78F5C751} "Acronis True Image Shell Context Menu Extension" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\tishell.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\Windows\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\Windows\system32\nvshell.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
{00020d75-0000-0000-c000-000000000046} "Microsoft Office Outlook" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\Windows\system32\nvshell.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
{E0D79304-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79305-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79306-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
{E0D79307-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, S.L." - C:\Program Files\WinZip\wzshlstb.dll
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "Norton Toolbar" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} "DellSystem.Scanner" - ? - C:\Windows\Downloaded Program Files\DellSystem.dll / hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.6.0_05" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10q.ocx / hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
{1E54D648-B804-468d-BC78-4AFFED8E262F} "System Requirements Lab Class" - "Husdawg, LLC" - C:\Windows\Downloaded Program Files\sysreqlab_nvd.dll / hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
{49312E18-AA92-4CC2-BB97-55DEA7BCADD6} "WMI Class" - ? - C:\Windows\system32\Dell\SYSTEM~1\SysPro.exe / hxxp://support.euro.dell.com/systemprofiler/SysProExe.CAB
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? - (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} "Norton Toolbar" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{6D53EC84-6AAE-4787-AEEE-F4628F01010C} "Symantec Intrusion Prevention" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} "Symantec NCO BHO" - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Digital Line Detect.lnk" - "Avanquest Software " - C:\Program Files\Digital Line Detect\DLG.exe (Shortcut exists | File exists)
"QuickSet.lnk" - "Dell Inc." - C:\Program Files\Dell\QuickSet\quickset.exe (Shortcut exists | File exists)
"WinZip Quick Pick.lnk" - "WinZip Computing, S.L." - C:\Program Files\WinZip\WZQKPICK.EXE (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ISUSPM" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Acronis Scheduler2 Service" - "Acronis" - "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"FreePDF Assistant" - "shbox.de" - C:\Program Files\FreePDF_XP\fpassist.exe
"IAAnotif" - "Intel Corporation" - "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
"PDVDDXSrv" - "CyberLink Corp." - "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
"SAOB Monitor" - "Acronis" - C:\Program Files\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"TrueImageMonitor.exe" - "Acronis" - "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll
"Redirected Port" - ? - C:\Windows\system32\redmonnt.dll (File found, but it contains no detailed information)
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Acronis Nonstop Backup-Dienst" (afcdpsrv) - "Acronis" - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
"Acronis Scheduler2 Service" (AcrSch2Svc) - "Acronis" - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
"Bluetooth Feature Support" (BthFilterHelper) - "CSR, plc" - C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe
"Broadcom ASF IP and SMBIOS Mailbox Monitor" (ASFIPmon) - "Broadcom Corporation" - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
"Dell Internal Network Card Power Management" (nicconfigsvc) - "Dell Inc." - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
"Intel(R) Matrix Storage Event Monitor" (IAANTMON) - "Intel Corporation" - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
"Intel(R) PROSet/Wireless Event Log" (EvtEng) - "Intel(R) Corporation" - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
"Intel(R) PROSet/Wireless Registry Service" (RegSrvc) - "Intel(R) Corporation" - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Norton Internet Security" (NIS) - "Symantec Corporation" - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
"NTRU TSS v1.2.1.29 TCS" (tcsd_win32.exe) - ? - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe (File found, but it contains no detailed information)
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"stllssvr" (stllssvr) - "MicroVision Development, Inc." - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru und zu guter letzt noch MBR-Log: Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Business Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Latitude D630
