Hier nun das gmer-log:
[code]
GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-25 19:47:38
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\00000057 WDC_WD32 rev.11.0
Running: 271kulpl.exe; Driver: C:\Users\JOHANN~1\AppData\Local\Temp\agldrkow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8F43D708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x90D6F7C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0x8F43E11C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8F448F28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8F448F74]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8F4490F6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8F448E96]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0x90D6FBBA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8F448EDE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThread [0x8F43E310]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThreadEx [0x8F43E498]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8F4490B0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDebugActiveProcess [0x8F43EA9C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8F43D756]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x90D6F8AC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8F43D3BE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8F43D7A4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8F442456]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8F43F464]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8F448F52]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8F448F96]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8F44911A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8F448EBC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8F44903A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8F448F06]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8F4490D4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x90D6FA2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8F43F330]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueueApcThreadEx [0x8F43F06C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8F43D7F2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8F43D840]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetContextThread [0x8F43E91C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8F43D448]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8F43D5F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8F43D59E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendProcess [0x8F43EBFE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendThread [0x8F43ED5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8F43D668]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0x90D6FAF6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwTerminateThread [0x8F43E794]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8F43D88E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0x90D6F962]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x90D87966]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82C583C9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C91D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82C98D80 4 Bytes [08, D7, 43, 8F]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82C98DA8 4 Bytes [C8, F7, D6, 90] {ENTER 0xd6f7, 0x90}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82C98E08 4 Bytes [1C, E1, 43, 8F]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82C98E5C 8 Bytes [28, 8F, 44, 8F, 74, 8F, 44, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82C98E68 4 Bytes [F6, 90, 44, 8F]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82E25C64 5 Bytes JMP 90D84806 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 82E3E290 5 Bytes JMP 90D86338 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82E533D7 4 Bytes CALL 8F43FB07 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82E6D1E0 4 Bytes CALL 8F43FB1D \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82EF711A 7 Bytes JMP 90D8796A \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91022000, 0x2D5378, 0xE8000020]
.text kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\csrss.exe[452] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[524] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[532] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[564] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text ...
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001503FC
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001501F8
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\DRIVERS\xaudio.exe[1064] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\AUDIODG.EXE[1140] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\atieclxx.exe[1252] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1332] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1412] kernel32.dll!SetUnhandledExceptionFilter 75F1F4FB 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1412] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1504] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1532] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1596] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1644] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text ...
.text C:\Windows\system32\Dwm.exe[2420] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[2420] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[2420] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2420] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\Dwm.exe[2420] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\Dwm.exe[2420] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\Dwm.exe[2420] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\Dwm.exe[2420] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\taskhost.exe[2444] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[2444] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[2444] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[2444] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 00170A08
.text C:\Windows\system32\taskhost.exe[2444] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001703FC
.text C:\Windows\system32\taskhost.exe[2444] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 00170804
.text C:\Windows\system32\taskhost.exe[2444] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001701F8
.text C:\Windows\system32\taskhost.exe[2444] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 00170600
.text C:\Windows\system32\SearchFilterHost.exe[2564] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2720] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2720] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2720] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2720] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 002A0A08
.text C:\Windows\system32\svchost.exe[2720] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 002A03FC
.text C:\Windows\system32\svchost.exe[2720] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 002A0804
.text C:\Windows\system32\svchost.exe[2720] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 002A01F8
.text C:\Windows\system32\svchost.exe[2720] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 002A0600
