Amerilion | 21.03.2011 20:12 | GERM: Code:
GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-03-21 19:56:26
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.BKFO
Running: 77fvwhd8.exe; Driver: C:\Users\******\AppData\Local\Temp\ugddrpoc.sys
---- System - GMER 1.0.15 ----
INT 0x62 ? 87A18F00
INT 0x72 ? 87A18F00
INT 0x82 ? 87A18F00
INT 0x82 ? 87A18F00
INT 0xA2 ? 8612EC88
INT 0xA2 ? 87A18F00
INT 0xA2 ? 87A18F00
INT 0xA2 ? 8612EC88
INT 0xA3 ? 87A18F00
INT 0xB1 ? 85797C88
INT 0xB1 ? 85797C88
---- Kernel code sections - GMER 1.0.15 ----
? System32\Drivers\spfk.sys Das System kann den angegebenen Pfad nicht finden. !
.text USBPORT.SYS!DllUnload 8ECE741B 5 Bytes JMP 87A18450
.text an6s76n6.SYS 901A5000 47 Bytes [82, 23, 1D, 83, 6C, 22, 1D, ...]
.text an6s76n6.SYS 901A5031 147 Bytes [68, E5, 82, 55, 80, E3, 82, ...]
.text an6s76n6.SYS 901A50C6 17 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; DEC EBP; SUB AL, 0x7c}
.text an6s76n6.SYS 901A50D8 14 Bytes [00, 00, 00, 00, 02, 00, 00, ...]
.text an6s76n6.SYS 901A50E7 31 Bytes [00, F0, 0E, 00, 00, 00, 00, ...]
.text ...
.text a9vp902v.SYS 8ED92000 47 Bytes [82, 23, 1D, 83, 6C, 22, 1D, ...]
.text a9vp902v.SYS 8ED92031 147 Bytes [68, E5, 82, 55, 80, E3, 82, ...]
.text a9vp902v.SYS 8ED920C6 17 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; LEAVE ; HLT ; POP ESP}
.text a9vp902v.SYS 8ED920D8 14 Bytes [00, 00, 00, 00, 02, 00, 00, ...]
.text a9vp902v.SYS 8ED920E7 31 Bytes [00, F0, 0E, 00, 00, 00, 00, ...]
.text ...
.vmp2 C:\Windows\system32\drivers\acedrv11.sys entry point in ".vmp2" section [0xA1F3869D]
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA1F3D300, 0x3B6D8, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA1F83300, 0x1BEE, 0xE8000020]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [80693F9C] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong] [806933E6] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8069390E] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80694178] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [80693116] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [806931D4] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A4976] \SystemRoot\System32\Drivers\spfk.sys
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[HAL.dll!KfAcquireSpinLock] 00F90000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[HAL.dll!KfReleaseSpinLock] 00500000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[storport.sys!StorPortPauseDevice] 009F0000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[storport.sys!StorPortResumeDevice] 00A80000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[storport.sys!StorPortInitialize] 00510000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[storport.sys!StorPortNotification] 00A30000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[TDI.SYS!TdiDeregisterPnPHandlers] 00920000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[TDI.SYS!TdiRegisterPnPHandlers] 009D0000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[NETIO.SYS!WskDeregister] 00F50000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[NETIO.SYS!WskReleaseProviderNPI] 00BC0000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[NETIO.SYS!WskRegister] 00B60000
IAT \SystemRoot\System32\Drivers\an6s76n6.SYS[NETIO.SYS!WskCaptureProviderNPI] 00DA0000
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[HAL.dll!KfAcquireSpinLock] 00005500
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[HAL.dll!KfReleaseSpinLock] 00008C00
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[storport.sys!StorPortPauseDevice] 00008900
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[storport.sys!StorPortResumeDevice] 00000D00
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[storport.sys!StorPortInitialize] 0000BF00
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[storport.sys!StorPortNotification] 0000E600
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[TDI.SYS!TdiDeregisterPnPHandlers] 00004100
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[TDI.SYS!TdiRegisterPnPHandlers] 00009900
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[NETIO.SYS!WskDeregister] 00000F00
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[NETIO.SYS!WskReleaseProviderNPI] 0000B000
