Lara Maus | 30.04.2011 12:45 | GMER hat sich nicht aufgehaengt.
Anbei das Log
GMER Logfile: Code:
GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-04-30 13:42:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-17 SAMSUNG_SP2004C rev.VM100-41
Running: g2m3e4r.exe; Driver: C:\DOKUME~1\HRBOB~1\LOKALE~1\Temp\pxtdqpow.sys
---- System - GMER 1.0.15 ----
SSDT B8724026 ZwCreateKey
SSDT B872401C ZwCreateThread
SSDT B872402B ZwDeleteKey
SSDT B8724035 ZwDeleteValueKey
SSDT spaa.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spaa.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT B872403A ZwLoadKey
SSDT spaa.sys ZwOpenKey [0xB7EB50C0]
SSDT B8724008 ZwOpenProcess
SSDT B872400D ZwOpenThread
SSDT spaa.sys ZwQueryKey [0xB7ECE20A]
SSDT spaa.sys ZwQueryValueKey [0xB7ECE08A]
SSDT B8724044 ZwReplaceKey
SSDT B872403F ZwRestoreKey
SSDT B8724030 ZwSetValueKey
INT 0x62 ? 89BEABF8
INT 0x63 ? 89A7CF00
INT 0x73 ? 89BEABF8
INT 0x83 ? 89BEABF8
INT 0x83 ? 89BEABF8
INT 0x83 ? 89BEABF8
INT 0xB4 ? 89A7CF00
---- Kernel code sections - GMER 1.0.15 ----
? spaa.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload B7CB48AC 5 Bytes JMP 89A7C4E0
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB707D3A0, 0x5CC259, 0xE8000020]
.text ahn275kr.SYS B7030386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ahn275kr.SYS B70303AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ahn275kr.SYS B70303C4 3 Bytes [00, 80, 02]
.text ahn275kr.SYS B70303C9 1 Byte [30]
.text ahn275kr.SYS B70303C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB390A300, 0x3ACC8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB83D0300, 0x1B7E, 0xE8000020]
? \Daemon\Engine.dll Das System kann den angegebenen Pfad nicht finden. !
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EB6042] spaa.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EB613E] spaa.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EB60C0] spaa.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EB6800] spaa.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EB66D6] spaa.sys
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\ahn275kr.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EC5B90] spaa.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89BE91F8
Device \Driver\usbohci \Device\USBPDO-0 89A8B1F8
Device \Driver\PCI_PNP5926 \Device\00000044 spaa.sys
Device \Driver\usbehci \Device\USBPDO-1 89B961F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89C581F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89C581F8
Device \Driver\Cdrom \Device\CdRom0 89B95500
Device \Driver\atapi \Device\Ide\IdePort0 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort4 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort5 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-17 [B7E2EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Ftdisk \Device\HarddiskVolume3 89C581F8
Device \Driver\Cdrom \Device\CdRom1 89B95500
Device \Driver\Cdrom \Device\CdRom2 89B95500
Device \Driver\Cdrom \Device\CdRom3 89B95500
Device \Driver\NetBT \Device\NetBt_Wins_Export 8912B1F8
Device \Driver\NetBT \Device\NetbiosSmb 8912B1F8
Device \Driver\sptd \Device\1573004676 spaa.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{A74C429D-BEF4-4543-90D2-2FA2376A8120} 8912B1F8
Device \Driver\usbohci \Device\USBFDO-0 89A8B1F8
Device \Driver\usbehci \Device\USBFDO-1 89B961F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8909F1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8909F1F8
Device \Driver\Ftdisk \Device\FtControl 89C581F8
Device \Driver\ahn275kr \Device\Scsi\ahn275kr1Port6Path0Target1Lun0 898A9500
Device \Driver\ahn275kr \Device\Scsi\ahn275kr1Port6Path0Target0Lun0 898A9500
Device \Driver\ahn275kr \Device\Scsi\ahn275kr1 898A9500
Device \FileSystem\Cdfs \Cdfs 8913C1F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Daemon\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0xF1 0xEC 0xBC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC5 0x7F 0xAE 0x60 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x15 0xF4 0xBA 0xBD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xF1 0xAA 0x94 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC5 0x7F 0xAE 0x60 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x15 0xF4 0xBA 0xBD ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xF1 0xAA 0x94 0x00 ...
