Butterbreze | 11.10.2010 18:51 | Guten Abend Cosinus,
GMER ist mir leider nach 2,5 Mal nachts laufen lassen entweder zwischendrin oder vor dem Abspeichern des Logs abgestürzt und wie Du gesagt hast, hab ich jetzt mit den beiden anderen Logfiles stattdessen weitergemacht. (GMER braucht auch sehr lang, wenn man "files" angekreuzt hat.) Ich wusste nicht genau, ob es gut ist bei OSAM und MBRcheck sowohl Internetverbindung als auch AntiVIR aktiviert zu lassen (hatte ich), alle anderen Programe waren zu während der Checks.
Hier nun die Logs:
OSAM Logfile: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxx://www.online-solutions.ru/en/
Saved at 17:59:38 on 11.10.2010
OS: Windows XP Professional Service Pack 3 (Build 2600)
Default Browser: Microsoft Corporation Internet Explorer 8.00.6001.18702
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Inc." - C:\Programme\Apple Software Update\SoftwareUpdate.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-3267661715-3879953132-3896943877-1005Core.job" - "Google Inc." - C:\Dokumente und Einstellungen\\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskUserS-1-5-21-3267661715-3879953132-3896943877-1005UA.job" - "Google Inc." - C:\Dokumente und Einstellungen\\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"CTDetect.cpl" - "Creative Technology Ltd." - C:\WINDOWS\system32\CTDetect.cpl
"CTDevCtrl.cpl" - "Creative Technology Ltd." - C:\WINDOWS\system32\CTDevCtrl.cpl
"infocardcpl.cpl" - "Microsoft Corporation" - C:\WINDOWS\system32\infocardcpl.cpl
"javacpl.cpl" - "Sun Microsystems, Inc." - C:\WINDOWS\system32\javacpl.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvcpl.cpl
"nvtuicpl.cpl" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvtuicpl.cpl
"PRApplet.cpl" - "Intel(R) Corporation" - C:\WINDOWS\system32\PRApplet.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Adobe Version Cue CS3" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.cpl
"Avira AntiVir Windows Workstation Konfiguration" - "Avira GmbH" - C:\PROGRA~1\ANTIVI~1\avconfig.cpl
"QuickTime" - "Apple Inc." - C:\Programme\Quicktime2007\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AsfAlrt" (AsfAlrt) - "Intel Corporation" - C:\WINDOWS\System32\drivers\AsfAlrt.sys
"ati2mtaa" (ati2mtaa) - "ATI Technologies Inc." - C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys
"avgntdd" (avgntdd) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avgntdd.sys
"avgntmgr" (avgntmgr) - "Avira GmbH" - C:\WINDOWS\System32\drivers\avgntmgr.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\WINDOWS\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\DOKUME~1\xx~1\LOKALE~1\Temp\catchme.sys (File not found)
"Cdr4_xp" (Cdr4_xp) - "Roxio" - C:\WINDOWS\system32\drivers\Cdr4_xp.sys
"Cdralw2k" (Cdralw2k) - "Roxio" - C:\WINDOWS\system32\drivers\Cdralw2k.sys
"cdudf_xp" (cdudf_xp) - "Roxio" - C:\WINDOWS\system32\drivers\cdudf_xp.sys
"Changer" (Changer) - ? - C:\WINDOWS\system32\drivers\Changer.sys (File not found)
"CO_Mon" (CO_Mon) - ? - C:\WINDOWS\System32\Drivers\CO_Mon.sys (File found, but it contains no detailed information)
"dvd_2K" (dvd_2K) - "Roxio" - C:\WINDOWS\system32\drivers\dvd_2K.sys
"eye-one display" (eyeonedp) - ? - C:\WINDOWS\System32\DRIVERS\eyeonedp.sys (File found, but it contains no detailed information)
"lbrtfdc" (lbrtfdc) - ? - C:\WINDOWS\system32\drivers\lbrtfdc.sys (File not found)
"mbr" (mbr) - ? - C:\DOKUME~1\xx1\LOKALE~1\Temp\mbr.sys (File not found)
"mmc_2K" (mmc_2K) - "Roxio" - C:\WINDOWS\system32\drivers\mmc_2K.sys
"OMCI WDM Device Driver" (omci) - "Dell Computer Corporation" - C:\WINDOWS\System32\DRIVERS\omci.sys
"PCIDump" (PCIDump) - ? - C:\WINDOWS\system32\drivers\PCIDump.sys (File not found)
"PDCOMP" (PDCOMP) - ? - C:\WINDOWS\system32\drivers\PDCOMP.sys (File not found)
"PDFRAME" (PDFRAME) - ? - C:\WINDOWS\system32\drivers\PDFRAME.sys (File not found)
"PDIHWCTL" (PDIHWCTL) - "Portrait Displays, Inc." - C:\WINDOWS\System32\drivers\pdihwctl.sys
"PDRELI" (PDRELI) - ? - C:\WINDOWS\system32\drivers\PDRELI.sys (File not found)
"PDRFRAME" (PDRFRAME) - ? - C:\WINDOWS\system32\drivers\PDRFRAME.sys (File not found)