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[NETIO.SYS!WskRegister] 00005400
IAT \SystemRoot\System32\Drivers\a9vp902v.SYS[NETIO.SYS!WskCaptureProviderNPI] 0000BB00
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74957817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [749AA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7495BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7494F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [749575E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7494E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74988395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7495DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7494FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7494FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [749471CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [749DCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7497C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7494D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74946853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7494687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3936] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74952AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 861321F8
Device \FileSystem\fastfat \FatCdrom 8ABDB1F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 8579A1F8
Device \Driver\usbuhci \Device\USBPDO-0 879F71F8
Device \Driver\usbuhci \Device\USBPDO-1 879F71F8
Device \Driver\usbuhci \Device\USBPDO-2 879F71F8
Device \Driver\usbehci \Device\USBPDO-3 879F91F8
Device \Driver\usbuhci \Device\USBPDO-4 879F71F8
Device \Driver\PCI_PNP6025 \Device\00000055 spfk.sys
Device \Driver\usbuhci \Device\USBPDO-5 879F71F8
Device \Driver\PCI_PNP6025 \Device\00000056 spfk.sys
Device \Driver\usbuhci \Device\USBPDO-6 879F71F8
Device \Driver\volmgr \Device\HarddiskVolume1 8579A1F8
Device \Driver\usbehci \Device\USBPDO-7 879F91F8
Device \Driver\volmgr \Device\HarddiskVolume2 8579A1F8
Device \Driver\cdrom \Device\CdRom0 87C221F8
Device \Driver\volmgr \Device\HarddiskVolume3 8579A1F8
Device \Driver\cdrom \Device\CdRom1 87C221F8
Device \Driver\sptd \Device\3880142041 spfk.sys
Device \Driver\netbt \Device\NetBt_Wins_Export 895541F8
Device \Driver\Smb \Device\NetbiosSmb 8956A398
Device \Driver\netbt \Device\NetBT_Tcpip_{45E75BEF-57A4-4901-9DB3-E4AE1503AE2D} 895541F8
Device \Driver\iScsiPrt \Device\RaidPort0 87CA61F8
Device \Driver\usbuhci \Device\USBFDO-0 879F71F8
Device \Driver\usbuhci \Device\USBFDO-1 879F71F8
Device \Driver\usbuhci \Device\USBFDO-2 879F71F8
Device \Driver\usbehci \Device\USBFDO-3 879F91F8
Device \Driver\usbuhci \Device\USBFDO-4 879F71F8
Device \Driver\usbuhci \Device\USBFDO-5 879F71F8
Device \Driver\sptd \Device\3880298042 spfk.sys
Device \Driver\usbuhci \Device\USBFDO-6 879F71F8
Device \Driver\usbehci \Device\USBFDO-7 879F91F8
Device \Driver\a9vp902v \Device\Scsi\a9vp902v1Port3Path0Target0Lun0 87CB3470
Device \Driver\a9vp902v \Device\Scsi\a9vp902v1 87CB3470
Device \Driver\an6s76n6 \Device\Scsi\an6s76n61 87C5D470
Device \FileSystem\fastfat \Fat 8ABDB1F8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 92F841F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\002243c7c22a (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\002243c7c22a@40a6d933de76 0x22 0xFA 0x90 0x3D ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x27 0x95 0x36 0x53 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7F 0x1F 0xC1 0xAB ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x55 0xD9 0x2E 0xA3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xEE 0xD6 0x34 0xD1 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x22 0x1B 0x1A 0x69 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002243c7c22a
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002243c7c22a@40a6d933de76 0x22 0xFA 0x90 0x3D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x27 0x95 0x36 0x53 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x13 0xFC 0x39 0x9C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x55 0xD9 0x2E 0xA3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xDD 0x7E 0x52 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x22 0x1B 0x1A 0x69 ...