---- EOF - GMER 1.0.15 ---- --- --- ---
und MBRCheck log gibts auch direkt dazu :=) Zitat:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000001fc
Kernel Drivers (total 117):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806D1000 \WINDOWS\system32\hal.dll
0xB85A8000 \WINDOWS\system32\KDCOM.DLL
0xB84B8000 \WINDOWS\system32\BOOTVID.dll
0xB7EB4000 spaa.sys
0xB85AA000 \WINDOWS\System32\Drivers\WMILIB.SYS
0xB7E9C000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
0xB7E6D000 ACPI.sys
0xB7E5C000 pci.sys
0xB80A8000 isapnp.sys
0xB8670000 pciide.sys
0xB8328000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xB80B8000 MountMgr.sys
0xB7E3D000 ftdisk.sys
0xB8330000 PartMgr.sys
0xB80C8000 VolSnap.sys
0xB7E25000 atapi.sys
0xB80D8000 disk.sys
0xB80E8000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xB7E05000 fltmgr.sys
0xB7DF3000 sr.sys
0xB7DDC000 KSecDD.sys
0xB7D4F000 Ntfs.sys
0xB7D22000 NDIS.sys
0xB8338000 nvcchflt.sys
0xB7D08000 Mup.sys
0xB8198000 \SystemRoot\System32\DRIVERS\processr.sys
0xB83B8000 \SystemRoot\System32\DRIVERS\usbohci.sys
0xB7C9C000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xB83C0000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xB7A65000 \SystemRoot\system32\drivers\ALCXWDM.SYS
0xB7A41000 \SystemRoot\system32\drivers\portcls.sys
0xB81A8000 \SystemRoot\system32\drivers\drmk.sys
0xB7A1E000 \SystemRoot\system32\drivers\ks.sys
0xB81B8000 \SystemRoot\System32\DRIVERS\imapi.sys
0xB81C8000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xB81D8000 \SystemRoot\System32\DRIVERS\redbook.sys
0xB83C8000 \SystemRoot\System32\DRIVERS\RTL8139.SYS
0xB8558000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
0xB79DE000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
0xB79AB000 \SystemRoot\system32\DRIVERS\NVSNPU.SYS
0xB707D000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xB7069000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB7030000 \SystemRoot\System32\Drivers\ahn275kr.SYS
0xB8440000 \SystemRoot\System32\DRIVERS\fdc.sys
0xB8228000 \SystemRoot\System32\DRIVERS\serial.sys
0xB856C000 \SystemRoot\System32\DRIVERS\serenum.sys
0xB701C000 \SystemRoot\System32\DRIVERS\parport.sys
0xB8238000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xB8448000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xB8450000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xB87C2000 \SystemRoot\System32\DRIVERS\audstub.sys
0xB8248000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xB8570000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB7005000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xB8258000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xB8268000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xB8458000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xB6FF4000 \SystemRoot\System32\DRIVERS\psched.sys
0xB8278000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xB8460000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xB8468000 \SystemRoot\System32\DRIVERS\raspti.sys
0xB8288000 \SystemRoot\System32\DRIVERS\termdd.sys
0xB85C8000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB6F96000 \SystemRoot\System32\DRIVERS\update.sys
0xB8578000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xB8298000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xB82A8000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xB85CA000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xB85E6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xB8715000 \SystemRoot\System32\Drivers\Null.SYS
0xB85E8000 \SystemRoot\System32\Drivers\Beep.SYS
0xB84A0000 \SystemRoot\System32\drivers\vga.sys
0xB85EA000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xB85EC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xB84A8000 \SystemRoot\System32\Drivers\Msfs.SYS
0xB84B0000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB855C000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xB4D73000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xB4D1A000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xB4CF2000 \SystemRoot\System32\DRIVERS\netbt.sys
0xB4CD0000 \SystemRoot\System32\drivers\afd.sys
0xB82E8000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB8340000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xB4CA5000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xB4C35000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xB82F8000 \SystemRoot\System32\Drivers\Fips.SYS
0xB4C0F000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xB8308000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xB4BC1000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xB85F2000 \??\D:\Avira\AntiVir Desktop\avgio.sys
0xB8598000 \SystemRoot\System32\DRIVERS\hidusb.sys
0xB8128000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
0xB8380000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
0xB8138000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB4BA9000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xB85F4000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB7CD0000 \SystemRoot\System32\drivers\Dxapi.sys
0xB83A0000 \SystemRoot\System32\watchdog.sys
0xBD000000 \SystemRoot\System32\drivers\dxg.sys
0xB8789000 \SystemRoot\System32\drivers\dxgthk.sys
0xBD012000 \SystemRoot\System32\nv4_disp.dll
0xBD623000 \SystemRoot\System32\ATMFD.DLL
0xB3E5E000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xB3F47000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xB3B89000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xB3A84000 \SystemRoot\system32\drivers\wdmaud.sys
0xB3F03000 \SystemRoot\system32\drivers\sysaudio.sys
0xB85D6000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB390A000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xB83D0000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xB3588000 \SystemRoot\System32\Drivers\HTTP.sys
0xB331A000 \??\C:\DOKUME~1\HRBOB~1\LOKALE~1\Temp\pxtdqpow.sys
0xB32EF000 \SystemRoot\system32\drivers\kmixer.sys
0x7C910000 \WINDOWS\system32\ntdll.dll
0x10000000 \Daemon\Engine.dll
Processes (total 30):
0 System Idle Process
4 System
440 C:\WINDOWS\system32\smss.exe
488 csrss.exe
512 C:\WINDOWS\system32\winlogon.exe
556 C:\WINDOWS\system32\services.exe
568 C:\WINDOWS\system32\lsass.exe
732 D:\Avira\AntiVir Desktop\avguard.exe
780 D:\Avira\AntiVir Desktop\avshadow.exe
924 C:\WINDOWS\system32\nvsvc32.exe
952 C:\WINDOWS\system32\svchost.exe
1000 svchost.exe
1068 C:\WINDOWS\system32\svchost.exe
1148 svchost.exe
1244 svchost.exe
1412 C:\WINDOWS\explorer.exe
1464 C:\WINDOWS\system32\spoolsv.exe
1500 D:\Avira\AntiVir Desktop\sched.exe
1572 svchost.exe
1708 D:\Avira\AntiVir Desktop\avgnt.exe
1732 C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
1916 C:\Programme\Java\jre6\bin\jqs.exe
1944 C:\WINDOWS\system32\PnkBstrA.exe
1956 C:\WINDOWS\system32\PnkBstrB.exe
1992 C:\WINDOWS\system32\svchost.exe
1296 alg.exe
1524 C:\WINDOWS\system32\CNAB4RPK.EXE
3244 C:\Programme\Mozilla Firefox\firefox.exe
3476 C:\WINDOWS\system32\notepad.exe
3608 C:\Dokumente und Einstellungen\Hr Bob\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000007`52c65e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000015`f8cfa000 (NTFS)
PhysicalDrive0 Model Number: SAMSUNGSP2004C, Rev: VM100-41
Size Device Name MBR Status
--------------------------------------------
186 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11
Done!
| |