"PfModNT" (PfModNT) - "Creative Technology Ltd." - C:\WINDOWS\System32\PfModNT.sys
"pwd_2k" (pwd_2k) - "Roxio" - C:\WINDOWS\system32\drivers\pwd_2k.sys
"ssmdrv" (ssmdrv) - "AVIRA GmbH" - C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
"U3sHlpDr" (U3sHlpDr) - ? - C:\WINDOWS\System32\Drivers\U3sHlpDr.sys (File found, but it contains no detailed information)
"UdfReadr_xp" (UdfReadr_xp) - "Roxio" - C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
"WDICA" (WDICA) - ? - C:\WINDOWS\system32\drivers\WDICA.sys (File not found)
[Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Desktop\Components )-----
"(0) Source" - ? - /C:/DOKUME~1/xx~1/LOKALE~1/Temp/msohtml1/01/clip_image002.jpg (File not found)
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{09308CE0-6ECC-4DB6-A957-2AD37E5E3C7E} "StuffIt Archive Menu" - "Smith Micro Software, Inc." - C:\Programme\Smith Micro\StuffIt\ArchiveMenu.dll
{3FBFD0B0-EB46-4797-9101-615610E87DA6} "StuffIt Compress Menu" - "Smith Micro Software, Inc." - C:\Programme\Smith Micro\StuffIt\CompressMenu.dll
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
{89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" - "Microsoft Corporation" - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
{1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" - "Microsoft Corporation" - C:\WINDOWS\system32\mscoree.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
{CD00020A-8B95-11D1-82DB-00C04FB1625D} "Microsoft PKM KnowledgePluggable Class" - "Microsoft Corporation" - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - C:\Programme\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu.dll
{5E44E225-A408-11CF-B581-008029601108} "Adaptec DirectCD Shell Extension" - "Roxio" - C:\PROGRA~1\Roxio\EASYCD~1\DirectCD\Shellex.dll
{42071714-76d4-11d1-8b24-00a0c9068ff3} "CPL-Erweiterung für Anzeigeverschiebung" - ? - deskpan.dll (File not found)
{1CDB2949-8F65-4355-8456-263E7C208A5D} "Desktop Explorer" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} "Desktop Explorer Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{1D2680C9-0E2A-469d-B787-065558BC7D43} "Fusion Cache" - "Microsoft Corporation" - c:\WINDOWS\system32\mscoree.dll
{CE000992-A58C-4441-8938-744CD72AB27F} "i-Nav IDN Resolver" - "VeriSign, Inc." - C:\Programme\VeriSign\i-Nav\i-nav_4_2_1.dll
{CE000994-A58C-4441-8938-744CD72AB27F} "i-Nav IDN SearchHook" - "VeriSign, Inc." - C:\Programme\VeriSign\i-Nav\i-nav_4_2_1.dll
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Programme\iTunes\iTunesMiniPlayer.dll
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "Kontextmenü für die Verschlüsselung" - ? - (File not found | COM-object registry key not found)
{32683183-48a0-441b-a342-7c2a440a9478} "Media Band" - ? - (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office10\msohev.dll
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} "nView Desktop Context Menu" - "NVIDIA Corporation" - C:\WINDOWS\system32\nvshell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Programme\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office10\OLKFSTUB.DLL
{59AF8E81-BE3C-11d5-BE40-00A0244C457F} "SafeGuard® PrivateCrypto extension" - "Utimaco Safeware AG" - C:\Programme\Utimaco\SafeGuard PrivateCrypto\pcshell.dll
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Programme\AntiVir Workstation\shlext.dll
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{764BF0E1-F219-11ce-972D-00AA00A14F56} "Shellerweiterungen für die Dateikomprimierung" - ? - (File not found | COM-object registry key not found)
{e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" - "Microsoft Corporation" - c:\WINDOWS\system32\dfshim.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Programme\ATI Technologies\ATI.ACE\atiacmxx.dll
{B8323370-FF27-11D2-97B6-204C4F4F5020} "SmartFTP Shell Extension DLL" - "SmartFTP" - C:\Programme\SmartFTP\SmartHook.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Programme\WinRAR\rarext.dll (File found, but it contains no detailed information)
{E0D79304-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
