GMER
GMER Logfile: Code:
GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-07-04 13:24:15
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\000000b2 WDC_WD15 rev.80.0
Running: oiq886te.exe; Driver: C:\Users\Maurice\AppData\Local\Temp\pfliifob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x8C980992]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x8C9823FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x8C982674]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x8C9828E6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x8C9812AA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x8C981A52]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x8C981E4E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x8C9814C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x8C981D34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x8C980582]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x8C981C08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x8C98072A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x8C981F6E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x8C980F32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x8C981030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x8C981C9E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x8C983596]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x8C984716]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x8C981694]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x8C983688]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x8C983D62]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x8C981EE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x8C981336]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x8C981DC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x8C980BDC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x8C983AFC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x8C982004]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x8C980AD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x8C982B30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x8C98409C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x8C98398E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x8C982368]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x8C98222E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x8C983330]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x8C9845B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x8C98179C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x8C98114C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x8C982BD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x8C983790]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x8C9841EC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x8C9842DE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x8C984418]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x8C9834BA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x8C980D7C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x8C980CD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x8C983F40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x8C980E68]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 83249339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83282D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 83289DCC 4 Bytes [92, 09, 98, 8C]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 83289DF4 8 Bytes [FA, 23, 98, 8C, 74, 26, 98, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1143 83289E38 4 Bytes [E6, 28, 98, 8C]
.text ntkrnlpa.exe!KeRemoveQueueEx + 116F 83289E64 4 Bytes [AA, 12, 98, 8C]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 83289E88 4 Bytes [52, 1A, 98, 8C]
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9262A000, 0x2F786C, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA28BB300, 0x1B7E, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Real\RealPlayer\Update\realsched.exe[3092] kernel32.dll!SetUnhandledExceptionFilter 77483D01 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\000000a7 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ???j?l??tunnel?ox????i???????????????????5??????s????7??????{152c3281-3409-11df-abf3-806e6f6e6963}????????:??????D?gB9??Microsoft????i????N??i???7??????????? ???i???????????????????????????????????????????V??00????N??i?????????D?????i???????????i????D??i??? ???????i???????????????????????2?????????????????????i?????7???n????N??i???7???????????????????,??????????S???????????????????????USB\DevClass_00&SubClass_00&Prot_00?USB\DevClass_00&SubClass_00?USB\DevClass_00?USB\COMPOSITE????????i??? ???????i???????????i???????????????????????????????????i??????????s.??????????????????????\??\USB#VID_09DA&PID_8090#5&27e4fbe1&0&3#{a5dcbf10-6530-11d2-901f-00c04fb951ed}?????? ???????i??????????????????????????????????? ???????i?????i???????1??L????????? ??????idg?????i???i???i??(?????????????????ad???????????7?g?????????????????t??????????? ???????i?????i?????i????????&??????????????>?????i????????????usbstor.inf:Generic.NTx86:USBSTOR_BULK:6.1.7601.17577:usb\class_08&subclass_06&prot_50??????usb\class_08&subclass_06&prot_5