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\002243c7c22a (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\002243c7c22a@40a6d933de76 0x22 0xFA 0x90 0x3D ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x27 0x95 0x36 0x53 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x82 0x6F 0xCF 0xD5 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x55 0xD9 0x2E 0xA3 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xDD 0x7E 0x52 0x02 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x22 0x1B 0x1A 0x69 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures@User_Feed_Synchronization-{CA64AF00-3FA6-4A84-83EA-9D622EE2C500}.job.fp 1971410001
---- EOF - GMER 1.0.15 ----
OSAM: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 20:07:25 on 21.03.2011
OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.15
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"ISUSPM.cpl" - "InstallShield Software Corporation" - C:\Windows\system32\ISUSPM.cpl
"nvcpl.cpl" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
"Pando" - "Pando Networks" - C:\Program Files\Pando Networks\Media Booster\PMB.cpl
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"a9vp902v" (a9vp902v) - "Microsoft Corporation" - C:\Windows\system32\drivers\a9vp902v.sys (Hidden registry entry, rootkit activity | File signed by Microsoft)
"acedrv11" (acedrv11) - "Protect Software GmbH" - C:\Windows\system32\drivers\acedrv11.sys
"an6s76n6" (an6s76n6) - "Microsoft Corporation" - C:\Windows\system32\drivers\an6s76n6.sys (Hidden registry entry, rootkit activity | File signed by Microsoft)
"ASMMAP" (ASMMAP) - ? - C:\Program Files\ATKGFNEX\ASMMAP.sys
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys (File found, but it contains no detailed information)
"AVerMedia A815" (AVerAF15) - "AVerMedia TECHNOLOGIES, Inc." - C:\Windows\System32\Drivers\AVerAF15.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\******\AppData\Local\Temp\catchme.sys (File not found)
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found)
"ghaio" (ghaio) - ? - C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys (File found, but it contains no detailed information)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys (File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys (File found, but it contains no detailed information)
"oUltraf" (oUltraf) - ? - C:\Users\*******\AppData\Local\Temp\oUltraf.sys (File not found)
"Philips SA60xx Recovery Device" (VtcDrv) - "Windows (R) Codename Longhorn DDK provider" - C:\Windows\System32\Drivers\vtcdrv.sys
"REVOLTEC FightBoard" (systormflb) - ? - C:\Windows\System32\DRIVERS\systormflb.sys (File not found)
"sptd" (sptd) - "Duplex Secure Ltd." - C:\Windows\System32\Drivers\sptd.sys (File is exclusively opened, access blocked)
"Spyware Terminator Driver 2" (sp_rsdrv2) - ? - C:\Windows\system32\drivers\sp_rsdrv2.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"Syntek STK1150" (StkAMini) - "Syntek America Inc." - C:\Windows\System32\Drivers\StkAMini.sys
"Syntek STK1150 Filter Driver" (StkScan) - "Syntek America Inc." - C:\Windows\System32\Drivers\StkScan.sys
"ugddrpoc" (ugddrpoc) - ? - C:\Users\******\AppData\Local\Temp\ugddrpoc.sys (Hidden registry entry, rootkit activity | File not found)
"XDva327" (XDva327) - ? - C:\Windows\system32\XDva327.sys (File not found)
[Explorer]
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\Display\nvui.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? - (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{BD88A479-9623-4897-8546-BC62B9628F44} "SPTHandler" - "Crawler.com" - C:\Program Files\Spyware Terminator\sptcontmenu.dll
{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} "UnlockerShellExtension" - ? - C:\Program Files\Unlocker\UnlockerCOM.dll (File found, but it contains no detailed information)