{E0D79305-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
{E0D79306-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
{E0D79307-84BE-11CE-9641-444553540000} "WinZip" - "WinZip Computing, Inc." - C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer xxs )-----
{32683183-48a0-441b-a342-7c2a440a9478} "{32683183-48a0-441b-a342-7c2a440a9478}" - ? - (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
<binary data> "Google Toolbar" - "Google Inc." - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
ITxx7Height "ITxx7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITxx7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "ITxxLayout" - ? - (File not found | COM-object registry key not found)
<binary data> "softonic-de3 Toolbar" - "Conduit Ltd." - C:\Programme\softonic-de3\tbsof1.dll
<binary data> "{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}" - ? - (File not found | COM-object registry key not found)
<binary data> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" - ? - (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks )-----
{CE000994-A58C-4441-8938-744CD72AB27F} "i-Nav IDN SearchHook" - "VeriSign, Inc." - C:\Programme\VeriSign\i-Nav\i-nav_4_2_1.dll
{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} "softonic-de3 Toolbar" - "Conduit Ltd." - C:\Programme\softonic-de3\tbsof1.dll
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{17D72920-7A15-11D4-921E-0080C8DA7A5E} "AimSp32 Class" - "Approach Infinity Media Corportation" - C:\WINDOWS\Downloaded Program Files\aimsp32.dll / hxx://rimmel.ai-media.com/save/makeover.cab
{917623D1-D8E5-11D2-BE8B-00104B06BDE3} "CamImage Class" - ? - C:\WINDOWS\Downloaded Program Files\AxisCamControl.ocx / hxx://141.39.245.118/activex/AxisCamControl.cab
{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} "GpcContainer Class" - "WebEx Communications, Inc" - C:\Programme\WebEx\ieatgpc.dll /
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_21" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_21.dll / hxx://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} "Java Plug-in 1.6.0_21" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_21.dll / hxx://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_21" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\npjpi160_21.dll / hxx://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
{166B1BCA-3F9C-11CF-8075-444553540000} "Shockwave ActiveX Control" - "Macromedia, Inc." - C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll / hxx://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx / hxx://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} "Symantec AntiVirus scanner" - "Symantec Corporation" - C:\WINDOWS\Downloaded Program Files\avsniff.dll / hxx://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
{644E432F-49D3-41A1-8DD5-E099162EEEC5} "Symantec RuFSI Utility Class" - "Symantec Corporation" - C:\WINDOWS\Downloaded Program Files\rufsi.dll / hxx://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
{FA9740A2-5802-42E2-B509-81186EEB3C42} "WABControl Class" - "LinkedIn, Ltd." - C:\WINDOWS\Downloaded Program Files\wabctrl.dll / hxxs://www.linkedin.com/cab/wabctrl.cab
{62475759-9E84-458E-A1AB-5D2C442ADFDE} "{62475759-9E84-458E-A1AB-5D2C442ADFDE}" - ? - (File not found | COM-object registry key not found) / hxx://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/de/win/QuickTimeFullInstaller.exe
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{CE000996-A58C-4441-8938-744CD72AB27F} "ClsidExtension" - "VeriSign, Inc." - C:\Programme\VeriSign\i-Nav\i-nav_4_2_1.dll
"Hilfe zu i-Nav" - ? - hxx://idn.verisign-grs.com/plug-in/support/index.jsp (HTTP value)
{86529161-034E-4F8A-88D2-3C625E612E04} "Run WinHTTrack" - ? - C:\Programme\HTTrack09\WinHTTrackIExx.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} "Contribute Toolbar" - "Adobe Systems Incorporated." - C:\Programme\Adobe\Adobe Contribute CS3\contributeieplugin.dll
<binary data> "Google Toolbar" - "Google Inc." - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} "softonic-de3 Toolbar" - "Conduit Ltd." - C:\Programme\softonic-de3\tbsof1.dll
