GMER Log: Code:
GMER 1.0.15.15570 - hxxp://www.gmer.net
Rootkit scan 2011-04-05 19:10:45
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-8 WDC_WD2500BEVS-22UST0 rev.01.01A01
Running: 6d2661g9.exe; Driver: C:\Users\Vee\AppData\Local\Temp\pfldypow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8DC4C9CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8EA99A68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8DC4EEAC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8DC4EF04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8DC4F01A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8DC4EE02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8DC4EF54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8DC4EE56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8DC4EFC8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8DC4C9EE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8EA99B18]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8DC4C7B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8DC4CA12]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8DC4F412]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8DC4D4AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8DC4EEDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8DC4EF2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8DC4F044]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8DC4EE2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8DC4EF94]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8DC4EE84]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8DC4EFF2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8EA99BB0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8DC4D370]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8DC4CA36]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8DC4CA5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8DC4C812]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8DC4C94E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8DC4C92A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8DC4C972]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8DC4CA7E]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 82A81589 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AA6092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 214 82AAD824 4 Bytes [CA, C9, C4, 8D]
.text ntkrnlpa.exe!RtlSidHashLookup + 23C 82AAD84C 4 Bytes [68, 9A, A9, 8E]
.text ntkrnlpa.exe!RtlSidHashLookup + 2F0 82AAD900 8 Bytes [AC, EE, C4, 8D, 04, EF, C4, ...] {LODSB ; OUT DX, AL ; LES ECX, DWORD [EBP-0x723b10fc]}
.text ntkrnlpa.exe!RtlSidHashLookup + 2FC 82AAD90C 4 Bytes [1A, F0, C4, 8D]
.text ntkrnlpa.exe!RtlSidHashLookup + 318 82AAD928 4 Bytes [02, EE, C4, 8D]
.text ...
? System32\Drivers\spsl.sys Das System kann den angegebenen Pfad nicht finden. !
.text USBPORT.SYS!DllUnload 8EB59CA0 5 Bytes JMP 85D17450
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00100120
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0010006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001000E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00100030
.text C:\Program Files\Bonjour\mDNSResponder.exe[148] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001000A8
.text C:\Windows\system32\taskhost.exe[360] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\taskhost.exe[360] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\taskhost.exe[360] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 000F0120
.text C:\Windows\system32\taskhost.exe[360] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 000F006C
.text C:\Windows\system32\taskhost.exe[360] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 000F00E4
.text C:\Windows\system32\taskhost.exe[360] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 000F0030
.text C:\Windows\system32\taskhost.exe[360] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 000F00A8
.text C:\Windows\system32\wininit.exe[448] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0007006C
.text C:\Windows\system32\wininit.exe[448] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00070030
.text C:\Windows\system32\wininit.exe[448] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00100120
.text C:\Windows\system32\wininit.exe[448] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0010006C
.text C:\Windows\system32\wininit.exe[448] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001000E4
.text C:\Windows\system32\wininit.exe[448] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00100030
.text C:\Windows\system32\wininit.exe[448] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001000A8
.text C:\Windows\system32\svchost.exe[460] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[460] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\svchost.exe[460] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00250120
.text C:\Windows\system32\svchost.exe[460] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0025006C
.text C:\Windows\system32\svchost.exe[460] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 002500E4
.text C:\Windows\system32\svchost.exe[460] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00250030
.text C:\Windows\system32\svchost.exe[460] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 002500A8
.text C:\Windows\system32\services.exe[516] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\services.exe[516] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\lsass.exe[524] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 000A006C
.text C:\Windows\system32\lsass.exe[524] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 000A0030
.text C:\Windows\system32\lsm.exe[536] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 000A006C
