vielen lieben dank fue deine reaktion, anbei die logs:
Attach:
[code]
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.DDS Logfile: Code:
DDS (Ver_2011-08-26.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
.
'Full Speed' Internet Booster + Performance Tests
7-Zip 9.20
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Apple Application Support
Apple Software Update
avast! Internet Security
Bitcoin
CCleaner
Command & Conquer Generals
Command and ConquerTM Generals Zero Hour
CoreAVC Professional Edition (remove only)
CrystalDiskInfo 4.1.3
DVDFab 8.1.7.5 (07/04/2012) Qt
FileASSASSIN
FileServe Manager 1.0.0.3394
FileZilla Client 3.5.3
GPL Ghostscript
Haali Media Splitter
HD Tune Pro 5.00
HDDlife Pro 4.0
IncrediMail
IncrediMail 2.0
IncrediMail Password Recovery
Internet Cyclone 1.92
IrfanView (remove only)
Java Auto Updater
Java(TM) 6 Update 31
Java(TM) 7 Update 3
K-Lite Mega Codec Pack 7.8.0
LG Tool Kit
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft .NET Framework 4 Client Profile
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft_VC100_CRT_SP1_x86
MSVC80_x86_v2
MSVC90_x86
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mytoolsoft Watermark Software 2.7.6
Nokia Connectivity Cable Driver
Nokia Ovi Suite Software Updater
Nokia Suite
Notepad++
NTREGOPT 1.1j
NVIDIA Graphics Driver 296.10
NVIDIA Install Application
OviMPlatform
PantsOff 2.0
PC Connectivity Solution
PDF-XChange Viewer
PerfectDisk 10 Professional
PhotoME
PowerISO
QuickTime
Realtek AC'97 Audio
Registry Repair 4.1.0.388
RouterControl 2.0
Samsung New PC Studio
Samsung SF-360_CF-360 Series
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
SRWare Iron version SRWare Iron 18.0.1050.0
System Requirements Lab
TeamViewer 7
Technitium MAC Address Changer v6.0
Tinypic 3.18
TUGZip 3.5
TuneUp Utilities 2011
TuneUp Utilities Language Pack (en-US)
Uniblue SpeedUpMyPC
Unlocker 1.9.1
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Virtual CD v10
WIDCOMM Bluetooth Software 6.0.1.6300
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
WinPcap 4.1.2
WinUtilities 10.38 Professional Edition
WordToPDF 2.7
.
==== End Of File =========================== DDS: Code:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by ----- at 12:53:48 on 2012-05-23
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uWindow Title = >>> 'Full Speed' Enabled <<<
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
uPolicies-explorer: HideClock = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Download with FileServe Manager - c:\program files\fileserve manager\GetUrl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\microsoft office\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: Interfaces\{177994D8-96D5-4F24-AA0A-66B749006129} : NameServer = 208.67.222.222,208.67.220.220
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-05-22 13:12:56 -------- d-----w- c:\users\-----\appdata\roaming\GlarySoft
2012-05-22 13:04:46 -------- d-----w- c:\program files\Uniblue
2012-05-22 12:21:31 -------- d-----w- c:\program files\Glarysoft
2012-05-21 10:12:57 -------- d-----w- c:\program files\Passcape
2012-05-18 11:58:38 -------- d-----w- c:\users\-----\appdata\roaming\Profiles
2012-05-18 11:58:37 -------- d-----w- c:\users\-----\appdata\roaming\Skins
2012-05-18 11:58:37 -------- d-----w- c:\users\-----\appdata\roaming\Settings
2012-05-18 11:58:37 -------- d-----w- c:\users\-----\appdata\roaming\Language
2012-05-10 20:37:24 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-10 20:37:21 936960 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2012-05-10 20:37:20 989184 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2012-05-10 20:37:20 969216 ----a-w- c:\program files\windows journal\JNWDRV.dll
2012-05-10 20:37:20 1221632 ----a-w- c:\program files\windows journal\NBDoc.DLL
2012-05-10 20:37:04 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-10 20:37:04 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-10 20:37:03 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-05-10 20:36:02 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-10 20:36:00 1077248 ----a-w- c:\windows\system32\DWrite.dll
2012-05-05 12:35:11 -------- d-----w- c:\program files\common files\SpeechEngines
2012-05-02 18:50:37 -------- d-sh--w- c:\programdata\MPK
2012-05-02 18:50:37 -------- d-sh--w- c:\program files\KGB
2012-04-30 21:37:12 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-04-30 21:36:48 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-04-30 21:36:48 19444544 ----a-w- c:\windows\system32\nvoglv32.dll
2012-04-30 21:36:48 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
2012-04-28 17:09:20 -------- d-----w- c:\users\-----\appdata\roaming\HD Tune Pro
2012-04-28 17:06:19 -------- d-----w- c:\program files\HDTune
2012-04-28 16:44:43 -------- d-----w- c:\users\-----\appdata\local\Western Digital
2012-04-28 16:36:57 -------- d-----w- c:\users\-----\appdata\roaming\BinarySense
2012-04-28 16:35:48 -------- d-----w- c:\program files\HdLife
2012-04-28 16:35:48 -------- d-----w- c:\program files\common files\BinarySense
2012-04-28 15:41:51 59904 ----a-w- c:\windows\system32\wbemdisp.tlb
2012-04-28 15:41:51 102160 ----a-w- c:\windows\system32\VB6KO.DLL