Logical Drives Mask: 0x0002003c
Kernel Drivers (total 181):
0x82015000 \SystemRoot\system32\ntkrnlpa.exe
0x823CF000 \SystemRoot\system32\hal.dll
0x80400000 \SystemRoot\system32\kdcom.dll
0x80407000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80477000 \SystemRoot\system32\PSHED.dll
0x80488000 \SystemRoot\system32\BOOTVID.dll
0x80490000 \SystemRoot\system32\CLFS.SYS
0x804D1000 \SystemRoot\system32\CI.dll
0x80606000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80682000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8068F000 \SystemRoot\system32\drivers\acpi.sys
0x806D5000 \SystemRoot\system32\drivers\WMILIB.SYS
0x806DE000 \SystemRoot\system32\drivers\msisadrv.sys
0x806E6000 \SystemRoot\system32\drivers\pci.sys
0x8070D000 \SystemRoot\System32\drivers\partmgr.sys
0x8071C000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8071F000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x80729000 \SystemRoot\system32\drivers\volmgr.sys
0x80738000 \SystemRoot\System32\drivers\volmgrx.sys
0x80782000 \SystemRoot\system32\DRIVERS\intelide.sys
0x80789000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x80797000 \SystemRoot\system32\DRIVERS\pcmcia.sys
0x807C4000 \SystemRoot\system32\drivers\pciide.sys
0x807CB000 \SystemRoot\System32\drivers\mountmgr.sys
0x82603000 \SystemRoot\system32\drivers\iastorv.sys
0x826A4000 \SystemRoot\system32\drivers\iastor.sys
0x82762000 \SystemRoot\system32\drivers\atapi.sys
0x8276A000 \SystemRoot\system32\drivers\ataport.SYS
0x82788000 \SystemRoot\system32\drivers\fltmgr.sys
0x88206000 \SystemRoot\system32\drivers\NIS\1206000.01D\SYMDS.SYS
0x8825D000 \SystemRoot\system32\drivers\fileinfo.sys
0x8826D000 \SystemRoot\system32\drivers\NIS\1206000.01D\SYMEFA.SYS
0x88328000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x88332000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8840F000 \SystemRoot\system32\drivers\ndis.sys
0x8851A000 \SystemRoot\system32\drivers\msrpc.sys
0x88545000 \SystemRoot\system32\drivers\NETIO.SYS
0x88607000 \SystemRoot\System32\drivers\tcpip.sys
0x886F1000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8870C000 \SystemRoot\system32\DRIVERS\timntr.sys
0x8880C000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8891C000 \SystemRoot\system32\drivers\volsnap.sys
0x88A08000 \SystemRoot\system32\DRIVERS\tdrpm273.sys
0x88ABE000 \SystemRoot\System32\Drivers\spldr.sys
0x88AC6000 \SystemRoot\system32\DRIVERS\snapman.sys
0x88AEE000 \SystemRoot\system32\DRIVERS\PBADRV.sys
0x88AF9000 \SystemRoot\System32\Drivers\mup.sys
0x88B08000 \SystemRoot\System32\drivers\ecache.sys
0x88B2F000 \SystemRoot\system32\drivers\disk.sys
0x88B40000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x88B61000 \SystemRoot\system32\drivers\crcdisk.sys
0x88B8A000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x88B95000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x88B9E000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8D60F000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8DD53000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8DDF3000 \SystemRoot\System32\drivers\watchdog.sys
0x8D600000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x88BAD000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x88BEB000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x88955000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8EA00000 \SystemRoot\system32\DRIVERS\NETw5v32.sys
0x8EE13000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8EE23000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8EE31000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EE44000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0x8EE70000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EE7B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EE86000 \SystemRoot\system32\DRIVERS\serial.sys
0x8EEA0000 \SystemRoot\system32\DRIVERS\serenum.sys
0x8EEAA000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8EEC2000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8EEC6000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8EECF000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8EEFE000 \SystemRoot\system32\DRIVERS\storport.sys
0x8EF3F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8EF4A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EF61000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EF6C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EF8F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8EF9E000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8EFB2000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8FC06000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0x8FC8F000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FC9F000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8FCA1000 \SystemRoot\system32\DRIVERS\ks.sys