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ???j????????????????????????????????????????????t???????????????????????????????or??????????20??????????????????????@%systemroot%\system32\drivers\RdpRefMp.sys,-100????????????????????????????????????????SCSI Miniport????k?l?????????l???m??????????????????? ????????????????????????????$?????????p???? ???e????????????????????????V????????g????LegacyDriver?????????????????6??.1??????????????t????????????????????p???????????????????n??????????????t???????????????????????????????????t????????????????????????k?k?1??system32\DRIVERS\pacer.sys????????????????????????????????????????????????????????????????P??????????????????????????????e???-???????C??{533c5b84-ec70-11d2-9505-00c04f79deaf}\0010?????????????????Microsoft????????????????????????????e???????????k?k?1???j????????????????V?????????????STORAGE\VolumeSnapshot??=C????r?????????????{00000000-0000-0000-0000-000000000000}?B-H????X??????????????????y???k??????#{???i?i?k?????? ????????????????????????j???k???k??{71a27cdd-812a-11d0-bec7-08002be2092f}\0006?ff?????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????????????????????????????????????????????????11?}?1????$??????.???????7??????????????????????11???????????????????? ??????????????????????????????????????????????????????????????????????????????????????f???????????????f??????????.NTx86??????Microsoft???? ???????f???????????????????????????????f??????????? ???1??|???\?l??????H?????????????????????????????? ??????? ??????? ????????????.??x???X?h??????D???????????????????????????????????? ??????? ?????Root\*6TO4MP\0044???? ?????????????????????1????????????????????00000407?????????????????????????????????????????????????????????????????????????????????????-??????D3??Root\*6TO4MP\0048???????????????????????acpi\authenticamd_-_x86??????????????n??????????????????Net???????D?????????????????????????????????????????????? ???????????????????f?1????????????????????? ?????????????????????1????????????&????????????????????/??? ?????????????????????1????????????????????? ???????????????????f?1????????????????????? ?????????????????????1????????????????????? ?????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ???j?k??\SystemRoot\system32\drivers\kbdhid.sys?????system32\DRIVERS\kl2.sys?????~???????????????j???????????????????????????????????????????????j?????????????????????????????????? ??????g?????????????e??un??un???????e??????t???@%systemroot%\system32\wkssvc.dll,-1005?????@%systemroot%\system32\wkssvc.dll,-1007?????????????????e????????????????????????5???~????????????R??j??????????system32\DRIVERS\lirsgt.sys?????????????????????????????????????s????????j???e?f?~???????l?l?i???????U??????????\SystemRoot\system32\drivers\mouclass.sys?????Z??j?????????n??????:??????S?g_1???????????n??11???????????????????????B??????????????????????????????????????????????Pointer Class?????????????????B??j??????????storprop.dll,AtaPropPageProvider?????j?j?????????????????????????e??????el???????????????e???????j???.???????i?k????FSFilter Virtualization?????@%SystemRoot%\system32\drivers\ndis.sys,-201?????????????????j???????????n?k?n?n?j????$??j???4???????-???????????z??????????p????????????e???????????z?z?o??????????????????11?
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ???jSv???j???j??????????????? ???????i???????????i?1????????????????????? h????????????????????j????? ???????i?????j???????1????????????????????? ?i???i???i???i???i???i???i???j???j???j???j????? ???????j???????????i?1????????????????????? ???????5???????k?????j????? ???????i?????j???????1????????????????????? ???????j???????????i?1?????????????????????????h???????????5?????????????????????????j????? ???????i?????j???????1????????????????????? ???????j???????????i?1?????????????????????????i???6??????7&21d63dca&0?7?????????????j??????8??j????????h?????mshdc.inf_x86_neutral_f64b9c35a3a5be81???????j?j?j?j?j?j?j????<??j????????h??????????&???????j???????h????b??j?????????n?????????????????????????????????????????f???????????????????????????t???j???e??????????????????????????????e???????????????????????????nettun.inf?00}??@%systemroot%\system32\DRIVERS\RDPCDD.sys,-100???????????????????????????e?g?n???j???????????????????????????????????????6?.17??????????????????????????????t?????X??????1???t?????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ????????Net?1}????????????????????m???????t?????????????????????*6to4mp? "???????????????t????,??????????????????????????????k???????k???????k??? ?????????????????????????????????e??????`??????k???c??? ???????|???????????d?:??????????%?&????????????????????B??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{1EA6CF0A-FBE0-4912-993F-2E0D29FF0724}] SEQPACKET 3??r??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{12F85669-41C3-43A6-9BD1-2D408BCE84F9}] DATAGRAM 70??A???????????-????????m??????????????????????????????????B??????????????Microsoft???????????????????????????????????????l???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0460A44E-BF9B-4390-B541-6C61E6B57A13}] DATAGRAM 91?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????AC???????????????????0???????e?? ?@