2012-04-28 15:41:50 16384 ----a-w- c:\windows\system32\lgfwunis.exe
2012-04-28 15:41:50 115016 ----a-w- c:\windows\system32\MSINET.OCX
2012-04-28 15:41:50 -------- d-----w- c:\program files\lg_fwupdate
2012-04-28 15:41:41 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2012-04-28 15:41:41 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2012-04-28 15:41:41 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll
2012-04-28 15:41:41 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2012-04-28 15:41:40 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2012-04-28 15:32:00 -------- d-----w- c:\program files\DVD Genie
.
==================== Find3M ====================
.
2012-05-22 13:26:12 249856 ----a-w- c:\windows\system32\uxtheme.dll
2012-05-22 13:26:10 2755072 ----a-w- c:\windows\system32\themeui.dll
2012-05-22 13:26:07 37376 ----a-w- c:\windows\system32\themeservice.dll
2012-05-10 06:54:28 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-10 06:54:28 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-08 16:35:20 60416 ----a-w- c:\windows\ALCFDRTM.VER
2012-04-04 13:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-27 12:54:29 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-03-27 12:54:29 567696 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-24 11:40:47 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2012-03-07 20:40:02 1010720 --s---r- c:\windows\system32\MSCHRT20.OCX
2012-03-01 05:46:57 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-03-01 05:37:41 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-03-01 05:33:23 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-03-01 05:29:16 5120 ----a-w- c:\windows\system32\wmi.dll
2012-02-29 23:59:00 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:59:00 5892928 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:59:00 2517312 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:59:00 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-02-29 23:59:00 2301248 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:59:00 17543488 ----a-w- c:\windows\system32\nvcompiler.dll
2012-02-29 23:59:00 15009600 ----a-w- c:\windows\system32\nvd3dum.dll
2012-02-29 23:59:00 10819392 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-02-29 20:56:41 3881792 ----a-w- c:\windows\system32\nvcpl.dll
2012-02-29 20:55:16 2719040 ----a-w- c:\windows\system32\nvsvc.dll
2012-02-29 20:53:47 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-02-29 20:53:46 645440 ----a-w- c:\windows\system32\nvvsvc.exe
2012-02-29 20:53:46 62272 ----a-w- c:\windows\system32\nvshext.dll
2012-02-28 01:18:55 1799168 ----a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 12:54:58.06 =============== --- --- ---
Gmer:
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-05-23 12:44:41
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_SP1203N rev.TL100-30
Running: rqfnzd0n.exe; Driver: C:\Users\-----\AppData\Local\Temp\pgddqpow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8B2E7CAE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAlpcSendWaitReceivePort [0x8B2EA16E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8B2E9B34]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8B2E9B8C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8B2E9CA2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8B2E9A8A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8B2E9BDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8B2E9ADE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8B2E9C50]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8B2E7CD2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8B2E7ADA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8B2E7CF6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8B2EA548]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8B2E87F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8B2E9B64]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8B2E9BB4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8B2E9CCC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8B2E9AB6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8B2E9C1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8B2E9B0C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8B2E9C7A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8B2E86BE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwReplyWaitReceivePort [0x8B2EA57E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwReplyWaitReceivePortEx [0x8B2EA142]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8B2E7D1A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8B2E7D3E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8B2E7B34]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8B2E7C44]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8B2E7C56]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x910A8BAE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwRollbackEnlistment + 1409 83047989 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 830674E2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 1393 8306E750 4 Bytes [AE, 7C, 2E, 8B]
.text ntoskrnl.exe!KeRemoveQueueEx + 140B 8306E7C8 4 Bytes [6E, A1, 2E, 8B]
.text ntoskrnl.exe!KeRemoveQueueEx + 146F 8306E82C 8 Bytes [34, 9B, 2E, 8B, 8C, 9B, 2E, ...]