<binary data> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{AE7CD045-E861-484f-8273-0445EE161910} "Adobe PDF Conversion Toolbar Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
{074C1DC5-9320-4A9A-947D-C042949C6216} "ContributeBHO Class" - "Adobe Systems Incorporated." - C:\Programme\Adobe\Adobe Contribute CS3\contributeieplugin.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" - "Google Inc." - C:\Programme\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
{CE000992-A58C-4441-8938-744CD72AB27F} "i-Nav IDN Resolver" - "VeriSign, Inc." - C:\Programme\VeriSign\i-Nav\i-nav_4_2_1.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jp2ssv.dll
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} "JQSIEStartDetectorImpl Class" - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{F4971EE7-DAA0-4053-9964-665D8EE6A077} "SmartSelect Class" - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} "softonic-de3 Toolbar" - "Conduit Ltd." - C:\Programme\softonic-de3\tbsof1.dll
[Logon]
-----( %AllUsersProfile%\Startmenü\Programme\Autostart )-----
"ATI CATALYST System Tray.lnk" - "ATI Technologies Inc." - C:\Programme\ATI Technologies\ATI.ACE\CLI.exe (Shortcut exists | File exists)
"DESKTOP.INI" - ? - C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\DESKTOP.INI
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Programme\Microsoft Office\Office10\OSA.EXE (Shortcut exists | File exists)
"WinZip Quick Pick.lnk" - "WinZip Computing, Inc." - C:\Programme\Winzip\WZQKPICK.EXE (Shortcut exists | File exists)
-----( %UserProfile%\Startmenü\Programme\Autostart )-----
"DESKTOP.INI" - ? - C:\Dokumente und Einstellungen\\Startmenü\Programme\Autostart\DESKTOP.INI
"OpenOffice.org 3.1.lnk" - ? - C:\Programme\OpenOffice.org 3\program\quickstart.exe (Shortcut exists | File found, but it contains no detailed information | File exists)
"Terminkalender.lnk" - ? - C:\Dokumente und Einstellungen\\Startmenü\Programme\Autostart\Terminkalender.lnk (Shortcut exists | File not found)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Google Update" - "Google Inc." - "C:\Dokumente und Einstellungen\\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" /c
"swg" - "Google Inc." - "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Acrobat Assistant 8.0" - "Adobe Systems Inc." - "C:\Programme\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"AdaptecDirectCD" - "Roxio" - "C:\Programme\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
"Adobe Acrobat Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe_ID0EYTHM" - "Adobe Systems Incorporated" - C:\PROGRA~1\GEMEIN~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"ATICCC" - "ATI Technologies Inc." - "C:\Programme\ATI Technologies\ATI.ACE\cli.exe" runtime
"AtiPTA" - "ATI Technologies, Inc." - atiptaxx.exe
"avgnt" - "Avira GmbH" - "C:\Programme\AntiVir Workstation\avgnt.exe" /min
"diagent" - "Creative Technology Ltd" - C:\Programme\Creative\SBLive\Diagnostics\diagent.exe startup
"DVDSentry" - "Dell - Advanced Desktop Engineering" - C:\WINDOWS\System32\DSentry.exe
"iTunesHelper" - "Apple Inc." - "C:\Programme\iTunes\iTunesHelper.exe"
"Lexmark X74-X75" - "Lexmark International, Inc." - "C:\Programme\Lexmark X74-X75\lxbbbmgr.exe"
"nwiz" - "NVIDIA Corporation" - nwiz.exe /install
"QuickTime Task" - "Apple Inc." - "C:\Programme\Quicktime2007\QTTask.exe" -atboottime
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe"
"UpdReg" - "Creative Technology Ltd." - C:\WINDOWS\UpdReg.EXE
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PDFCreator" - ? - C:\WINDOWS\system32\pdfcmnnt.dll (File found, but it contains no detailed information)
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
"Adobe Version Cue CS3 {de_DE} " (Adobe Version Cue CS3) - "Adobe Systems Incorporated" - C:\Programme\Gemeinsame Dateien\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
"AntiVir Windows Workstation Guard" (AntiVirService) - "Avira GmbH" - C:\Programme\AntiVir Workstation\avguard.exe
"AntiVir Windows Workstation MailGuard" (AntiVirMailService) - "Avira GmbH" - C:\Programme\AntiVir Workstation\avmailc.exe