{DBD8E168-244D-448C-9922-25508950D1DC} "USIShellExt Class" - "Ulead Systems, Inc." - C:\Program Files\Common Files\Ulead Systems\DVD\USIShex.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
<binary data> "{D4027C7F-154A-4066-A1AD-4243D8127440}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_23" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_23.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
"FlashGet" - "FlashGet.com" - C:\Program Files\FlashGet\FlashGet.exe
"ICQ7.2" - "ICQ, LLC." - C:\Program Files\ICQ7.2\ICQ.exe
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} "FGCatchUrl" - "www.flashget.com" - C:\Program Files\FlashGet\jccatch.dll
{F156768E-81EF-470C-9057-481BA8380DBA} "FlashGet GetFlash Class" - "www.flashget.com" - C:\Program Files\FlashGet\getflash.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" - "Nero AG" - "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"DAEMON Tools Lite" - "DT Soft Ltd" - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
"ISUSPM Startup" - "InstallShield Software Corporation" - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"ATKMEDIA" - "ASUS" - C:\Program Files\ASUS\ATK Media\DMedia.exe
"ATKOSD2" - "ASUS" - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"HControlUser" - ? - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
"ISUSScheduler" - "InstallShield Software Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"SwitchBoard" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"TkBellExe" - "RealNetworks, Inc." - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UnlockerAssistant" - ? - "C:\Program Files\Unlocker\UnlockerAssistant.exe" (File found, but it contains no detailed information)
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"PCL hpz3l5ha" - "Hewlett-Packard Company" - C:\Windows\system32\hpz3l5ha.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"ASLDR Service" (ASLDRService) - ? - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
"ATKGFNEX Service" (ATKGFNEXSrv) - ? - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Bluetooth Service" (btwdins) - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"FLEXnet Licensing Service" (FLEXnet Licensing Service) - "Macrovision Europe Ltd." - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - ? - C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (File not found)
"hpqcxs08" (hpqcxs08) - ? - C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (File not found)
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"NMIndexingService" (NMIndexingService) - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
"nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des
"NVIDIA Driver Helper Service" (NVSvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
"NVIDIA Stereoscopic 3D Driver Service" (Stereo Service) - "NVIDIA Corporation" - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe (File found, but it contains no detailed information)
"spmgr" (spmgr) - ? - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
"Spyware Terminator Realtime Shield Service" (sp_rssrv) - "Crawler.com" - C:\Program Files\Spyware Terminator\sp_rsser.exe
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"SwitchBoard" (SwitchBoard) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"Syntek AVStream USB2.0 ATV Service" (StkSSrv) - ? - C:\Windows\System32\StkCSrv.exe (File not found)
"Syntek STK1150 Service" (StkASSrv) - "Syntek America Inc." - C:\Windows\System32\StkASv2K.exe
"TeamViewer 6" (TeamViewer6) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
"Ulead Burning Helper" (UleadBurningHelper) - "Ulead Systems, Inc." - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru MBRCheck wollte eine Eingabe, Y für weitere Optionen, ich hab vorläufig auf N gedrückt, Log: Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: ASUSTeK Computer Inc.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: ASUSTeK Computer Inc.