.text C:\Windows\System32\svchost.exe[2760] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[2768] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[2768] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[2768] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[2768] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 00110A08
.text C:\Windows\Explorer.EXE[2768] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001103FC
.text C:\Windows\Explorer.EXE[2768] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 00110804
.text C:\Windows\Explorer.EXE[2768] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001101F8
.text C:\Windows\Explorer.EXE[2768] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 00110600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2904] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3108] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[3108] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[3108] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3108] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 00090A08
.text C:\Windows\system32\SearchIndexer.exe[3108] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 000903FC
.text C:\Windows\system32\SearchIndexer.exe[3108] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 00090804
.text C:\Windows\system32\SearchIndexer.exe[3108] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 000901F8
.text C:\Windows\system32\SearchIndexer.exe[3108] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 00090600
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001603FC
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001601F8
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 00190A08
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001903FC
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 00190804
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001901F8
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3244] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 00190600
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3340] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Launch Manager\LManager.exe[3632] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001603FC
.text C:\Program Files\Launch Manager\LManager.exe[3632] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001601F8
.text C:\Program Files\Launch Manager\LManager.exe[3632] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\Launch Manager\LManager.exe[3632] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 00560A08
.text C:\Program Files\Launch Manager\LManager.exe[3632] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 005603FC
.text C:\Program Files\Launch Manager\LManager.exe[3632] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 00560804
.text C:\Program Files\Launch Manager\LManager.exe[3632] USER32.dll!SetWinEventHook 75CA24DC 3 Bytes JMP 005601F8
.text C:\Program Files\Launch Manager\LManager.exe[3632] USER32.dll!SetWinEventHook + 4 75CA24E0 1 Byte [8A]
.text C:\Program Files\Launch Manager\LManager.exe[3632] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 00560600
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001603FC
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001601F8
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 002F0A08
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 002F03FC
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 002F0804
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 002F01F8
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3640] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 002F0600
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3660] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 001603FC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 001601F8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3680] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\SearchProtocolHost.exe[3804] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchProtocolHost.exe[3804] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchProtocolHost.exe[3804] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
.text C:\Windows\system32\SearchProtocolHost.exe[3804] USER32.dll!UnhookWindowsHookEx 75C9ADF9 5 Bytes JMP 000D0A08
.text C:\Windows\system32\SearchProtocolHost.exe[3804] USER32.dll!UnhookWinEvent 75C9B750 5 Bytes JMP 000D03FC
.text C:\Windows\system32\SearchProtocolHost.exe[3804] USER32.dll!SetWindowsHookExW 75C9E30C 5 Bytes JMP 000D0804
.text C:\Windows\system32\SearchProtocolHost.exe[3804] USER32.dll!SetWinEventHook 75CA24DC 5 Bytes JMP 000D01F8
.text C:\Windows\system32\SearchProtocolHost.exe[3804] USER32.dll!SetWindowsHookExA 75CC6D0C 5 Bytes JMP 000D0600
.text C:\Windows\system32\svchost.exe[4056] ntdll.dll!LdrUnloadDll 7746C86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[4056] ntdll.dll!LdrLoadDll 7747223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[4056] kernel32.dll!GetBinaryTypeW + 70 75F369F4 1 Byte [62]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1412] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [71E0F6D0] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll (Common functions/AVAST Software)
IAT C:\Program Files\AVAST Software\Avast\AvastUI.exe[2904] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [71E0F6D0] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll (Common functions/AVAST Software)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernelmodustreiber-Frameworklaufzeit/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004b halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:2952] A5462F2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001060d092ff
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001060d092ff (not active ControlSet)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\***_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP\HP\xa0Update.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP\xa0Update.lnk 1
---- EOF - GMER 1.0.15 ---- --- --- ---
OSAM liefert: Code:
OSAM Logfile:
Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:58:19 on 25.09.2012
OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 15.0.1
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Common]
-----( %SystemRoot%\Tasks )-----
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\Windows\system32\drivers\aswFsBlk.sys
"aswMonFlt" (aswMonFlt) - "AVAST Software" - C:\Windows\system32\drivers\aswMonFlt.sys
"aswRdr" (aswRdr) - "AVAST Software" - C:\Windows\System32\Drivers\aswrdr2.sys
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys
"aswSP" (aswSP) - "AVAST Software" - C:\Windows\system32\drivers\aswSP.sys
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\Windows\system32\drivers\aswTdi.sys
"catchme" (catchme) - ? - C:\Users\JOHANN~1\AppData\Local\Temp\catchme.sys (File not found)
"Dritek General Port I/O" (DritekPortIO) - ? - C:\Program Files\Launch Manager\DPortIO.sys (File not found)
[Explorer]
-----( HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components )-----
6de2ed6f-0b56-4d57-b0f0-551ec8cbb27f "StubPath" - "Expert System S.p.A." - C:\ProgramData\Duden\dkreg.exe /dktray=on /csapi=on /ALLUSERS
{07e84f41-11d5-4615-aaf6-368df0762b41} "StubPath" - "Expert System S.p.A." - C:\ProgramData\Duden\dkreg.exe /dktray=off /csapi=off /ALLUSERS
