GMER Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-10 00:01:21
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.1AA0
Running: h8bkkujc.exe; Driver: C:\Users\Admin\AppData\Local\Temp\uwtoapob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x90D38708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x90EA57C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0x90D3911C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x90D43F28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x90D43F74]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x90D440F6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x90D43E96]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0x90EA5BBA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x90D43EDE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThread [0x90D39310]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThreadEx [0x90D39498]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x90D440B0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDebugActiveProcess [0x90D39A9C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x90D38756]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x90EA58AC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x90D383BE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x90D387A4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x90D3D456]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x90D3A464]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x90D43F52]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x90D43F96]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x90D4411A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x90D43EBC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x90D4403A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x90D43F06]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x90D440D4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x90EA5A2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x90D3A330]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueueApcThreadEx [0x90D3A06C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x90D387F2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x90D38840]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetContextThread [0x90D3991C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x90D38448]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x90D385F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x90D3859E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendProcess [0x90D39BFE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendThread [0x90D39D5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x90D38668]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0x90EA5AF6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwTerminateThread [0x90D39794]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x90D3888E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0x90EA5962]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x90EBD966]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82C423C9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C7BD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82C82D80 4 Bytes [08, 87, D3, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82C82DA8 4 Bytes [C8, 57, EA, 90] {ENTER 0xea57, 0x90}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82C82E08 4 Bytes [1C, 91, D3, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82C82E5C 8 Bytes [28, 3F, D4, 90, 74, 3F, D4, ...] {SUB [EDI], BH; AAM 0x90; JZ 0x45; AAM 0x90}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82C82E68 4 Bytes [F6, 40, D4, 90] {TEST BYTE [EAX-0x2c], 0x90}
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82E0FC64 5 Bytes JMP 90EBA806 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 82E28290 5 Bytes JMP 90EBC338 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82E3D3D7 4 Bytes CALL 90D3AB07 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82E571E0 4 Bytes CALL 90D3AB1D \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82EE111A 7 Bytes JMP 90EBD96A \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91611000, 0x2D5378, 0xE8000020]
PAGE peauth.sys 9D628B9B 72 Bytes [49, E8, 7B, AC, AD, 99, C3, ...]
.text kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\csrss.exe[488] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[560] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[568] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\services.exe[608] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text ...
.text C:\Windows\system32\taskhost.exe[1428] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[1428] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[1428] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[1428] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[1428] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[1428] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[1428] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[1428] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 000E0600
.text C:\Program Files\iPod\bin\iPodService.exe[1452] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Program Files\iPod\bin\iPodService.exe[1452] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Program Files\iPod\bin\iPodService.exe[1452] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[1452] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00100A08
.text C:\Program Files\iPod\bin\iPodService.exe[1452] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001003FC
.text C:\Program Files\iPod\bin\iPodService.exe[1452] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00100804
.text C:\Program Files\iPod\bin\iPodService.exe[1452] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001001F8
.text C:\Program Files\iPod\bin\iPodService.exe[1452] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00100600
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1472] kernel32.dll!SetUnhandledExceptionFilter 776EF4FB 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1472] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1588] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1724] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1760] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text ...
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00090A08
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000903FC
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00090804
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000901F8
.text C:\Program Files\iTunes\iTunesHelper.exe[2280] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00090600
.text C:\Windows\system32\svchost.exe[2312] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00190A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001903FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00190804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001901F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2368] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00190600
.text C:\Windows\system32\svchost.exe[2384] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2392] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[2392] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[2392] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2392] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\Dwm.exe[2392] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\Dwm.exe[2392] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\Dwm.exe[2392] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\Dwm.exe[2392] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\WUDFHost.exe[2416] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 001503FC