System Product Name: M50Vn
Logical Drives Mask: 0x0000003c
Kernel Drivers (total 172):
0x82E11000 \SystemRoot\system32\ntkrnlpa.exe
0x831CB000 \SystemRoot\system32\hal.dll
0x8040D000 \SystemRoot\system32\kdcom.dll
0x80414000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80484000 \SystemRoot\system32\PSHED.dll
0x80495000 \SystemRoot\system32\BOOTVID.dll
0x8049D000 \SystemRoot\system32\CLFS.SYS
0x804DE000 \SystemRoot\system32\CI.dll
0x80608000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80684000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80691000 \SystemRoot\System32\Drivers\spfk.sys
0x8078A000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x80793000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x807B9000 \SystemRoot\system32\drivers\acpi.sys
0x80600000 \SystemRoot\system32\drivers\msisadrv.sys
0x805BE000 \SystemRoot\system32\drivers\pci.sys
0x805E5000 \SystemRoot\System32\drivers\partmgr.sys
0x805F4000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x80400000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8AE02000 \SystemRoot\system32\drivers\volmgr.sys
0x8AE11000 \SystemRoot\System32\drivers\volmgrx.sys
0x8AE5B000 \SystemRoot\System32\drivers\mountmgr.sys
0x8AE6B000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x8AF44000 \SystemRoot\system32\drivers\atapi.sys
0x8AF4C000 \SystemRoot\system32\drivers\ataport.SYS
0x8AF6A000 \SystemRoot\system32\drivers\msahci.sys
0x8AF74000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8AF82000 \SystemRoot\system32\drivers\fltmgr.sys
0x8AFB4000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B008000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B079000 \SystemRoot\system32\drivers\ndis.sys
0x8B184000 \SystemRoot\system32\drivers\msrpc.sys
0x8B1AF000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B205000 \SystemRoot\System32\drivers\tcpip.sys
0x8B2EF000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B40D000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B51D000 \SystemRoot\system32\drivers\volsnap.sys
0x8B556000 \SystemRoot\System32\Drivers\spldr.sys
0x8B55E000 \SystemRoot\System32\Drivers\mup.sys
0x8B56D000 \SystemRoot\System32\drivers\ecache.sys
0x8B594000 \SystemRoot\system32\drivers\disk.sys
0x8B5A5000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B5C6000 \SystemRoot\system32\drivers\crcdisk.sys
0x8B5DC000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8B5E7000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8B5F0000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8EE0F000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8F7AC000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x8EC00000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8ECA0000 \SystemRoot\System32\drivers\watchdog.sys
0x8ECAC000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8ECB7000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8ECF5000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8ED04000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8FC09000 \SystemRoot\system32\DRIVERS\NETw5v32.sys
0x9001C000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x9002C000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x9003A000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x90054000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x90065000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x90079000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x900CB000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x900DE000 \SystemRoot\system32\DRIVERS\kbfiltr.sys
0x900E6000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x900F1000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x90121000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x90123000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x9012E000 \SystemRoot\system32\DRIVERS\itecir.sys
0x90186000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x9019E000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x901A4000 \SystemRoot\System32\Drivers\an6s76n6.SYS
0x8ED91000 \SystemRoot\System32\Drivers\a9vp902v.SYS
0x901DB000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x901DF000 \SystemRoot\system32\DRIVERS\ATKACPI.sys
0x8EDCA000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8F7AE000 \SystemRoot\system32\DRIVERS\storport.sys
0x901E7000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x901F2000 \SystemRoot\system32\DRIVERS\ManyCam.sys
0x8F7EF000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0x8AFC4000 \SystemRoot\system32\DRIVERS\ks.sys