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???f?????????????:???????????????f??*6to4mp??D??????or???j?j?????g?gMi??RasPppoe??????N?????????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}?_10???f???s?s?s???????j????N??????????????????????i??????????????????04??PCI\VEN_197B&DEV_2380&REV_00?PCI\VEN_197B&DEV_2380?PCI\VEN_197B&CC_0C0010?PCI\VEN_197B&CC_0C00?PCI\VEN_197B?PCI\CC_0C0010?PCI\CC_0C00????????g?gMi???????????R?????sPC???f?f?f?f?f?f?f???????????e?e?e?e?e?e?e?e?e?f?f??Microsoft???????????.NT??????????f???????6???f???e??tunnel?CCA????|??i???????3???f?fr ??TDI??????????????4???4??????el???????k??????????????????HD???????f???v??se???????k????N??h????????D?????.NT??????????????????????????j?j?????g?ys????????????s?????sol???????????t?????s%\?????????????????s????????????? ??????? ???????4???f???????e??????????????????????????????????LegacyDriver?????????????f???j?j?f???????f??KSecDD?060???????????%??????????LegacyDriver?????f???????g???????????????????????????????????????????????f?f?i?i?f?i?:???/?l6???PCI\VEN_1022&DEV_1204&SUBSYS_00000000&REV_00?PCI\VE
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???j?j????????????R??j????????h???????0??p???n?????eta??PnP Filter?????????????????g??????????????????????b??j?????????n????????????????????????@%SystemRoot%\system32\drivers\fltmgr.sys,-10000????????????????p???System32\drivers\hwpolicy.sys????j???j???j?????k?l??1.2.0.125????????q????T??j????????h????????j?j????????????????????????f????????????e????System32\Drivers\ksecdd.sys???????:??j????????h??????????j???0??e2???????????n??????????p???Fs_Rec?00????????j???????????j????????????????????????????????????????????????8??j????????h??????????????????d???????????????????????????5???F??????d6???? ??5??????p?????????????????????????b??j?????????n????.NT?ms??oem3.inf?????j??????????????????????????g???system32\DRIVERS\nwifi.sys???????????????????????v??????????????????????? ???f???\?????\To??????????%SystemRoot%\System32\srvsvc.dll??????L??p??????k???????????????t???text????System32\Drivers\ksecpkg.sys?????????????5??s????????????????????????j??????p????????????d?????????V2A???????j????????????????????????????m??k?
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???j?j????????????????????????f????????????e????System32\Drivers\ksecdd.sys???????:??j????????h??????????j???0??e2???????????n??????????p???Fs_Rec?00????????j???????????j????????????????????????????????????????????????8??j????????h??????????????????d???????????????????????????5???F??????d6???? ??5??????p?????????????????????????b??j?????????n????.NT?ms??oem3.inf?????j??????????????????????????g???system32\DRIVERS\nwifi.sys???????????????????????v??????????????????????? ???f???\?????\To??????????%SystemRoot%\System32\srvsvc.dll??????L??p??????k???????????????t???text????System32\Drivers\ksecpkg.sys?????????????5??s????????????????????????j??????p????????????d?????????V2A???????j????????????????????????????m??k??????????????????????????HIDClass????????????????????????????????????p???Cryptography?????????j???????e????<??j????????h??????j??????????tunnel???????j???j???????????????????j?????j?n??????????????????????Maurice??????????h??@%SystemRoot%\system32\drivers\fileinfo.sys,-100?????????j???-??e5????X????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???j?n??????????????????????Maurice??????????h??@%SystemRoot%\system32\drivers\fileinfo.sys,-100?????????j???-??e5????X??????????e???s?z?s???????j???0???2?????? ??????g????????z.????P??j????????h?????@%SystemRoot%\system32\drivers\nsiproxy.sys,-2???????????????????????n??%m??%m??????????????RPCSS?????????8????????????e?????????j????<??j????????h??????????????????p???l???k??????????PNP_TDI??????????g???????????????????????k??????????Extended Base???????C0??????r???????????????Controls the underlying video driver stacks to provide fully-featured display capabilities.?????Keyboard Class???????????k???????????????????????????j??????????????????system32\drivers\nsiproxy.sys??????????????????????????????????????g?????????????????e???????j???9????????????????????????????Z??j?????????e????input.inf????f?h?j?g?t??\SystemRoot\system32\drivers\HDAudBus.sys??????j????system32\DRIVERS\kl1.sys?????????????????????????????????????s??rpcss???????????????????t???7616269602?8?<?????j?????u?u?u?????|?9?|????????t???????p????l?