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 001501F8
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00170A08
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001703FC
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00170804
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001701F8
.text C:\Program Files\FreePDF_XP\fpassist.exe[2608] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00170600
.text C:\Windows\system32\taskeng.exe[2896] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\taskeng.exe[2896] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\taskeng.exe[2896] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[2896] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\taskeng.exe[2896] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\taskeng.exe[2896] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\taskeng.exe[2896] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\taskeng.exe[2896] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\taskhost.exe[2956] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[2956] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[2956] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[2956] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[2956] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[2956] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[2956] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[2956] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 000E0600
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00110A08
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001103FC
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00110804
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001101F8
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[3456] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00110600
.text C:\Windows\Explorer.EXE[3488] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[3488] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[3488] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[3488] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 000A0A08
.text C:\Windows\Explorer.EXE[3488] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000A03FC
.text C:\Windows\Explorer.EXE[3488] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 000A0804
.text C:\Windows\Explorer.EXE[3488] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000A01F8
.text C:\Windows\Explorer.EXE[3488] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 000A0600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3596] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00120A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001203FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00120804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001201F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[3612] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00120600
.text C:\Windows\system32\SearchIndexer.exe[3716] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[3716] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[3716] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3716] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00090A08
.text C:\Windows\system32\SearchIndexer.exe[3716] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 000903FC
.text C:\Windows\system32\SearchIndexer.exe[3716] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00090804
.text C:\Windows\system32\SearchIndexer.exe[3716] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 000901F8
.text C:\Windows\system32\SearchIndexer.exe[3716] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00090600
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00110A08
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001103FC
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00110804
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001101F8
.text C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00110600
.text C:\Windows\system32\AUDIODG.EXE[3804] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] ntdll.dll!LdrUnloadDll 7794C86E 5 Bytes JMP 000A03FC
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] ntdll.dll!LdrLoadDll 7795223E 5 Bytes JMP 000A01F8
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] USER32.dll!UnhookWindowsHookEx 772DADF9 5 Bytes JMP 00140A08
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] USER32.dll!UnhookWinEvent 772DB750 5 Bytes JMP 001403FC
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] USER32.dll!SetWindowsHookExW 772DE30C 5 Bytes JMP 00140804
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] USER32.dll!SetWinEventHook 772E24DC 5 Bytes JMP 001401F8
.text C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe[3880] USER32.dll!SetWindowsHookExA 77306D0C 5 Bytes JMP 00140600
.text C:\Users\Admin\Desktop\h8bkkujc.exe[3928] kernel32.dll!GetBinaryTypeW + 70 777069F4 1 Byte [62]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1472] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [736AF6D0] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll (Common functions/AVAST Software)
IAT C:\Program Files\AVAST Software\Avast\AvastUI.exe[3596] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [736AF6D0] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll (Common functions/AVAST Software)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3784] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000074 bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000074 bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004d halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001e4ccc84e3
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001e4ccc84e3 (not active ControlSet)
---- EOF - GMER 1.0.15 ---- OSAM Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 00:05:51 on 10.09.2012
OS: Windows 7 Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 15.0.1
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\Windows\system32\drivers\aswFsBlk.sys
"aswMonFlt" (aswMonFlt) - "AVAST Software" - C:\Windows\system32\drivers\aswMonFlt.sys
"aswRdr" (aswRdr) - "AVAST Software" - C:\Windows\System32\Drivers\aswrdr2.sys
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys
"aswSP" (aswSP) - "AVAST Software" - C:\Windows\system32\drivers\aswSP.sys
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\Windows\system32\drivers\aswTdi.sys
"catchme" (catchme) - ? - C:\Users\Admin\AppData\Local\Temp\catchme.sys (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"PSI" (PSI) - "Secunia" - C:\Windows\System32\DRIVERS\psi_mf.sys
"uwtoapob" (uwtoapob) - ? - C:\Users\Admin\AppData\Local\Temp\uwtoapob.sys (Hidden registry entry, rootkit activity | File not found)
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - "The Document Foundation" - C:\Program Files\LibreOffice 3.5\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{653DCCC2-13DB-45B2-A389-427885776CFE} "Activities Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplact.dll
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Program Files\AVAST Software\Avast\ashShell.dll
{124597D8-850A-41AE-849C-017A4FA99CA2} "Buttons Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplbtn.dll