.text ntoskrnl.exe!KeRemoveQueueEx + 147B 8306E838 4 Bytes [A2, 9C, 2E, 8B]
.text ntoskrnl.exe!KeRemoveQueueEx + 1497 8306E854 4 Bytes [8A, 9A, 2E, 8B]
.text ...
PAGE ntoskrnl.exe!ObMakeTemporaryObject 831F448A 5 Bytes JMP 910A45D4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!RtlCompareUnicodeStrings + 50C 8321B9D6 5 Bytes JMP 910A6012 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 832E4944 7 Bytes JMP 910A8BB2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? C:\Users\-----\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtCreateFile + 6 779855CE 4 Bytes [28, 00, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtCreateFile + B 779855D3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtMapViewOfSection + 6 77985C2E 1 Byte [28]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtMapViewOfSection + 6 77985C2E 4 Bytes [28, 03, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtMapViewOfSection + B 77985C33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenFile + 6 77985CDE 4 Bytes [68, 00, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenFile + B 77985CE3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenProcess + 6 77985D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenProcess + B 77985D93 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenProcessToken + 6 77985D9E 4 Bytes CALL 769874A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenProcessToken + B 77985DA3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenProcessTokenEx + 6 77985DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenProcessTokenEx + B 77985DB3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenThread + 6 77985E0E 4 Bytes [68, 01, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenThread + B 77985E13 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenThreadToken + 6 77985E1E 4 Bytes [68, 02, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenThreadToken + B 77985E23 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenThreadTokenEx + 6 77985E2E 4 Bytes CALL 76987535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtOpenThreadTokenEx + B 77985E33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtQueryAttributesFile + 6 77985F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtQueryAttributesFile + B 77985F43 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtQueryFullAttributesFile + 6 77985FEE 4 Bytes CALL 769876F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtQueryFullAttributesFile + B 77985FF3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtSetInformationFile + 6 7798663E 4 Bytes [28, 01, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtSetInformationFile + B 77986643 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtSetInformationThread + 6 7798669E 4 Bytes [28, 02, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtSetInformationThread + B 779866A3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 1 Byte [68]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 4 Bytes [68, 03, 17, 00]
.text C:\Program Files\SRWare Iron\iron.exe[840] ntdll.dll!NtUnmapViewOfSection + B 779869C3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtCreateFile + 6 779855CE 4 Bytes [28, 00, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtCreateFile + B 779855D3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtMapViewOfSection + 6 77985C2E 1 Byte [28]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtMapViewOfSection + 6 77985C2E 4 Bytes [28, 03, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtMapViewOfSection + B 77985C33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenFile + 6 77985CDE 4 Bytes [68, 00, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenFile + B 77985CE3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenProcess + 6 77985D8E 4 Bytes [A8, 01, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenProcess + B 77985D93 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenProcessToken + 6 77985D9E 4 Bytes CALL 76987AA4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenProcessToken + B 77985DA3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenProcessTokenEx + 6 77985DAE 4 Bytes [A8, 02, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenProcessTokenEx + B 77985DB3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenThread + 6 77985E0E 4 Bytes [68, 01, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenThread + B 77985E13 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenThreadToken + 6 77985E1E 4 Bytes [68, 02, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenThreadToken + B 77985E23 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenThreadTokenEx + 6 77985E2E 4 Bytes CALL 76987B35 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtOpenThreadTokenEx + B 77985E33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtQueryAttributesFile + 6 77985F3E 4 Bytes [A8, 00, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtQueryAttributesFile + B 77985F43 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtQueryFullAttributesFile + 6 77985FEE 4 Bytes CALL 76987CF3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtQueryFullAttributesFile + B 77985FF3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtSetInformationFile + 6 7798663E 4 Bytes [28, 01, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtSetInformationFile + B 77986643 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtSetInformationThread + 6 7798669E 4 Bytes [28, 02, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtSetInformationThread + B 779866A3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 1 Byte [68]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 4 Bytes [68, 03, 1D, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1108] ntdll.dll!NtUnmapViewOfSection + B 779869C3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtCreateFile + 6 779855CE 4 Bytes [28, 00, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtCreateFile + B 779855D3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtMapViewOfSection + 6 77985C2E 1 Byte [28]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtMapViewOfSection + 6 77985C2E 4 Bytes [28, 03, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtMapViewOfSection + B 77985C33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenFile + 6 77985CDE 4 Bytes [68, 00, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenFile + B 77985CE3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenProcess + 6 77985D8E 4 Bytes [A8, 01, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenProcess + B 77985D93 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenProcessToken + 6 77985D9E 4 Bytes CALL 76989DA4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenProcessToken + B 77985DA3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenProcessTokenEx + 6 77985DAE 4 Bytes [A8, 02, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenProcessTokenEx + B 77985DB3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenThread + 6 77985E0E 4 Bytes [68, 01, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenThread + B 77985E13 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenThreadToken + 6 77985E1E 4 Bytes [68, 02, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenThreadToken + B 77985E23 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenThreadTokenEx + 6 77985E2E 4 Bytes CALL 76989E35 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtOpenThreadTokenEx + B 77985E33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtQueryAttributesFile + 6 77985F3E 4 Bytes [A8, 00, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtQueryAttributesFile + B 77985F43 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtQueryFullAttributesFile + 6 77985FEE 4 Bytes CALL 76989FF3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtQueryFullAttributesFile + B 77985FF3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtSetInformationFile + 6 7798663E 4 Bytes [28, 01, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtSetInformationFile + B 77986643 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtSetInformationThread + 6 7798669E 4 Bytes [28, 02, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtSetInformationThread + B 779866A3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 1 Byte [68]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 4 Bytes [68, 03, 40, 00]
.text C:\Program Files\SRWare Iron\iron.exe[1436] ntdll.dll!NtUnmapViewOfSection + B 779869C3 1 Byte [E2]
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1720] kernel32.dll!SetUnhandledExceptionFilter 7768F4FB 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtCreateFile + 6 779855CE 4 Bytes [28, 00, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtCreateFile + B 779855D3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtMapViewOfSection + 6 77985C2E 1 Byte [28]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtMapViewOfSection + 6 77985C2E 4 Bytes [28, 03, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtMapViewOfSection + B 77985C33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenFile + 6 77985CDE 4 Bytes [68, 00, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenFile + B 77985CE3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenProcess + 6 77985D8E 4 Bytes [A8, 01, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenProcess + B 77985D93 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenProcessToken + 6 77985D9E 4 Bytes CALL 76987CA4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenProcessToken + B 77985DA3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenProcessTokenEx + 6 77985DAE 4 Bytes [A8, 02, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenProcessTokenEx + B 77985DB3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenThread + 6 77985E0E 4 Bytes [68, 01, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenThread + B 77985E13 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenThreadToken + 6 77985E1E 4 Bytes [68, 02, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenThreadToken + B 77985E23 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenThreadTokenEx + 6 77985E2E 4 Bytes CALL 76987D35 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtOpenThreadTokenEx + B 77985E33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtQueryAttributesFile + 6 77985F3E 4 Bytes [A8, 00, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtQueryAttributesFile + B 77985F43 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtQueryFullAttributesFile + 6 77985FEE 4 Bytes CALL 76987EF3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtQueryFullAttributesFile + B 77985FF3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtSetInformationFile + 6 7798663E 4 Bytes [28, 01, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtSetInformationFile + B 77986643 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtSetInformationThread + 6 7798669E 4 Bytes [28, 02, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtSetInformationThread + B 779866A3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 1 Byte [68]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 4 Bytes [68, 03, 1F, 00]