0x8FCCB000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8FCD5000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8FCE2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8FD17000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8FD28000 \SystemRoot\system32\drivers\stwrt.sys
0x8FD7D000 \SystemRoot\system32\drivers\portcls.sys
0x8FDAA000 \SystemRoot\system32\drivers\drmk.sys
0x8879E000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x90607000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x9070A000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x907BE000 \SystemRoot\system32\drivers\modem.sys
0x907CB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x907D4000 \SystemRoot\System32\Drivers\Null.SYS
0x907DB000 \SystemRoot\System32\Drivers\Beep.SYS
0x907E2000 \SystemRoot\System32\drivers\vga.sys
0x8FDCF000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x907EE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x907F6000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8FDF0000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8EFC7000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8EFD5000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8EFDE000 \SystemRoot\system32\DRIVERS\tdx.sys
0x88580000 \SystemRoot\System32\Drivers\NIS\1206000.01D\SYMTDIV.SYS
0x885D9000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
0x889E2000 \SystemRoot\system32\DRIVERS\smb.sys
0x883A3000 \SystemRoot\system32\drivers\afd.sys
0x827BA000 \SystemRoot\System32\DRIVERS\netbt.sys
0x887DB000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8EFF4000 \SystemRoot\system32\DRIVERS\SymIMv.sys
0x887F1000 \SystemRoot\system32\DRIVERS\netbios.sys
0x883EB000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x807DB000 \SystemRoot\system32\drivers\NIS\1206000.01D\Ironx86.SYS
0x88800000 \SystemRoot\system32\drivers\NIS\1206000.01D\SRTSPX.SYS
0x805B1000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x889F6000 \SystemRoot\system32\drivers\nsiproxy.sys
0x91001000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20110602.001\IDSvix86.sys
0x9105C000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x910BA000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0x910D8000 \SystemRoot\System32\Drivers\dfsc.sys
0x910EF000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20110518.001\BHDrvx86.sys
0x911B7000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x911C0000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x911D0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x911D7000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x911D9000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x911E1000 \SystemRoot\System32\Drivers\crashdmp.sys
0x911EE000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x88A00000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x88B6A000 \SystemRoot\System32\Drivers\oz776.sys
0x88B7A000 \SystemRoot\System32\Drivers\SMCLIB.SYS
0x9A050000 \SystemRoot\System32\win32k.sys
0x88400000 \SystemRoot\System32\drivers\Dxapi.sys
0x827EC000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9A270000 \SystemRoot\System32\TSDDD.dll
0x9A290000 \SystemRoot\System32\cdd.dll
0x9B009000 \SystemRoot\system32\drivers\luafv.sys
0x9B024000 \SystemRoot\system32\DRIVERS\tifsfilt.sys
0x9B02E000 \SystemRoot\system32\drivers\spsys.sys
0x9B0DE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9B0EE000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9B118000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9B122000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9B135000 \SystemRoot\system32\drivers\HTTP.sys
0x9B1A2000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9B1BF000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9B1D8000 \SystemRoot\System32\drivers\mpsdrv.sys
0xA040F000 \SystemRoot\system32\drivers\mrxdav.sys
0xA0430000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA044F000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xA0488000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xA04A0000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA04C8000 \SystemRoot\System32\DRIVERS\srv.sys
0xA052F000 \??\C:\Program Files\Broadcom\ASFIPMon\BASFND.sys
0xA0531000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xA1608000 \SystemRoot\system32\drivers\peauth.sys
0xA16E6000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA16F0000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA16FC000 \SystemRoot\system32\DRIVERS\xaudio.sys