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{3BEABCC1-BF31-42df-88D9-A2955D6B8528} "IntelliPoint Sensitivity Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplsens.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "LibreOffice Column Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.5\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "LibreOffice Infotip Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.5\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "LibreOffice Property Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.5\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "LibreOffice Property Sheet Handler" - "The Document Foundation" - C:\Program Files\LibreOffice 3.5\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "LibreOffice Thumbnail Viewer" - "The Document Foundation" - C:\Program Files\LibreOffice 3.5\program\shlxthdl\shlxthdl.dll
{C533AB49-9805-4972-8326-A084696B00F0} "Touch Mouse Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcpltouchmouse.dll
{1184D0ED-DBCE-4170-8DBB-4D0C3905DA85} "Touch Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcpltouch.dll
{7834E880-F0CC-4FA7-B4F3-FDB0F4E816A5} "Touch Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcpltouchstrip.dll
{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE} "Wheel Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplwhl.dll
{20082881-FC36-4E47-9A7A-644C95FF749F} "Wireless Property Page" - "Microsoft Corporation" - c:\Program Files\Microsoft IntelliPoint\ipcplwir.dll
[Internet Explorer]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
[Known DLLs]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs )-----
"advapi32" - "Microsoft Corporation" - C:\Windows\system32\advapi32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"clbcatq" - "Microsoft Corporation" - C:\Windows\system32\clbcatq.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"COMDLG32" - "Microsoft Corporation" - C:\Windows\system32\COMDLG32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"DifxApi" - "Microsoft Corporation" - C:\Windows\system32\difxapi.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"gdi32" - "Microsoft Corporation" - C:\Windows\system32\gdi32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"IERTUTIL" - "Microsoft Corporation" - C:\Windows\system32\IERTUTIL.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"IMAGEHLP" - "Microsoft Corporation" - C:\Windows\system32\IMAGEHLP.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"IMM32" - "Microsoft Corporation" - C:\Windows\system32\IMM32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"kernel32" - "Microsoft Corporation" - C:\Windows\system32\kernel32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"LPK" - "Microsoft Corporation" - C:\Windows\system32\LPK.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"MSCTF" - "Microsoft Corporation" - C:\Windows\system32\MSCTF.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"MSVCRT" - "Microsoft Corporation" - C:\Windows\system32\MSVCRT.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"NORMALIZ" - "Microsoft Corporation" - C:\Windows\system32\NORMALIZ.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"NSI" - "Microsoft Corporation" - C:\Windows\system32\NSI.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"ole32" - "Microsoft Corporation" - C:\Windows\system32\ole32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"OLEAUT32" - "Microsoft Corporation" - C:\Windows\system32\OLEAUT32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"PSAPI" - "Microsoft Corporation" - C:\Windows\system32\PSAPI.DLL (Hidden registry entry, rootkit activity | File signed by Microsoft)
"rpcrt4" - "Microsoft Corporation" - C:\Windows\system32\rpcrt4.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"sechost" - "Microsoft Corporation" - C:\Windows\system32\sechost.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"Setupapi" - "Microsoft Corporation" - C:\Windows\system32\Setupapi.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"SHELL32" - "Microsoft Corporation" - C:\Windows\system32\SHELL32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"SHLWAPI" - "Microsoft Corporation" - C:\Windows\system32\SHLWAPI.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"URLMON" - "Microsoft Corporation" - C:\Windows\system32\URLMON.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"user32" - "Microsoft Corporation" - C:\Windows\system32\user32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"USP10" - "Microsoft Corporation" - C:\Windows\system32\USP10.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"WININET" - "Microsoft Corporation" - C:\Windows\system32\WININET.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"WLDAP32" - "Microsoft Corporation" - C:\Windows\system32\WLDAP32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"WS2_32" - "Microsoft Corporation" - C:\Windows\system32\WS2_32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Secunia PSI Tray.lnk" - "Secunia" - C:\Program Files\Secunia\PSI\psi_tray.exe (Shortcut exists | File exists)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avast" - "AVAST Software" - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"FreePDF Assistant" - "shbox.de" - "C:\Program Files\FreePDF_XP\fpassist.exe"
"IntelliPoint" - "Microsoft Corporation" - "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RIMBBLaunchAgent.exe" - "Research In Motion Limited" - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"EPSON PX720WD Series 32MonitorBE" - "SEIKO EPSON CORPORATION" - C:\Windows\system32\E_FLBGYE.DLL
"HP Discovery Port Monitor (HP Officejet 6500 E710n-z)" - "Hewlett-Packard Co." - C:\Windows\system32\HPDiscoPM5412.dll
"Redirected Port" - ? - C:\Windows\system32\redmonnt.dll (File found, but it contains no detailed information)
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"Secunia PSI Agent" (Secunia PSI Agent) - "Secunia" - C:\Program Files\Secunia\PSI\PSIA.exe
"Secunia Update Agent" (Secunia Update Agent) - "Secunia" - C:\Program Files\Secunia\PSI\sua.exe
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru aswMBR Code:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-10 00:08:18
-----------------------------
00:08:18.605 OS Version: Windows 6.1.7601 Service Pack 1
00:08:18.605 Number of processors: 4 586 0xF0B
00:08:18.605 ComputerName: *****-PC UserName: Admin
00:08:19.869 Initialize success
00:08:19.978 AVAST engine defs: 12090900
00:09:09.665 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
00:09:09.681 Disk 0 Vendor: SAMSUNG_ 1AA0 Size: 610480MB BusType: 8
00:09:09.681 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
00:09:09.681 Disk 1 Vendor: SAMSUNG_ 1AA0 Size: 610480MB BusType: 8
00:09:09.806 Disk 0 MBR read successfully
00:09:09.806 Disk 0 MBR scan
00:09:09.821 Disk 0 Windows 7 default MBR code
00:09:09.852 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
00:09:09.884 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 610378 MB offset 206848
00:09:09.977 Disk 0 scanning sectors +1250260992
00:09:10.102 Disk 0 scanning C:\Windows\system32\drivers
00:09:50.958 Service scanning
00:10:00.303 Modules scanning
00:11:10.409 Disk 0 trace - called modules:
00:11:10.441 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStorV.sys halmacpi.dll
00:11:10.441 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d4e5d8]
00:11:10.456 3 CLASSPNP.SYS[8bf9859e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85e76028]
00:11:11.798 AVAST engine scan C:\Windows
00:11:42.545 AVAST engine scan C:\Windows\system32
00:13:17.194 AVAST engine scan C:\Windows\system32\drivers
00:13:25.368 AVAST engine scan C:\Users\Admin
00:13:40.516 AVAST engine scan C:\ProgramData
00:14:01.701 Scan finished successfully
00:15:38.624 Disk 0 MBR has been saved successfully to "C:\Users\Admin\Desktop\MBR.dat"
00:15:38.624 The log file has been saved successfully to "C:\Users\Admin\Desktop\aswMBR.txt" |