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ???j????system32\DRIVERS\kl1.sys?????????????????????????????????????s??rpcss???????????????????t???7616269602?8?<?????j?????u?u?u?????|?9?|????????t???????p????l?x?}?}?}???????????m???p??????????????????????????????????????????t??????????????g?????????????s??*PNP09FF????sh???????k???????????????????h??????????????????????????????????????@%SystemRoot%\system32\drivers\mountmgr.sys,-101?????j?j?j?j?j?j?j??system32\drivers\ndis.sys????????????l??????????system32\drivers\MSPCLOCK.sys???s???Typ??????????????????n???????????????m?m?????????????????????s??????????????????t????j????????????????4??j?????????????????????????l?m???m?m?????????????+???+??NDIS Wrapper????\SystemRoot\system32\drivers\luafv.sys??????????????????????????????????????????????Microsoft????k?k????????????base????????????????t???t???????????????t????????????????????????f?f?j?j?j?j?j??????????????{0??????????????????????????????????????@%SystemRoot%\system32\drivers\fvevol.sys,-100????????2??j????????h??????????????????????????????.?????????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???j?????u?u?u?????|?9?|????????t???????p????l?x?}?}?}???????????m???p??????????????????????????????????????????t??????????????g?????????????s??*PNP09FF????sh???????k???????????????????h??????????????????????????????????????@%SystemRoot%\system32\drivers\mountmgr.sys,-101?????j?j?j?j?j?j?j??system32\drivers\ndis.sys????????????l??????????system32\drivers\MSPCLOCK.sys???s???Typ??????????????????n???????????????m?m?????????????????????s??????????????????t????j????????????????4??j?????????????????????????l?m???m?m?????????????+???+??NDIS Wrapper????\SystemRoot\system32\drivers\luafv.sys??????????????????????????????????????????????Microsoft????k?k????????????base????????????????t???t???????????????t????????????????????????f?f?j?j?j?j?j??????????????{0??????????????????????????????????????@%SystemRoot%\system32\drivers\fvevol.sys,-100????????2??j????????h??????????????????????????????.?????????????j?k??\SystemRoot\system32\drivers\kbdhid.sys?????system32\DRIVERS\kl2.sys?????~???????????????j?????????????????????
---- EOF - GMER 1.0.15 ---- --- --- ---
OSAM
OSAM Logfile: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 13:37:37 on 04.07.2011
OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 5.0
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Kaspersky Lab ZAO" - C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll
"AppInit_DLLs" - "Kaspersky Lab ZAO" - C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll
[Boot Execute]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager )-----
"BootExecute" - ? - C:\Windows\system32\lsdelete.exe (File found, but it contains no detailed information)
[Common]
-----( %SystemRoot%\Tasks )-----
"Ad-Aware Update (Weekly).job" - "Lavasoft Limited " - C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"PhysX.cpl" - "NVIDIA Corporation" - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys (File found, but it contains no detailed information)
"catchme" (catchme) - ? - C:\Users\Maurice\AppData\Local\Temp\catchme.sys (File not found)
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found)
"Lavasoft helper driver" (Lavasoft Kernexplorer) - ? - C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys (File found, but it contains no detailed information)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"Profos" (Profos) - ? - C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys (File not found)
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
{872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - c:\program files\real\realplayer\rpshell.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{52B87208-9CCF-42C9-B88E-069281105805} "Trojan Remover Shell Extension" - ? - (File not found | COM-object registry key not found)
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 (HTTP value)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "&Windows Live Toolbar" - "Microsoft Corporation" - C:\Program Files\Windows Live\Toolbar\wltcore.dll
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{4248FE82-7FCB-46AC-B270-339F08212110} "&Virtuelle Tastatur" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
"eBay - Der weltweite Online-Marktplatz" - ? - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 (HTTP value)
"ICQ7.5" - "ICQ, LLC." - C:\Program Files\ICQ7.5\ICQ.exe
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "In Blog veröffentlichen" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
{CCF151D8-D089-449F-A5A4-D9909053F20F} "Li&nks untersuchen" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "&Windows Live Toolbar" - "Microsoft Corporation" - C:\Program Files\Windows Live\Toolbar\wltcore.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{E33CF602-D945-461A-83F0-819F76A199F8} "FilterBHO Class" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} "IEVkbdBHO Class" - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} "Search Helper" - "Microsoft Corporation" - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} "Windows Live Toolbar Helper" - "Microsoft Corporation" - C:\Program Files\Windows Live\Toolbar\wltcore.dll