"AntiVir Windows Workstation MailGuard Hilfsdienst" (AVEService) - "Avira GmbH" - C:\Programme\AntiVir Workstation\avesvc.exe
"AntiVir Windows Workstation Planer" (AntiVirScheduler) - "Avira GmbH" - C:\Programme\AntiVir Workstation\sched.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"ASF Agent" (ASFAgent) - "Intel Corporation" - C:\Programme\Intel\ASF Agent\ASFAgent.exe
"ASP.NET State Service" (aspnet_state) - "Microsoft Corporation" - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
"ATI Smart" (ATI Smart) - ? - C:\WINDOWS\SYSTEM32\ati2sgag.exe
"Avira AntiVir Professional WebGuard" (antivirwebservice) - "Avira GmbH" - C:\Programme\AntiVir Workstation\AVWEBGRD.EXE
"Creative Service for CDROM Access" (Creative Service for CDROM Access) - "Creative Technology Ltd" - C:\WINDOWS\System32\CTsvcCDA.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Programme\Bonjour\mDNSResponder.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Macrovision Europe Ltd." - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"Google Software Updater" (gusvc) - "Google" - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Programme\Google\Update\GoogleUpdate.exe
"HID Input Service" (HidServ) - ? - C:\WINDOWS\System32\hidserv.dll (File not found)
"Iap" (Iap) - "Dell Computer Corporation" - C:\Programme\Dell\OpenManage\Client\Iap.exe
"Intel NCS NetService" (NetSvc) - "Intel(R) Corporation" - C:\Programme\Intel\NCS\Sync\NetSvc.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Programme\iPod\bin\iPodService.exe
"Java Quick Starter" (JavaQuickStarterService) - "Sun Microsystems, Inc." - C:\Programme\Java\jre6\bin\jqs.exe
"VeriSign Updater" (navi) - "VeriSign, Inc." - C:\Programme\VeriSign\NAVI\naviagent.exe
"Windows CardSpace" (idsvc) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
"Windows Presentation Foundation Font Cache 3.0.0.0" (FontCache3.0.0.0) - "Microsoft Corporation" - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
"WMDM PMSP Service" (WMDM PMSP Service) - "Microsoft Corporation" - C:\WINDOWS\System32\MsPMSPSv.exe
[Winlogon]
-----( HKCU\Control Panel\IOProcs )-----
"MVB" - ? - mvfs32.dll (File not found)
-----( HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify )-----
"WgaLogon" - "Microsoft Corporation" - C:\WINDOWS\system32\WgaLogon.dll
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Programme\Bonjour\mdnsNSP.dll
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"AVSDA" - "Avira GmbH" - C:\WINDOWS\system32\avsda.dll
===[ Logfile end ]=========================================[ Logfile end ]===--- --- ------ --- ---
If You have questions or want to get some help, You can visit hxx://forum.online-solutions.ru Zitat:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000001d
Kernel Drivers (total 137):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EF000 \WINDOWS\system32\hal.dll
0xF79A1000 \WINDOWS\system32\KDCOM.DLL
0xF78B1000 \WINDOWS\system32\BOOTVID.dll
0xF7451000 ACPI.sys
0xF79A3000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xF7440000 pci.sys
0xF74A1000 isapnp.sys
0xF7A69000 pciide.sys
0xF7721000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xF74B1000 MountMgr.sys
0xF7421000 ftdisk.sys
0xF79A5000 dmload.sys
0xF73FB000 dmio.sys
0xF7729000 PartMgr.sys
0xF74C1000 VolSnap.sys
0xF73E3000 atapi.sys
0xF74D1000 disk.sys
0xF74E1000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF73C3000 fltmgr.sys
0xF73B1000 sr.sys
0xF74F1000 avgntmgr.sys
0xF739A000 KSecDD.sys
0xF730D000 Ntfs.sys
0xF72E0000 NDIS.sys
0xF72C6000 Mup.sys
0xF7501000 agp440.sys
0xF7541000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xF65C7000 \SystemRoot\System32\DRIVERS\nv4_mini.sys
0xF65B3000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xF7851000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xF658F000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xF7859000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xF6453000 \SystemRoot\system32\drivers\P16X.sys
0xF6430000 \SystemRoot\system32\drivers\ks.sys
0xF640C000 \SystemRoot\system32\drivers\portcls.sys
0xF7551000 \SystemRoot\system32\drivers\drmk.sys