0xA1704000 \SystemRoot\system32\DRIVERS\afcdp.sys
0xA172C000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xA1742000 \SystemRoot\System32\Drivers\NIS\1206000.01D\SRTSP.SYS
0xA17C8000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xA05B5000 \SystemRoot\System32\Drivers\fastfat.SYS
0xA17DD000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0xA05DD000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0xB9206000 \??\C:\Users\admin\AppData\Local\Temp\ugdiafow.sys
0xB921F000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110603.002\NAVEX15.SYS
0xB9396000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110603.002\NAVENG.SYS
0xB93AA000 \SystemRoot\system32\DRIVERS\BthFilt.sys
0xB93B2000 \SystemRoot\System32\Drivers\BTHUSB.sys
0xA0535000 \SystemRoot\System32\Drivers\bthport.sys
0xB93BF000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0xB93E8000 \SystemRoot\system32\DRIVERS\BthEnum.sys
0xAC60C000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x77280000 \Windows\System32\ntdll.dll
Processes (total 76):
0 System Idle Process
4 System
560 C:\Windows\System32\smss.exe
764 csrss.exe
816 C:\Windows\System32\wininit.exe
828 csrss.exe
860 C:\Windows\System32\services.exe
884 C:\Windows\System32\lsass.exe
892 C:\Windows\System32\lsm.exe
1040 C:\Windows\System32\winlogon.exe
1064 C:\Windows\System32\svchost.exe
1116 C:\Windows\System32\nvvsvc.exe
1144 C:\Windows\System32\svchost.exe
1292 C:\Windows\System32\svchost.exe
1344 C:\Windows\System32\svchost.exe
1364 C:\Windows\System32\svchost.exe
1452 C:\Windows\System32\audiodg.exe
1480 C:\Windows\System32\svchost.exe
1504 C:\Windows\System32\SLsvc.exe
1536 C:\Windows\System32\svchost.exe
1652 C:\Windows\System32\nvvsvc.exe
1776 C:\Windows\System32\svchost.exe
1904 C:\Windows\System32\wlanext.exe
1980 C:\Windows\System32\spoolsv.exe
196 C:\Windows\System32\svchost.exe
732 C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
544 C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
1076 C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
1492 C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe
1680 C:\Windows\System32\svchost.exe
2044 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
2088 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2124 C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe
2268 C:\Windows\System32\svchost.exe
2284 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
2336 C:\Windows\System32\stacsv.exe
2412 C:\Windows\System32\svchost.exe
2444 C:\Windows\System32\svchost.exe
2472 C:\Windows\System32\SearchIndexer.exe
2544 C:\Windows\System32\drivers\XAudio.exe
2588 C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
2764 WmiPrvSE.exe
3520 C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe
3576 C:\Windows\System32\dwm.exe
3628 C:\Windows\System32\taskeng.exe
3656 C:\Windows\explorer.exe
3896 C:\Program Files\DellTPad\Apoint.exe
3904 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
3912 C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
3924 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
3936 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3956 C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
3972 C:\Program Files\FreePDF_XP\fpassist.exe
2076 C:\Program Files\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe
2188 C:\Program Files\Common Files\Java\Java Update\jusched.exe
1640 C:\Windows\System32\rundll32.exe
1684 C:\Windows\System32\rundll32.exe
1272 C:\Program Files\DellTPad\ApMsgFwd.exe
124 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
3276 C:\Program Files\Digital Line Detect\DLG.exe
2276 C:\Program Files\Dell\QuickSet\quickset.exe
2920 C:\Program Files\DellTPad\hidfind.exe
2908 C:\Program Files\DellTPad\ApntEx.exe
3856 C:\Windows\System32\svchost.exe
3836 dllhost.exe
4632 WUDFHost.exe
5916 C:\Windows\System32\taskeng.exe
4436 C:\Program Files\Windows Sidebar\sidebar.exe
576 C:\Program Files\Windows Sidebar\sidebar.exe
1432 C:\Program Files\Internet Explorer\iexplore.exe
5076 C:\Program Files\Internet Explorer\iexplore.exe
3312 C:\Windows\System32\Macromed\Flash\FlashUtil10q_ActiveX.exe
5900 C:\Windows\System32\SearchProtocolHost.exe
5912 C:\Windows\System32\SearchFilterHost.exe
1636 C:\Users\admin\Desktop\MBRCheck.exe
5064 C:\Windows\System32\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000b`40100000 (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x0000000b`c0100000 (NTFS)
PhysicalDrive0 Model Number: HitachiHTS725016A9A362, Rev: PCBOC70E
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done! Viele Grüße
Wolo |