.text C:\Windows\system32\lsm.exe[536] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 000A0030
.text C:\Windows\system32\winlogon.exe[608] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0007006C
.text C:\Windows\system32\winlogon.exe[608] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00070030
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00110120
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0011006C
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001100E4
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00110030
.text C:\Windows\system32\winlogon.exe[608] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001100A8
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\nvvsvc.exe[768] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0016006C
.text C:\Windows\system32\nvvsvc.exe[768] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00160030
.text C:\Windows\system32\nvvsvc.exe[768] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 001F0120
.text C:\Windows\system32\nvvsvc.exe[768] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 001F006C
.text C:\Windows\system32\nvvsvc.exe[768] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001F00E4
.text C:\Windows\system32\nvvsvc.exe[768] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 001F0030
.text C:\Windows\system32\nvvsvc.exe[768] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001F00A8
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\System32\svchost.exe[864] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\System32\svchost.exe[864] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\System32\svchost.exe[864] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 001B0120
.text C:\Windows\System32\svchost.exe[864] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 001B006C
.text C:\Windows\System32\svchost.exe[864] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001B00E4
.text C:\Windows\System32\svchost.exe[864] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 001B0030
.text C:\Windows\System32\svchost.exe[864] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001B00A8
.text C:\Windows\System32\svchost.exe[940] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\System32\svchost.exe[940] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\System32\svchost.exe[940] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 002A0120
.text C:\Windows\System32\svchost.exe[940] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 002A006C
.text C:\Windows\System32\svchost.exe[940] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 002A00E4
.text C:\Windows\System32\svchost.exe[940] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 002A0030
.text C:\Windows\System32\svchost.exe[940] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 002A00A8
.text C:\Windows\system32\svchost.exe[976] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 000A006C
.text C:\Windows\system32\svchost.exe[976] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 000A0030
.text C:\Windows\system32\svchost.exe[976] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00CB0120
.text C:\Windows\system32\svchost.exe[976] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 00CB006C
.text C:\Windows\system32\svchost.exe[976] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 00CB00E4
.text C:\Windows\system32\svchost.exe[976] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00CB0030
.text C:\Windows\system32\svchost.exe[976] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 00CB00A8
.text C:\Windows\system32\svchost.exe[1136] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[1136] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\svchost.exe[1136] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00400120
.text C:\Windows\system32\svchost.exe[1136] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0040006C
.text C:\Windows\system32\svchost.exe[1136] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 004000E4
.text C:\Windows\system32\svchost.exe[1136] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00400030
.text C:\Windows\system32\svchost.exe[1136] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 004000A8
.text C:\Windows\system32\nvvsvc.exe[1240] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0016006C
.text C:\Windows\system32\nvvsvc.exe[1240] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00160030
.text C:\Windows\system32\nvvsvc.exe[1240] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00200120
.text C:\Windows\system32\nvvsvc.exe[1240] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0020006C
.text C:\Windows\system32\nvvsvc.exe[1240] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 002000E4
.text C:\Windows\system32\nvvsvc.exe[1240] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00200030
.text C:\Windows\system32\nvvsvc.exe[1240] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 002000A8
.text C:\Windows\system32\svchost.exe[1264] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[1264] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\svchost.exe[1264] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00900120
.text C:\Windows\system32\svchost.exe[1264] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0090006C
.text C:\Windows\system32\svchost.exe[1264] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 009000E4
.text C:\Windows\system32\svchost.exe[1264] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00900030
.text C:\Windows\system32\svchost.exe[1264] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 009000A8
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1404] kernel32.dll!SetUnhandledExceptionFilter 77023162 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Windows\system32\Dwm.exe[1532] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\Dwm.exe[1532] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\Dwm.exe[1532] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 000F0120