0xF7285000 \SystemRoot\System32\DRIVERS\gameenum.sys
0xF62C7000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xF7861000 \SystemRoot\System32\DRIVERS\fdc.sys
0xF7561000 \SystemRoot\System32\DRIVERS\serial.sys
0xF7281000 \SystemRoot\System32\DRIVERS\serenum.sys
0xF62B3000 \SystemRoot\System32\DRIVERS\parport.sys
0xF7571000 \SystemRoot\System32\DRIVERS\imapi.sys
0xF7581000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
0xF7591000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF75A1000 \SystemRoot\System32\DRIVERS\redbook.sys
0xF6294000 \SystemRoot\System32\Drivers\pwd_2k.SYS
0xF7869000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
0xF7871000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xF6206000 \SystemRoot\system32\drivers\smwdm.sys
0xF79E3000 \SystemRoot\system32\drivers\aeaudio.sys
0xF7BA5000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF75B1000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xF7275000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xF61EF000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF75C1000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF75D1000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xF7879000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xF61DE000 \SystemRoot\System32\DRIVERS\psched.sys
0xF75E1000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xF7881000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF7889000 \SystemRoot\System32\DRIVERS\raspti.sys
0xF61AE000 \SystemRoot\System32\DRIVERS\rdpdr.sys
0xF75F1000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF7891000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xF7899000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF79E5000 \SystemRoot\System32\DRIVERS\swenum.sys
0xF5FDC000 \SystemRoot\System32\DRIVERS\update.sys
0xF78A1000 \SystemRoot\System32\DRIVERS\omci.sys
0xF793D000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF78A9000 \SystemRoot\System32\Drivers\mmc_2K.SYS
0xF7601000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7611000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xF79E7000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xF7741000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xF7971000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xECEA1000 \SystemRoot\SYSTEM32\DRIVERS\avgntdd.sys
0xF79E9000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7AD5000 \SystemRoot\System32\Drivers\Null.SYS
0xF79EB000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7751000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
0xF7759000 \SystemRoot\System32\drivers\vga.sys
0xF79ED000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79EF000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xECE46000 \SystemRoot\System32\Drivers\cdudf_xp.SYS
0xF7761000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7769000 \SystemRoot\System32\Drivers\Npfs.SYS
0xECE01000 \SystemRoot\System32\Drivers\UdfReadr_xp.SYS
0xF69A7000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xECDB4000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xECD5B000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xECD33000 \SystemRoot\System32\DRIVERS\netbt.sys
0xF699F000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xECD11000 \SystemRoot\System32\drivers\afd.sys
0xF7651000 \SystemRoot\System32\DRIVERS\netbios.sys
0xF7771000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xECCE6000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xECC76000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xF7681000 \SystemRoot\System32\Drivers\Fips.SYS
0xECC50000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xF7691000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xF7779000 \SystemRoot\System32\DRIVERS\usbccgp.sys
0xF799D000 \SystemRoot\System32\DRIVERS\hidusb.sys
0xF76A1000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
0xF7291000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xF7289000 \SystemRoot\System32\DRIVERS\kbdhid.sys