[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corporation" - C:\Windows\system32\livessp.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Shortcut exists | File exists)
"desktop.ini" - ? - C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"Adobe Gamma Loader.lnk" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ICQ" - "ICQ, LLC." - "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
"Logitech Vid" - "Logitech Inc." - "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode
"SpybotSD TeaTimer" - "Safer Networking Limited" - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"AVP" - "Kaspersky Lab ZAO" - "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
"CLMLServer" - "CyberLink" - "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
"HTC Sync Loader" - ? - "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LWS" - "Logitech Inc." - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"TkBellExe" - "RealNetworks, Inc." - "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"FABS - Helping agent for MAGIX media database" (Fabs) - "MAGIX AG" - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
"Firebird Server - MAGIX Instance" (FirebirdServerMAGIXInstance) - "MAGIX®" - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
"Internet Pass-Through Service" (PassThru Service) - ? - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Kaspersky Anti-Virus Service" (AVP) - "Kaspersky Lab ZAO" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
"Lavasoft Ad-Aware Service" (Lavasoft Ad-Aware Service) - "Lavasoft Limited" - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe (File found, but it contains no detailed information)
"Protexis Licensing V2" (PSI_SVC_2) - "Protexis Inc." - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
"SeaPort" (SeaPort) - "Microsoft Corporation" - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
"WindowsLive Local NSP" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
===[ Logfile end ]=========================================[ Logfile end ]=== --- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru[/QUOTE]
MBR Zitat:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 32-bit
Base Board Manufacturer: MEDIONPC
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: MEDIONPC
System Product Name: MS-7646
Logical Drives Mask: 0x000000fc
Kernel Drivers (total 161):
0x83245000 \SystemRoot\system32\ntkrnlpa.exe
0x8320E000 \SystemRoot\system32\halmacpi.dll
0x80BC5000 \SystemRoot\system32\kdcom.dll
0x8C20A000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x8C215000 \SystemRoot\system32\PSHED.dll
0x8C226000 \SystemRoot\system32\BOOTVID.dll
0x8C22E000 \SystemRoot\system32\CLFS.SYS
0x8C270000 \SystemRoot\system32\CI.dll
0x8C31B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8C38C000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8C39A000 \SystemRoot\system32\drivers\ACPI.sys
0x8C3E2000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8C3EB000 \SystemRoot\system32\drivers\msisadrv.sys
0x8C41F000 \SystemRoot\system32\drivers\pci.sys
0x8C449000 \SystemRoot\system32\drivers\vdrvroot.sys
0x8C454000 \SystemRoot\System32\drivers\partmgr.sys
0x8C465000 \SystemRoot\system32\drivers\volmgr.sys
0x8C475000 \SystemRoot\System32\drivers\volmgrx.sys
0x8C4C0000 \SystemRoot\system32\DRIVERS\amdide.sys
0x8C4C7000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8C4D5000 \SystemRoot\System32\drivers\mountmgr.sys
0x8C4EB000 \SystemRoot\system32\drivers\atapi.sys
0x8C4F4000 \SystemRoot\system32\drivers\ataport.SYS
0x8C517000 \SystemRoot\system32\DRIVERS\amdsata.sys
0x8C528000 \SystemRoot\system32\DRIVERS\storport.sys
0x8C570000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8C579000 \SystemRoot\system32\drivers\fltmgr.sys
0x8C5AD000 \SystemRoot\system32\drivers\fileinfo.sys
0x8C5BE000 \SystemRoot\system32\DRIVERS\Lbd.sys
0x8C60C000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8C73B000 \SystemRoot\System32\Drivers\msrpc.sys
0x8C766000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8C779000 \SystemRoot\System32\Drivers\cng.sys
0x8C7D6000 \SystemRoot\System32\drivers\pcw.sys
0x8C7E4000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8C830000 \SystemRoot\system32\drivers\ndis.sys
0x8C8E7000 \SystemRoot\system32\drivers\NETIO.SYS
0x8C925000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8CA0F000 \SystemRoot\System32\drivers\tcpip.sys
0x8CB59000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8CB8A000 \SystemRoot\system32\drivers\volsnap.sys
0x8CBC9000 \SystemRoot\System32\Drivers\spldr.sys
0x8CBD1000 \SystemRoot\System32\drivers\rdyboost.sys