.text C:\Windows\system32\Dwm.exe[1532] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 000F006C
.text C:\Windows\system32\Dwm.exe[1532] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 000F00E4
.text C:\Windows\system32\Dwm.exe[1532] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 000F0030
.text C:\Windows\system32\Dwm.exe[1532] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 000F00A8
.text C:\Windows\Explorer.EXE[1556] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\Explorer.EXE[1556] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\Explorer.EXE[1556] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00150120
.text C:\Windows\Explorer.EXE[1556] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0015006C
.text C:\Windows\Explorer.EXE[1556] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001500E4
.text C:\Windows\Explorer.EXE[1556] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00150030
.text C:\Windows\Explorer.EXE[1556] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001500A8
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0017006C
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00170030
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00210120
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0021006C
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 002100E4
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00210030
.text C:\Program Files\Java\jre6\bin\jusched.exe[1712] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 002100A8
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00100120
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0010006C
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001000E4
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00100030
.text C:\Program Files\iTunes\iTunesHelper.exe[1892] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001000A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00090120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0009006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 000900E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00090030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1972] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 000900A8
.text C:\Windows\System32\spoolsv.exe[2036] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\System32\spoolsv.exe[2036] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\System32\spoolsv.exe[2036] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00140120
.text C:\Windows\System32\spoolsv.exe[2036] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0014006C
.text C:\Windows\System32\spoolsv.exe[2036] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001400E4
.text C:\Windows\System32\spoolsv.exe[2036] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00140030
.text C:\Windows\System32\spoolsv.exe[2036] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001400A8
.text C:\Windows\system32\svchost.exe[2196] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[2196] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\SearchIndexer.exe[2820] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\SearchIndexer.exe[2820] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\SearchIndexer.exe[2820] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00250120
.text C:\Windows\system32\SearchIndexer.exe[2820] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0025006C
.text C:\Windows\system32\SearchIndexer.exe[2820] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 002500E4
.text C:\Windows\system32\SearchIndexer.exe[2820] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00250030
.text C:\Windows\system32\SearchIndexer.exe[2820] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 002500A8
.text C:\Program Files\iPod\bin\iPodService.exe[2876] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0016006C
.text C:\Program Files\iPod\bin\iPodService.exe[2876] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00160030
.text C:\Program Files\iPod\bin\iPodService.exe[2876] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00200120
.text C:\Program Files\iPod\bin\iPodService.exe[2876] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0020006C
.text C:\Program Files\iPod\bin\iPodService.exe[2876] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 002000E4
.text C:\Program Files\iPod\bin\iPodService.exe[2876] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00200030
.text C:\Program Files\iPod\bin\iPodService.exe[2876] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 002000A8
.text C:\Windows\system32\svchost.exe[2928] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[2928] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\svchost.exe[2996] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\svchost.exe[2996] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\svchost.exe[2996] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 001F0120
.text C:\Windows\system32\svchost.exe[2996] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 001F006C
.text C:\Windows\system32\svchost.exe[2996] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001F00E4
.text C:\Windows\system32\svchost.exe[2996] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 001F0030
.text C:\Windows\system32\svchost.exe[2996] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001F00A8
.text C:\Windows\system32\svchost.exe[3052] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 000A006C
.text C:\Windows\system32\svchost.exe[3052] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 000A0030