.text C:\Program Files\SRWare Iron\iron.exe[2000] ntdll.dll!NtUnmapViewOfSection + B 779869C3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtCreateFile + 6 779855CE 4 Bytes [28, 00, 33, 00] {SUB [EAX], AL; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtCreateFile + B 779855D3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtMapViewOfSection + 6 77985C2E 1 Byte [28]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtMapViewOfSection + 6 77985C2E 4 Bytes [28, 03, 33, 00] {SUB [EBX], AL; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtMapViewOfSection + B 77985C33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenFile + 6 77985CDE 4 Bytes [68, 00, 33, 00]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenFile + B 77985CE3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenProcess + 6 77985D8E 4 Bytes [A8, 01, 33, 00] {TEST AL, 0x1; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenProcess + B 77985D93 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenProcessToken + 6 77985D9E 4 Bytes CALL 769890A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenProcessToken + B 77985DA3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenProcessTokenEx + 6 77985DAE 4 Bytes [A8, 02, 33, 00] {TEST AL, 0x2; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenProcessTokenEx + B 77985DB3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenThread + 6 77985E0E 4 Bytes [68, 01, 33, 00]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenThread + B 77985E13 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenThreadToken + 6 77985E1E 4 Bytes [68, 02, 33, 00]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenThreadToken + B 77985E23 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenThreadTokenEx + 6 77985E2E 4 Bytes CALL 76989135 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtOpenThreadTokenEx + B 77985E33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtQueryAttributesFile + 6 77985F3E 4 Bytes [A8, 00, 33, 00] {TEST AL, 0x0; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtQueryAttributesFile + B 77985F43 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtQueryFullAttributesFile + 6 77985FEE 4 Bytes CALL 769892F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtQueryFullAttributesFile + B 77985FF3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtSetInformationFile + 6 7798663E 4 Bytes [28, 01, 33, 00] {SUB [ECX], AL; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtSetInformationFile + B 77986643 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtSetInformationThread + 6 7798669E 4 Bytes [28, 02, 33, 00] {SUB [EDX], AL; XOR EAX, [EAX]}
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtSetInformationThread + B 779866A3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 1 Byte [68]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 4 Bytes [68, 03, 33, 00]
.text C:\Program Files\SRWare Iron\iron.exe[3668] ntdll.dll!NtUnmapViewOfSection + B 779869C3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtCreateFile + 6 779855CE 4 Bytes [28, 00, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtCreateFile + B 779855D3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtMapViewOfSection + 6 77985C2E 1 Byte [28]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtMapViewOfSection + 6 77985C2E 4 Bytes [28, 03, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtMapViewOfSection + B 77985C33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenFile + 6 77985CDE 4 Bytes [68, 00, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenFile + B 77985CE3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenProcess + 6 77985D8E 4 Bytes [A8, 01, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenProcess + B 77985D93 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenProcessToken + 6 77985D9E 4 Bytes CALL 7698A0A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenProcessToken + B 77985DA3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenProcessTokenEx + 6 77985DAE 4 Bytes [A8, 02, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenProcessTokenEx + B 77985DB3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenThread + 6 77985E0E 4 Bytes [68, 01, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenThread + B 77985E13 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenThreadToken + 6 77985E1E 4 Bytes [68, 02, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenThreadToken + B 77985E23 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenThreadTokenEx + 6 77985E2E 4 Bytes CALL 7698A135 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtOpenThreadTokenEx + B 77985E33 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtQueryAttributesFile + 6 77985F3E 4 Bytes [A8, 00, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtQueryAttributesFile + B 77985F43 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtQueryFullAttributesFile + 6 77985FEE 4 Bytes CALL 7698A2F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtQueryFullAttributesFile + B 77985FF3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtSetInformationFile + 6 7798663E 4 Bytes [28, 01, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtSetInformationFile + B 77986643 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtSetInformationThread + 6 7798669E 4 Bytes [28, 02, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtSetInformationThread + B 779866A3 1 Byte [E2]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 1 Byte [68]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtUnmapViewOfSection + 6 779869BE 4 Bytes [68, 03, 43, 00]
.text C:\Program Files\SRWare Iron\iron.exe[4088] ntdll.dll!NtUnmapViewOfSection + B 779869C3 1 Byte [E2]
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
---- Services - GMER 1.0.15 ----
Service C:\Windows\system32\DRIVERS\vdrv1000.sys (*** hidden *** ) [SYSTEM] vdrv1000 <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\00190e0d2b2c (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\00190e0d2b2c@fca13efdb1f7 0x52 0x8F 0xFF 0xE2 ...