0x8C94A000 \SystemRoot\System32\Drivers\mup.sys
0x8CC31000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8D153000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8D15B000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8D18D000 \SystemRoot\system32\DRIVERS\disk.sys
0x8D19E000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8D1C3000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x8CC11000 \SystemRoot\system32\drivers\cdrom.sys
0x8C95A000 \SystemRoot\system32\DRIVERS\klif.sys
0x8D1F3000 \SystemRoot\System32\Drivers\Null.SYS
0x8CA00000 \SystemRoot\System32\Drivers\Beep.SYS
0x8C9DA000 \SystemRoot\System32\drivers\vga.sys
0x8C800000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8C821000 \SystemRoot\System32\drivers\watchdog.sys
0x8CA07000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8C9E6000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8C9EE000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8C7ED000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8C5CD000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8C5DB000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C600000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x92A2C000 \SystemRoot\system32\drivers\afd.sys
0x92A86000 \SystemRoot\System32\DRIVERS\netbt.sys
0x92AB8000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x92ABF000 \SystemRoot\system32\DRIVERS\pacer.sys
0x92ADE000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x92AEF000 \SystemRoot\system32\DRIVERS\klim6.sys
0x92AF7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x92B05000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x92B18000 \SystemRoot\system32\drivers\termdd.sys
0x92B29000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x92B6A000 \SystemRoot\system32\drivers\nsiproxy.sys
0x92B74000 \SystemRoot\system32\drivers\mssmbios.sys
0x92B7E000 \SystemRoot\System32\drivers\discache.sys
0x92B8A000 \SystemRoot\System32\Drivers\dfsc.sys
0x92BA2000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x92BB0000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x92BD1000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x92A00000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x9300C000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x93601000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x936B8000 \SystemRoot\System32\drivers\dxgmms1.sys
0x936F1000 \SystemRoot\system32\drivers\HDAudBus.sys
0x93710000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x9376A000 \SystemRoot\system32\drivers\1394ohci.sys
0x93797000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x9379D000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x937A7000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x937F2000 \SystemRoot\system32\DRIVERS\usbfilter.sys
0x93588000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x93597000 \SystemRoot\system32\drivers\CompositeBus.sys
0x935A4000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x935B6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x935CE000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x935D9000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x92BE2000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8C400000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x93A27000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x93A3E000 \SystemRoot\system32\drivers\kbdclass.sys
0x93A4B000 \SystemRoot\system32\drivers\mouclass.sys
0x93A58000 \SystemRoot\system32\drivers\swenum.sys
0x93A5A000 \SystemRoot\system32\drivers\ks.sys
0x93A8E000 \SystemRoot\system32\drivers\umbus.sys
0x93A9C000 \SystemRoot\system32\drivers\usbhub.sys
0x93AE0000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x93AF1000 \SystemRoot\system32\drivers\AtiHdmi.sys
0x93B0F000 \SystemRoot\system32\drivers\portcls.sys
0x93B3E000 \SystemRoot\system32\drivers\drmk.sys
0x94238000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x9450C000 \SystemRoot\system32\DRIVERS\RTL8192su.sys
0x945B5000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x945BF000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x945D6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x945D8000 \SystemRoot\System32\Drivers\crashdmp.sys
0x945E5000 \SystemRoot\System32\Drivers\dump_diskdump.sys
0x945EF000 \SystemRoot\System32\Drivers\dump_amdsata.sys
0x94200000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x99A80000 \SystemRoot\System32\win32k.sys
0x94211000 \SystemRoot\System32\drivers\Dxapi.sys
0x9421B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x93B57000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x94226000 \SystemRoot\system32\drivers\hidusb.sys
0x93B6E000 \SystemRoot\system32\drivers\HIDCLASS.SYS
0x94231000 \SystemRoot\system32\drivers\HIDPARSE.SYS
0x9D61E000 \SystemRoot\system32\DRIVERS\lvuvc.sys
0x9DA3F000 \SystemRoot\system32\drivers\usbaudio.sys
0x9DA53000 \SystemRoot\system32\DRIVERS\lvrs.sys
