Kilmarnock | 30.09.2010 18:56 | Logfile von OSAM Zitat:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:53:02 on 30.09.2010
OS: Windows XP Home Edition Service Pack 3 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 7.00.6000.17080
Scanner Settings
Rootkits detection (hidden registry)
Rootkits detection (hidden files)
Retrieve files information
Check Microsoft signatures
Filters
Trusted entries
Empty entries
Hidden registry entries (rootkit activity)
Exclusively opened files
Not found files
Files without detailed information
Existing files
Non-startable services
Non-startable drivers
Active entries
Disabled entries
Risk Name Publisher Full Path Status
Control Panel Objects
%SystemRoot%\system32
|||||| "JAVACPL.CPL" "Sun Microsystems, Inc." C:\WINDOWS\system32\JAVACPL.CPL File exists
|||||| "TIControlPanel.cpl" "Texas Instruments Incorporated" C:\WINDOWS\system32\TIControlPanel.cpl File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
"AntiVir PersonalEdition Classic Konfiguration" C:\PROGRA~1\ANTIVI~1\avconfig.cpl File not found
|||||| "Avira AntiVir Personal - Free Antivirus " "Avira GmbH" C:\PROGRA~1\Avira\ANTIVI~1\avconfig.cpl File exists
Drivers
HKLM\SYSTEM\CurrentControlSet\Services
"Apple Mobile USB Driver" (USBAAPL) C:\WINDOWS\System32\Drivers\usbaapl.sys File not found
|||||| "avgio" (avgio) "Avira GmbH" C:\Programme\Avira\AntiVir Desktop\avgio.sys File exists
|||||| "avgntflt" (avgntflt) "Avira GmbH" C:\WINDOWS\System32\DRIVERS\avgntflt.sys File exists
|||||| "avipbb" (avipbb) "Avira GmbH" C:\WINDOWS\System32\DRIVERS\avipbb.sys File exists
"catchme" (catchme) C:\DOKUME~1\Thomas\LOKALE~1\Temp\catchme.sys File not found
|||||| "cdrbsvsd" (cdrbsvsd) "B.H.A Corporation" C:\WINDOWS\system32\drivers\cdrbsvsd.sys File exists
"Changer" (Changer) C:\WINDOWS\system32\drivers\Changer.sys File not found
"DgiVecp" (DgiVecp) C:\WINDOWS\system32\Drivers\DgiVecp.sys File not found
|||||| "Hotkey" (Hotkey) C:\WINDOWS\system32\drivers\Hotkey.sys File found, but it contains no detailed information
"Icatch(IV) Still Camera Device" (USBCamera) C:\WINDOWS\System32\Drivers\Bulk533.sys File not found
"lbrtfdc" (lbrtfdc) C:\WINDOWS\system32\drivers\lbrtfdc.sys File not found
"mailKmd" (mailKmd) C:\WINDOWS\system32\drivers\mailKmd.sys File not found
|||||| "MREMP50 NDIS Protocol Driver" (MREMP50) "Printing Communications Assoc., Inc. (PCAUSA)" C:\PROGRA~1\GEMEIN~1\Motive\MREMP50.SYS File exists
"MREMP50a64 NDIS Protocol Driver" (MREMP50a64) C:\PROGRA~1\GEMEIN~1\Motive\MREMP50a64.SYS File not found
"MREMPR5 NDIS Protocol Driver" (MREMPR5) C:\PROGRA~1\GEMEIN~1\Motive\MREMPR5.SYS File not found
"MRENDIS5 NDIS Protocol Driver" (MRENDIS5) C:\PROGRA~1\GEMEIN~1\Motive\MRENDIS5.SYS File not found
|||||| "MRESP50 NDIS Protocol Driver" (MRESP50) "Printing Communications Assoc., Inc. (PCAUSA)" C:\PROGRA~1\GEMEIN~1\Motive\MRESP50.SYS File exists
"MRESP50a64 NDIS Protocol Driver" (MRESP50a64) C:\PROGRA~1\GEMEIN~1\Motive\MRESP50a64.SYS File not found
|||||| "Padus ASPI Shell" (pfc) "Padus, Inc." C:\WINDOWS\System32\drivers\pfc.sys File exists
"PCIDump" (PCIDump) C:\WINDOWS\system32\drivers\PCIDump.sys File not found
"PDCOMP" (PDCOMP) C:\WINDOWS\system32\drivers\PDCOMP.sys File not found
"PDFRAME" (PDFRAME) C:\WINDOWS\system32\drivers\PDFRAME.sys File not found
"PDRELI" (PDRELI) C:\WINDOWS\system32\drivers\PDRELI.sys File not found
"PDRFRAME" (PDRFRAME) C:\WINDOWS\system32\drivers\PDRFRAME.sys File not found
"Polaroid Digital Cam Video" (Ca533av) C:\WINDOWS\System32\Drivers\Ca533av.sys File not found
|||||| "POWERKEY" (POWERKEY) C:\Program Files\Launch Manager\POWERKEY.sys File found, but it contains no detailed information
|||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\WINDOWS\System32\DRIVERS\ssmdrv.sys File exists
"SSPORT" (SSPORT) C:\WINDOWS\system32\Drivers\SSPORT.sys File not found
|||||| "Upper Class Filter Driver" (NTIDrvr) "NewTech Infosystems, Inc." C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys File exists
"uwdoafoc" (uwdoafoc) C:\DOKUME~1\Thomas\LOKALE~1\Temp\uwdoafoc.sys Hidden registry entry, rootkit activity | File not found
"Wbutton" (Wbutton) C:\WINDOWS\system32\drivers\Wbutton.sys File not found
"WDICA" (WDICA) C:\WINDOWS\system32\drivers\WDICA.sys File not found
Explorer
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
|||||| {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" "Microsoft Corporation" C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install File exists
HKLM\Software\Classes\Folder\shellex\ColumnHandlers
|||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Programme\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll File exists
HKLM\Software\Classes\Protocols\Handler
|||||| {3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" "Microsoft Corporation" C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\10\OWC10.DLL File exists