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807563E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Program Files\AVAST Software\Avast\ashShell.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office12\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{555D4D79-4BD2-4094-A395-CFC534424A05} "{555D4D79-4BD2-4094-A395-CFC534424A05}" - ? - (File not found | COM-object registry key not found)
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Research" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "avast! WebRep" - "AVAST Software" - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} "avast! WebRep" - "AVAST Software" - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
{53707962-6F74-2D53-2644-206D7942484F} "Spybot-S&D IE Protection" - "Safer Networking Limited" - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[Known DLLs]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs )-----
"advapi32" - "Microsoft Corporation" - C:\Windows\system32\advapi32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"clbcatq" - "Microsoft Corporation" - C:\Windows\system32\clbcatq.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"COMDLG32" - "Microsoft Corporation" - C:\Windows\system32\COMDLG32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"DifxApi" - "Microsoft Corporation" - C:\Windows\system32\difxapi.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"gdi32" - "Microsoft Corporation" - C:\Windows\system32\gdi32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"IERTUTIL" - "Microsoft Corporation" - C:\Windows\system32\IERTUTIL.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"IMAGEHLP" - "Microsoft Corporation" - C:\Windows\system32\IMAGEHLP.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"IMM32" - "Microsoft Corporation" - C:\Windows\system32\IMM32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"kernel32" - "Microsoft Corporation" - C:\Windows\system32\kernel32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"LPK" - "Microsoft Corporation" - C:\Windows\system32\LPK.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"MSCTF" - "Microsoft Corporation" - C:\Windows\system32\MSCTF.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"MSVCRT" - "Microsoft Corporation" - C:\Windows\system32\MSVCRT.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"NORMALIZ" - "Microsoft Corporation" - C:\Windows\system32\NORMALIZ.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"NSI" - "Microsoft Corporation" - C:\Windows\system32\NSI.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"ole32" - "Microsoft Corporation" - C:\Windows\system32\ole32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"OLEAUT32" - "Microsoft Corporation" - C:\Windows\system32\OLEAUT32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"PSAPI" - "Microsoft Corporation" - C:\Windows\system32\PSAPI.DLL (Hidden registry entry, rootkit activity | File signed by Microsoft)
"rpcrt4" - "Microsoft Corporation" - C:\Windows\system32\rpcrt4.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"sechost" - "Microsoft Corporation" - C:\Windows\system32\sechost.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"Setupapi" - "Microsoft Corporation" - C:\Windows\system32\Setupapi.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"SHELL32" - "Microsoft Corporation" - C:\Windows\system32\SHELL32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"SHLWAPI" - "Microsoft Corporation" - C:\Windows\system32\SHLWAPI.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"URLMON" - "Microsoft Corporation" - C:\Windows\system32\URLMON.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"user32" - "Microsoft Corporation" - C:\Windows\system32\user32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"USP10" - "Microsoft Corporation" - C:\Windows\system32\USP10.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"WININET" - "Microsoft Corporation" - C:\Windows\system32\WININET.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"WLDAP32" - "Microsoft Corporation" - C:\Windows\system32\WLDAP32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
"WS2_32" - "Microsoft Corporation" - C:\Windows\system32\WS2_32.dll (Hidden registry entry, rootkit activity | File signed by Microsoft)
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\***_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"avast" - "AVAST Software" - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"HP Software Update" - "Hewlett-Packard" - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"LManager" - "Dritek System Inc." - C:\Program Files\Launch Manager\LManager.exe
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"doPDF 7 Monitor" - "Softland" - C:\Windows\system32\dopdfmn7.dll
"Send To Microsoft OneNote Monitor" - "Microsoft Corporation" - C:\Windows\system32\msonpmon.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
"HP Network Devices Support" (HPSLPSVC) - "Hewlett-Packard Co." - C:\Users\***\AppData\Local\Temp\7zS1BE4\hpslpsvc32.dll
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Office Diagnostics Service" (odserv) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
===[ Logfile end ]=========================================[ Logfile end ]=== --- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru Ich hoffe aswMBR hat richtig funktioniert, ich wurde nicht gefragt ob ich ein
Definitions-Update machen will.
aswMBR liefert: Code:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-25 20:23:17
-----------------------------
20:23:17.240 OS Version: Windows 6.1.7601 Service Pack 1
20:23:17.256 Number of processors: 2 586 0x301
20:23:17.256 ComputerName: ***-PC UserName: ***_2
20:23:20.360 Initialize success
20:23:20.704 AVAST engine defs: 12092500
20:23:23.621 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058
20:23:23.636 Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 11
20:23:23.652 Disk 0 MBR read successfully
20:23:23.668 Disk 0 MBR scan
20:23:23.683 Disk 0 Windows 7 default MBR code
20:23:23.699 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048
20:23:23.714 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 205242 MB offset 20482048
20:23:23.761 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 89999 MB offset 440819712
20:23:23.777 Disk 0 scanning sectors +625137664
20:23:23.855 Disk 0 scanning C:\Windows\system32\drivers
20:23:39.985 Service scanning
20:24:06.880 Modules scanning
20:24:24.102 Disk 0 trace - called modules:
20:24:24.133 ntkrnlpa.exe CLASSPNP.SYS disk.sys amdxata.sys ACPI.sys halmacpi.dll storport.sys amdsata.sys
20:24:24.165 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x861c8030]
20:24:24.180 3 CLASSPNP.SYS[8ada959e] -> nt!IofCallDriver -> [0x861869c8]
20:24:24.196 5 amdxata.sys[8ab967b6] -> nt!IofCallDriver -> [0x86186f08]
20:24:24.227 7 ACPI.sys[833a13d4] -> nt!IofCallDriver -> \Device\00000058[0x86182030]
20:24:25.990 AVAST engine scan C:\Windows
20:24:29.094 AVAST engine scan C:\Windows\system32
20:27:16.592 AVAST engine scan C:\Windows\system32\drivers
20:27:49.539 AVAST engine scan C:\Users\***_2
20:28:09.242 AVAST engine scan C:\ProgramData
20:28:30.770 Scan finished successfully
20:28:50.707 Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\MBR.dat"
20:28:50.723 The log file has been saved successfully to "C:\Users\***\Desktop\aswMBR.txt" |