0x9DA99000 \SystemRoot\system32\drivers\kbdhid.sys
0x9DAA5000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x9DAB0000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x99CE0000 \SystemRoot\System32\TSDDD.dll
0x99D10000 \SystemRoot\System32\cdd.dll
0x9DAB9000 \SystemRoot\system32\drivers\luafv.sys
0x9DAD4000 \SystemRoot\system32\drivers\WudfPf.sys
0x9DAEE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9DAFE000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9DB44000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9DB54000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9DB67000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x9DB70000 \SystemRoot\system32\drivers\HTTP.sys
0x9D600000 \SystemRoot\system32\DRIVERS\bowser.sys
0x93B81000 \SystemRoot\System32\drivers\mpsdrv.sys
0x93B93000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x93BB6000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x93A00000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9D619000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xA382B000 \SystemRoot\system32\drivers\peauth.sys
0xA38C2000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA38CC000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA38ED000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA38FA000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA394A000 \SystemRoot\System32\DRIVERS\srv.sys
0xA399C000 \SystemRoot\System32\drivers\ipnat.sys
0xA39C2000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0xA39E3000 \??\C:\Windows\system32\drivers\mbam.sys
0x76EC0000 \Windows\System32\ntdll.dll
0x475B0000 \Windows\System32\smss.exe
0x77100000 \Windows\System32\apisetschema.dll
Processes (total 67):
0 System Idle Process
4 System
352 C:\Windows\System32\smss.exe
496 csrss.exe
580 C:\Windows\System32\wininit.exe
592 csrss.exe
632 C:\Windows\System32\services.exe
652 C:\Windows\System32\lsass.exe
660 C:\Windows\System32\lsm.exe
744 C:\Windows\System32\winlogon.exe
816 C:\Windows\System32\svchost.exe
892 C:\Windows\System32\svchost.exe
956 C:\Windows\System32\atiesrxx.exe
1016 C:\Windows\System32\svchost.exe
1056 C:\Windows\System32\svchost.exe
1088 C:\Windows\System32\svchost.exe
1128 C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1272 C:\Windows\System32\svchost.exe
1348 C:\Windows\System32\atieclxx.exe
1572 C:\Windows\System32\dwm.exe
1604 C:\Windows\explorer.exe
1788 C:\Windows\System32\spoolsv.exe
1800 C:\Windows\System32\taskhost.exe
1848 C:\Windows\System32\svchost.exe
1936 C:\Windows\System32\svchost.exe
1992 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
300 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
716 C:\Program Files\Bonjour\mDNSResponder.exe
908 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
1320 C:\Windows\System32\svchost.exe
1600 C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
116 C:\Windows\System32\PnkBstrA.exe
2076 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
2100 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2152 C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
2192 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
2208 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
2308 C:\Windows\System32\svchost.exe
2400 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2444 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
2564 C:\Program Files\iTunes\iTunesHelper.exe
2584 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
2596 C:\Program Files\Real\RealPlayer\Update\realsched.exe
2808 C:\Program Files\Windows Sidebar\sidebar.exe
2860 C:\Program Files\ICQ7.5\ICQ.exe
2900 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
3236 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
4032 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
3344 C:\Program Files\Mozilla Firefox\firefox.exe
2476 C:\Program Files\Mozilla Firefox\plugin-container.exe
4072 C:\Program Files\iPod\bin\iPodService.exe
2892 C:\Windows\System32\alg.exe
1764 C:\Windows\System32\SearchIndexer.exe
4140 C:\Windows\System32\taskhost.exe
4236 C:\Program Files\Windows Media Player\wmpnetwk.exe
4276 WUDFHost.exe
5652 C:\Windows\System32\svchost.exe
4216 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
3204 C:\Windows\System32\svchost.exe
2728 C:\Windows\System32\svchost.exe
4356 <unknown>
5840 <unknown>
3728 C:\Windows\explorer.exe
1400 C:\Windows\System32\audiodg.exe
3272 C:\Users\Maurice\Desktop\MBRCheck.exe
5212 C:\Windows\System32\conhost.exe
5464 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000158`10c00000 (NTFS)
PhysicalDrive0 Model Number: WDCWD15EARS-00Z5B1, Rev: 80.00A80
Size Device Name MBR Status
--------------------------------------------
1397 GB \\.\PhysicalDrive0
|
Warum lagt mein Rechner jetzt nach den durchläufen von den drei Programmen?
Das hat er vorher nicht..-.-
Und ich habe die drei Logs so gepostet, weil das in einem Quote Fenster zu unübersichtlich wäre. Nehme ich mal an. |