|||||| {CD00020A-8B95-11D1-82DB-00C04FB1625D} "Microsoft PKM KnowledgePluggable Class" "Microsoft Corporation" C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" File not found | COM-object registry key not found
|||||| {3FCEF010-09A4-11D4-8D3B-D12F9D3D8B02} "FileTimeShlExt Class" "Texas Instruments Incorporated" C:\PROGRA~1\GEMEIN~1\TISHAR~1\TICONN~1\TIShlExt.dll File exists
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" File not found | COM-object registry key not found
|||||| {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" "Microsoft Corporation" C:\Programme\Microsoft Office\Office10\msohev.dll File exists
|||||| {0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" "Microsoft Corporation" C:\Programme\Microsoft Office\Office10\OLKFSTUB.DLL File exists
|||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Programme\Avira\AntiVir Desktop\shlext.dll File exists
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "Shell Extensions for RealOne Player" File not found | COM-object registry key not found
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" File not found | COM-object registry key not found
{BD88A479-9623-4897-8546-BC62B9628F44} "SPTHandler" File not found | COM-object registry key not found
|||||| {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" "Microsoft Corporation" C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL File exists
|||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Programme\WinRAR\rarext.dll File found, but it contains no detailed information
Internet Explorer
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
"ITBar7Layout" File not found | COM-object registry key not found
"ITBarLayout" File not found | COM-object registry key not found
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units
|||||| {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} "BDSCANONLINE Control"
hxxp://download.bitdefender.com/resources/scanner/sources/de/scan8/oscan8.cab "BitDefender" C:\WINDOWS\DOWNLO~1\oscan82.ocx File exists
{DBC4B41E-1BEE-4FC3-A27D-5CF30D11056C} "CM4all Uploader Control"
https://hpt.sso.bluewin.ch/res/js/thirdparty/imageuploader/CM4allUploader.cab "Content Management AG" C:\WINDOWS\Downloaded Program Files\ImageUploader4.ocx File exists
|||| {67DABFBF-D0AB-41FA-9C46-CC0F21721616} "DivXBrowserPlugin Object"
hxxp://download.divx.com/player/DivXBrowserPlugin.cab "DivX,Inc." C:\Programme\DivX\DivX Web Player\npdivx32.dll File exists
|||| {8100D56A-5661-482C-BEE8-AFECE305D968} "Facebook Photo Uploader 5 Control"
hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab "The Facebook" C:\WINDOWS\Downloaded Program Files\PhotoUploader55.ocx File exists
{D8089245-3211-40F6-819B-9E5E92CD61A2} "FlashXControl Object"
https://royaljoker.microgaming.com/deutsch/FlashAX.cab "Microgaming Systems" C:\WINDOWS\system32\FlashAX\FlashAX.ocx File exists
{3B36B017-7E49-426B-95B0-B5CECD83C2E2} "IfolorUploader Control"
hxxp://chkr-web.ifolor.net/ORDERINGGENERAL/LowRes/app_support/ActiveX/IfolorUploader_chkr.cab "Ifolor AG" C:\WINDOWS\DOWNLO~1\IFOLOR~1.OCX File exists
|||| {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} "Image Uploader Control"
hxxp://www.extrafilm.ch/ImageUploader5.cab "Aurigma, Inc." C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx File exists
|||| {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.5.0_05"
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll File exists
|||| {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} "Java Plug-in 1.5.0_06"
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_06\bin\npjpi150_06.dll File exists
|||| {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} "Java Plug-in 1.5.0_08"
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_08\bin\npjpi150_08.dll File exists
|||| {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} "Java Plug-in 1.5.0_09"
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_09\bin\npjpi150_09.dll File exists
|||| {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} "Java Plug-in 1.5.0_10"
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_10\bin\npjpi150_10.dll File exists
|||| {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} "Java Plug-in 1.5.0_11"
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_11\bin\npjpi150_11.dll File exists
|||||| {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} "Java Plug-in 1.6.0_02"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_02\bin\npjpi160_02.dll File exists
|||||| {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} "Java Plug-in 1.6.0_03"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_03\bin\npjpi160_03.dll File exists
|||| {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.6.0_05"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll File exists
|||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_17"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre6\bin\npjpi160_17.dll File exists