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\00190e0d2b2c@9c4a7b422655 0xC5 0x59 0x86 0x88 ...
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@ServiceBinary C:\Windows\system32\drivers\VDRV1000.SYS
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@Group SCSI Miniport
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@ImagePath system32\DRIVERS\vdrv1000.sys
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@Start 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@Type 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000@Tag 64
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\Enum (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\Enum@0 ROOT\SCSIADAPTER\0000
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\Enum@Count 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\Enum@NextInstance 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\Enum@INITSTARTFAILED 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\parameters\pnpinterface (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\parameters\pnpinterface@1 1
Reg HKLM\SYSTEM\ControlSet001\services\vdrv1000\security (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00190e0d2b2c
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00190e0d2b2c@fca13efdb1f7 0x52 0x8F 0xFF 0xE2 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00190e0d2b2c@9c4a7b422655 0xC5 0x59 0x86 0x88 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@ServiceBinary C:\Windows\system32\drivers\VDRV1000.SYS
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@Group SCSI Miniport
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@ImagePath system32\DRIVERS\vdrv1000.sys
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000@Tag 64
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\Enum
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\Enum@0 ROOT\SCSIADAPTER\0000
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\Enum@Count 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\Enum@NextInstance 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\Enum@INITSTARTFAILED 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\parameters
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\parameters\pnpinterface
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\parameters\pnpinterface@1 1
Reg HKLM\SYSTEM\CurrentControlSet\services\vdrv1000\security
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\00190e0d2b2c (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\00190e0d2b2c@fca13efdb1f7 0x52 0x8F 0xFF 0xE2 ...
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\00190e0d2b2c@9c4a7b422655 0xC5 0x59 0x86 0x88 ...
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@ServiceBinary C:\Windows\system32\drivers\VDRV1000.SYS
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@Group SCSI Miniport
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@ImagePath system32\DRIVERS\vdrv1000.sys
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@Start 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@Type 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000@Tag 64
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\Enum (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\Enum@0 ROOT\SCSIADAPTER\0000
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\Enum@Count 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\Enum@NextInstance 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\Enum@INITSTARTFAILED 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\parameters\pnpinterface (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\parameters\pnpinterface@1 1
Reg HKLM\SYSTEM\ControlSet003\services\vdrv1000\security (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\## aswSnx private storage 0 bytes
File C:\## aswSnx private storage\snx_rhive 262144 bytes
File C:\## aswSnx private storage\snx_rhive.LOG1 9216 bytes
File C:\## aswSnx private storage\snx_rhive.LOG2 0 bytes
File C:\## aswSnx private storage\snx_rhive{9dfc2b22-a40a-11e1-b8b3-2433a5b4733b}.TM.blf 65536 bytes
File C:\## aswSnx private storage\snx_rhive{9dfc2b22-a40a-11e1-b8b3-2433a5b4733b}.TMContainer00000000000000000001.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\snx_rhive{9dfc2b22-a40a-11e1-b8b3-2433a5b4733b}.TMContainer00000000000000000002.regtrans-ms 524288 bytes
---- EOF - GMER 1.0.15 ---- --- --- --- |