0xECC17000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xECBFF000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF79F3000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF5FB4000 \SystemRoot\System32\drivers\Dxapi.sys
0xF7781000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7B92000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBF464000 \SystemRoot\System32\ati2dvag.dll
0xBF49B000 \SystemRoot\System32\ati2cqag.dll
0xBF4CF000 \SystemRoot\System32\atikvmag.dll
0xBF504000 \SystemRoot\System32\ati3duag.dll
0xBF746000 \SystemRoot\System32\ativvaxx.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xBA4E8000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xBA083000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xF7A37000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB9F7E000 \SystemRoot\system32\drivers\wdmaud.sys
0xBA1E8000 \SystemRoot\system32\drivers\sysaudio.sys
0xF77C9000 \??\C:\WINDOWS\System32\drivers\AsfAlrt.sys
0xB9B89000 \SystemRoot\System32\DRIVERS\srv.sys
0xB9E50000 \??\C:\WINDOWS\System32\drivers\pdihwctl.sys
0xF79DF000 \??\C:\WINDOWS\System32\PfModNT.sys
0xF79FF000 \??\C:\WINDOWS\System32\Drivers\U3sHlpDr.sys
0xB9CE8000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB9468000 \SystemRoot\System32\Drivers\HTTP.sys
0xB86A8000 \SystemRoot\System32\DRIVERS\e1000325.sys
0xB7D1B000 \SystemRoot\system32\drivers\kmixer.sys
0x7C910000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 60):
0 System Idle Process
4 System
416 C:\WINDOWS\SYSTEM32\smss.exe
472 csrss.exe
504 C:\WINDOWS\SYSTEM32\winlogon.exe
548 C:\WINDOWS\SYSTEM32\services.exe
560 C:\WINDOWS\SYSTEM32\lsass.exe
708 C:\WINDOWS\SYSTEM32\ati2evxx.exe
720 C:\WINDOWS\SYSTEM32\svchost.exe
816 svchost.exe
856 C:\WINDOWS\SYSTEM32\svchost.exe
896 svchost.exe
1012 svchost.exe
1160 C:\WINDOWS\SYSTEM32\ati2evxx.exe
1240 C:\WINDOWS\explorer.exe
1368 C:\WINDOWS\SYSTEM32\LEXBCES.EXE
1400 C:\WINDOWS\SYSTEM32\spoolsv.exe
1456 C:\WINDOWS\SYSTEM32\LEXPPS.EXE
1564 svchost.exe
1620 C:\Programme\AntiVir Workstation\sched.exe
1632 C:\Programme\AntiVir Workstation\avguard.exe
1644 C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1680 C:\Programme\Intel\ASF Agent\ASFAgent.exe
1768 C:\Programme\AntiVir Workstation\avesvc.exe
1812 C:\Programme\Bonjour\mDNSResponder.exe
1832 C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE
1952 C:\Programme\Dell\OpenManage\Client\Iap.exe
1984 C:\Programme\Java\jre6\bin\jqs.exe
2044 C:\Programme\VeriSign\NAVI\naviagent.exe
164 C:\WINDOWS\SYSTEM32\nvsvc32.exe
368 C:\WINDOWS\SYSTEM32\svchost.exe
460 C:\WINDOWS\SYSTEM32\MsPMSPSv.exe
1212 wmiprvse.exe
1132 NAVICL~1.EXE
2148 C:\WINDOWS\SYSTEM32\DSentry.exe
2172 C:\Programme\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
2180 C:\Programme\Lexmark X74-X75\lxbbbmgr.exe
2196 C:\Programme\AntiVir Workstation\avgnt.exe
2208 C:\WINDOWS\SYSTEM32\rundll32.exe
2224 C:\WINDOWS\SYSTEM32\atiptaxx.exe
2244 C:\Programme\ATI Technologies\ATI.ACE\CLI.exe
2304 C:\WINDOWS\SYSTEM32\rundll32.exe
2324 C:\Programme\Lexmark X74-X75\lxbbbmon.exe
2340 C:\Programme\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
2376 C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
2384 C:\Programme\Quicktime2007\QTTask.exe
2420 C:\Programme\iTunes\iTunesHelper.exe
2480 C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
2608 C:\Programme\AntiVir Workstation\avmailc.exe
2624 C:\Programme\Creative\SBLive\Diagnostics\diagent.exe
2696 C:\Programme\ATI Technologies\ATI.ACE\CLI.exe
2744 C:\Programme\Winzip\WZQKPICK.EXE
2800 C:\Programme\AntiVir Workstation\avwebgrd.exe
3116 C:\Programme\OpenOffice.org 3\program\soffice.exe
3184 C:\Programme\OpenOffice.org 3\program\soffice.bin
3280 alg.exe
3656 C:\Programme\iPod\bin\iPodService.exe
2644 C:\Programme\Messenger\msmsgs.exe
3720 C:\WINDOWS\SYSTEM32\wuauclt.exe
3912 C:\Dokumente und Einstellungen\xx\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02f10c00 (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: ST380011A, Rev: 3.16
PhysicalDrive1 Model Number: IBM-DJNA-372200, Rev: J71OA30K
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
21 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11
Done!
| :dummguck:
;-) Butterbreze |