|||| {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} "Java Plug-in 1.6.0_17"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre6\bin\npjpi160_17.dll File exists
|||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_17"
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre6\bin\npjpi160_17.dll File exists
Microsoft XML Parser for Java "Microsoft XML Parser for Java"
file://C:\WINDOWS\Java\classes\xmldso.cab File not found | COM-object registry key not found
|||||| {166B1BCA-3F9C-11CF-8075-444553540000} "Shockwave ActiveX Control"
hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab "Adobe Systems, Inc." C:\WINDOWS\system32\Adobe\Director\SwDir.dll File exists
|||||| {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object"
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab "Adobe Systems, Inc." C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx File exists
|||| {17492023-C23A-453E-A040-C7C580BBF700} "Windows Genuine Advantage Validation Tool"
hxxp://go.microsoft.com/fwlink/?linkid=39204 "Microsoft Corporation" C:\WINDOWS\system32\legitcheckcontrol.dll File exists
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} "{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}"
hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab File not found | COM-object registry key not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
|||||| "Exec" C:\WINDOWS\bdoscandel.exe File found, but it contains no detailed information
|| "PartyPoker.com" C:\Programme\PartyGaming\PartyPoker\RunApp.exe File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
|||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Programme\Java\jre6\bin\jp2ssv.dll File exists
|||| {E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" "Sun Microsystems, Inc." C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll File exists
Logon
%AllUsersProfile%\Startmenü\Programme\Autostart
|||| "Adobe Reader - Schnellstart.lnk" "Adobe Systems Incorporated" C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe Shortcut exists | File exists
|||||| "DESKTOP.INI" C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\DESKTOP.INI File exists
|||| "Microsoft Office.lnk" "Microsoft Corporation" C:\Programme\Microsoft Office\Office10\OSA.EXE Shortcut exists | File exists
%UserProfile%\Startmenü\Programme\Autostart
|||||| "DESKTOP.INI" C:\Dokumente und Einstellungen\Thomas\Startmenü\Programme\Autostart\DESKTOP.INI File exists
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
|||||| "avgnt" "Avira GmbH" "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min File exists
|||| "CtrlVol" "Wistron" C:\Program Files\Launch Manager\CtrlVol.exe File exists
|||| "LaunchAp" C:\Program Files\Launch Manager\LaunchAp.exe File exists
|||| "LManager" "Wistron" C:\Program Files\Launch Manager\HotkeyApp.exe File exists
|||| "LMgrOSD" C:\Program Files\Launch Manager\OSDCtrl.exe File exists
|||| "PCMService" "CyberLink Corp." "C:\Program Files\Arcade\PCMService.exe" File exists
|||| "PowerKey" "C:\Program Files\Launch Manager\PowerKey.exe" File exists
|| "preload" "Wistron" C:\Windows\RUNXMLPL.exe File exists
|||| "RemoteControl" "Cyberlink Corp." C:\Programme\CyberLink\PowerDVD\PDVDServ.exe File exists
|||| "Samsung PanelMgr" C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun File exists
|||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Programme\Java\jre6\bin\jusched.exe" File exists
|||| "Wbutton" "C:\Program Files\Launch Manager\Wbutton.exe" File exists
|||||| "{1290A33C-85F5-4164-A1BE-7DD299D4986A}" "CyberLink Corp." C:\Programme\CyberLink\PowerBackup\PBKScheduler.exe File exists
Services
HKLM\SYSTEM\CurrentControlSet\Services
"Anwendungsverwaltung" (AppMgmt) C:\WINDOWS\System32\appmgmts.dll File not found
|||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Programme\Avira\AntiVir Desktop\avguard.exe File exists
|||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Programme\Avira\AntiVir Desktop\sched.exe File exists
"HID Input Service" (HidServ) C:\WINDOWS\System32\hidserv.dll File not found
|||||| "Java Quick Starter" (JavaQuickStarterService) "Sun Microsystems, Inc." C:\Programme\Java\jre6\bin\jqs.exe File exists
|||||| "McciCMService" (McciCMService) "Motive Communications, Inc." C:\Programme\Gemeinsame Dateien\Motive\McciCMService.exe File exists
|||||| "Notebook Manager Service" (anbmService) "OSA Technologies Inc." C:\Acer\eManager\anbmServ.exe File exists
Winlogon
HKCU\Control Panel\Desktop
|||||| "SCRNSAVE.EXE" C:\WINDOWS\ACER.SCR File found, but it contains no detailed information
HKCU\Control Panel\IOProcs
"MVB" mvfs32.dll File not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
{c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" appmgmts.dll File not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
|||| "WgaLogon" "Microsoft Corporation" C:\WINDOWS\system32\WgaLogon.dll File exists
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
| |