0x8B3E3000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EE00000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x9020D000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x90230000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x9023F000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x90253000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x90268000 \SystemRoot\system32\DRIVERS\termdd.sys
0x90278000 \SystemRoot\system32\DRIVERS\swenum.sys
0x9027A000 \SystemRoot\system32\DRIVERS\circlass.sys
0x90288000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x90292000 \SystemRoot\system32\DRIVERS\umbus.sys
0x9029F000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x902D4000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x9080D000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x90A1A000 \SystemRoot\system32\drivers\portcls.sys
0x90A47000 \SystemRoot\system32\drivers\drmk.sys
0x90A6C000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x90B92000 \SystemRoot\system32\drivers\modem.sys
0x90B9F000 \SystemRoot\system32\drivers\nvhda32v.sys
0x90BC0000 \SystemRoot\system32\DRIVERS\hidir.sys
0x90BCB000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x90BDB000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x90BE2000 \SystemRoot\system32\drivers\MODEMCSA.sys
0x90BEC000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x90BF5000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x90800000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x902E5000 \SystemRoot\System32\Drivers\Null.SYS
0x902EC000 \SystemRoot\System32\Drivers\Beep.SYS
0x902F3000 \SystemRoot\System32\drivers\vga.sys
0x902FF000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x90320000 \SystemRoot\system32\DRIVERS\ATSwpDrv.sys
0x90343000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x9034B000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90353000 \SystemRoot\System32\Drivers\Msfs.SYS
0x9035E000 \SystemRoot\System32\Drivers\Npfs.SYS
0x9036C000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x90375000 \SystemRoot\system32\DRIVERS\tdx.sys
0x9038B000 \SystemRoot\system32\DRIVERS\smb.sys
0x9039F000 \SystemRoot\system32\drivers\afd.sys
0x90C06000 \SystemRoot\System32\DRIVERS\netbt.sys
0x90C38000 \SystemRoot\system32\DRIVERS\pacer.sys
0x90C4E000 \SystemRoot\system32\DRIVERS\netbios.sys
0x90C5C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x90C6F000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x90C75000 \??\C:\Windows\system32\drivers\sp_rsdrv2.sys
0x90C98000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90CD4000 \SystemRoot\system32\drivers\nsiproxy.sys
0x90CDE000 \SystemRoot\System32\Drivers\dfsc.sys
0x90CF5000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x90D1B000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x90D32000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x90D3B000 \SystemRoot\system32\DRIVERS\etFilter.sys
0x90D6E000 \SystemRoot\system32\DRIVERS\etDevice.sys
0x90DE2000 \SystemRoot\system32\DRIVERS\etScan.sys
0x90DE4000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8B30A000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x9AE30000 \SystemRoot\System32\win32k.sys
0x90DF1000 \SystemRoot\System32\drivers\Dxapi.sys
0x903E7000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9B050000 \SystemRoot\System32\TSDDD.dll
0x9B080000 \SystemRoot\System32\ATMFD.DLL
0xA0003000 \SystemRoot\system32\drivers\luafv.sys
0xA001E000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xA0033000 \SystemRoot\system32\drivers\spsys.sys
0xA00E3000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xA00F3000 \SystemRoot\system32\DRIVERS\nwifi.sys
0xA011D000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA0127000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xA013A000 \??\C:\Program Files\ATKGFNEX\ASMMAP.sys
0xA0141000 \SystemRoot\system32\drivers\HTTP.sys
0xA01AE000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA01CB000 \SystemRoot\system32\DRIVERS\bowser.sys
0xA01E4000 \SystemRoot\System32\drivers\mpsdrv.sys
0xA1E0A000 \SystemRoot\system32\drivers\mrxdav.sys
0xA1E2B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA1E4A000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xA1E83000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xA1E9B000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA1EC3000 \SystemRoot\System32\DRIVERS\srv.sys
0xA1F11000 \??\C:\Windows\system32\drivers\acedrv11.sys
0xA1F3D000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xA1F80000 \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
0xA1F83000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xA3E02000 \SystemRoot\system32\drivers\peauth.sys
0xA3EE0000 \SystemRoot\System32\Drivers\fastfat.SYS
0xA3F08000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA3F12000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA3F1E000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x9B0E0000 \SystemRoot\System32\cdd.dll
0xA3F46000 \??\C:\Users\*****\AppData\Local\Temp\ugddrpoc.sys
0x77D80000 \Windows\System32\ntdll.dll
0x10000000 \Program Files\Alcohol Soft\Alcohol 120\Alcoholx.dll
Processes (total 91):
0 System Idle Process
4 System
504 C:\Windows\System32\smss.exe
580 csrss.exe
632 C:\Windows\System32\wininit.exe
676 C:\Windows\System32\services.exe
712 C:\Windows\System32\lsass.exe
724 C:\Windows\System32\lsm.exe
860 C:\Windows\System32\svchost.exe
964 C:\Windows\System32\nvvsvc.exe
992 C:\Windows\System32\svchost.exe
1096 C:\Windows\System32\svchost.exe
1120 C:\Windows\System32\svchost.exe
1136 C:\Windows\System32\svchost.exe
1212 C:\Windows\System32\audiodg.exe
1232 C:\Windows\System32\svchost.exe
1248 C:\Windows\System32\SLsvc.exe
1288 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\svchost.exe
1516 C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe
1528 C:\Program Files\ATKGFNEX\GFNEXSrv.exe
1592 C:\Windows\System32\taskeng.exe
1636 C:\Windows\System32\spoolsv.exe
1660 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1688 C:\Windows\System32\svchost.exe
2024 C:\Windows\System32\agrsmsvc.exe
2040 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
352 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
520 C:\Program Files\Bonjour\mDNSResponder.exe
588 C:\Windows\System32\svchost.exe
572 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
696 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
1204 C:\Windows\System32\svchost.exe
1928 C:\Windows\System32\svchost.exe
2068 C:\Windows\System32\PnkBstrA.exe
2144 C:\Windows\System32\svchost.exe
2160 C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
2176 C:\Program Files\Spyware Terminator\sp_rsser.exe
2216 C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
2296 C:\Windows\System32\svchost.exe
2308 C:\Windows\System32\StkASv2K.exe
2368 C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
2416 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
2456 C:\Windows\System32\svchost.exe
2580 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2600 C:\Windows\System32\SearchIndexer.exe
2892 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
1428 C:\Windows\System32\svchost.exe
3176 csrss.exe
3360 C:\Windows\System32\winlogon.exe
4036 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
3548 C:\Windows\System32\nvvsvc.exe
1092 C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
1032 C:\Program Files\ASUS\ATK Hotkey\HControl.exe
2720 C:\Program Files\Wireless Console 2\wcourier.exe
3496 C:\Program Files\P4G\BatteryLife.exe
364 C:\Windows\System32\dwm.exe
248 C:\Windows\System32\taskeng.exe
4068 C:\Program Files\TeamViewer\Version6\TeamViewer.exe
3936 C:\Windows\explorer.exe
2208 C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
3772 C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
3232 C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
2084 C:\Program Files\ASUS\ATK Hotkey\WDC.exe
3748 C:\Program Files\TeamViewer\Version6\tv_w32.exe
3376 C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
2676 C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
3152 C:\Windows\RtHDVCpl.exe
832 C:\Program Files\ASUS\ATK Media\DMedia.exe
2464 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2408 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
1924 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
2256 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2272 C:\Program Files\iTunes\iTunesHelper.exe
2688 C:\Program Files\Windows Sidebar\sidebar.exe
880 C:\Program Files\Windows Media Player\wmpnscfg.exe
892 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
1036 C:\Program Files\Windows Media Player\wmpnetwk.exe
816 C:\Program Files\Windows Sidebar\sidebar.exe
4172 C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
4228 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
4328 C:\Program Files\iPod\bin\iPodService.exe
4508 C:\Windows\System32\wuauclt.exe
4596 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
6112 C:\Program Files\Windows NT\Accessories\wordpad.exe
4124 C:\Program Files\Mozilla Firefox\firefox.exe
5712 C:\Program Files\Mozilla Firefox\plugin-container.exe
5320 C:\Windows\System32\SearchProtocolHost.exe
3836 C:\Windows\System32\SearchFilterHost.exe
4840 C:\Users\*****\Desktop\MBRCheck.exe
5520 C:\Windows\System32\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`71200000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000046`d7600000 (NTFS)
PhysicalDrive0 Model Number: HitachiHTS545050KTA300, Rev: BKFOC60G
Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 16FACB29D75458833E397367B1DA17929157C2B3
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done! |