.text C:\Windows\system32\WUDFHost.exe[3132] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\system32\WUDFHost.exe[3132] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\system32\WUDFHost.exe[3132] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00100120
.text C:\Windows\system32\WUDFHost.exe[3132] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0010006C
.text C:\Windows\system32\WUDFHost.exe[3132] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001000E4
.text C:\Windows\system32\WUDFHost.exe[3132] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00100030
.text C:\Windows\system32\WUDFHost.exe[3132] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001000A8
.text C:\Windows\System32\svchost.exe[3848] ntdll.dll!LdrUnloadDll 77B3BEAF 5 Bytes JMP 0006006C
.text C:\Windows\System32\svchost.exe[3848] ntdll.dll!LdrLoadDll 77B3F5B5 5 Bytes JMP 00060030
.text C:\Windows\System32\svchost.exe[3848] USER32.dll!UnhookWindowsHookEx 773DCC7B 5 Bytes JMP 00180120
.text C:\Windows\System32\svchost.exe[3848] USER32.dll!UnhookWinEvent 773DD924 5 Bytes JMP 0018006C
.text C:\Windows\System32\svchost.exe[3848] USER32.dll!SetWindowsHookExW 773E210A 5 Bytes JMP 001800E4
.text C:\Windows\System32\svchost.exe[3848] USER32.dll!SetWinEventHook 773E507E 5 Bytes JMP 00180030
.text C:\Windows\System32\svchost.exe[3848] USER32.dll!SetWindowsHookExA 77406DFA 5 Bytes JMP 001800A8
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88A1B90E] \SystemRoot\System32\Drivers\spsl.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88A1BF9C] \SystemRoot\System32\Drivers\spsl.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUlong] [88A1B3E6] \SystemRoot\System32\Drivers\spsl.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88A1C178] \SystemRoot\System32\Drivers\spsl.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88A1B1D4] \SystemRoot\System32\Drivers\spsl.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 84A7A1F8
Device \FileSystem\fastfat \FatCdrom 85D25470
Device \Driver\volmgr \Device\VolMgrControl 84A741F8
Device \Driver\usbuhci \Device\USBPDO-0 85DF71F8
Device \Driver\usbuhci \Device\USBPDO-1 85DF71F8
Device \Driver\usbehci \Device\USBPDO-2 85CF5470
Device \Driver\usbuhci \Device\USBPDO-3 85DF71F8
Device \Driver\usbuhci \Device\USBPDO-4 85DF71F8
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{C335EEA2-1750-4D18-8837-E5DC6DB8530E} 85CA11F8
Device \Driver\usbuhci \Device\USBPDO-5 85DF71F8
Device \Driver\usbehci \Device\USBPDO-6 85CF5470
Device \Driver\PCI_PNP4028 \Device\00000057 spsl.sys
Device \Driver\volmgr \Device\HarddiskVolume1 84A741F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\volmgr \Device\HarddiskVolume2 84A741F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\atapi \Device\Ide\IdePort0 84A771F8
Device \Driver\atapi \Device\Ide\IdePort1 84A771F8
Device \Driver\atapi \Device\Ide\IdePort2 84A771F8
Device \Driver\atapi \Device\Ide\IdePort3 84A771F8
Device \Driver\atapi \Device\Ide\IdePort4 84A771F8
Device \Driver\atapi \Device\Ide\IdePort5 84A771F8
Device \Driver\atapi \Device\Ide\IdePort6 84A771F8
Device \Driver\msahci \Device\Ide\PciIde2Channel0 84A781F8
Device \Driver\msahci \Device\Ide\PciIde2Channel1 84A781F8
Device \Driver\msahci \Device\Ide\PciIde2Channel2 84A781F8
Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-8 84A771F8
Device \Driver\volmgr \Device\HarddiskVolume3 84A741F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\USBSTOR \Device\00000073 875C3470
Device \Driver\USBSTOR \Device\00000074 875C3470
Device \Driver\volmgr \Device\HarddiskVolume4 84A741F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\USBSTOR \Device\00000075 875C3470
Device \Driver\USBSTOR \Device\00000076 875C3470
Device \Driver\NetBT \Device\NetBt_Wins_Export 85CA11F8
Device \Driver\ACPI_HAL \Device\0000004a halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000079 bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000079 bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{27852BB0-8506-48DE-8F8C-576D817DB8C3} 85CA11F8
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device \Driver\usbuhci \Device\USBFDO-0 85DF71F8
Device \Driver\usbuhci \Device\USBFDO-1 85DF71F8
Device \Driver\BTHUSB \Device\0000007b bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device \Driver\BTHUSB \Device\0000007b bthport.sys (Bluetooth-Bustreiber/Microsoft Corporation)
Device \Driver\usbehci \Device\USBFDO-2 85CF5470
Device \Driver\usbuhci \Device\USBFDO-3 85DF71F8
Device \Driver\usbuhci \Device\USBFDO-4 85DF71F8
Device \Driver\usbuhci \Device\USBFDO-5 85DF71F8
Device \Driver\sptd \Device\1629280029 spsl.sys
Device \Driver\usbehci \Device\USBFDO-6 85CF5470
Device \Driver\awk0y679 \Device\Scsi\awk0y6791 85BCF1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FB401F87-E611-43F1-B357-3C66150271EF} 85CA11F8
Device \FileSystem\fastfat \Fat 85D25470
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001060d10d32
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x96 0x4D 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4D 0xA1 0xD5 0x20 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC9 0x85 0x60 0x55 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x88 0x20 0xA1 0xF0 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0xAF 0x5E 0xD9 0x82 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001060d10d32 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x96 0x4D 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4D 0xA1 0xD5 0x20 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC9 0x85 0x60 0x55 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x88 0x20 0xA1 0xF0 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0xAF 0x5E 0xD9 0x82 ...
---- Files - GMER 1.0.15 ----
File C:\## aswSnx private storage 0 bytes
File C:\## aswSnx private storage\snx_rhive 262144 bytes
File C:\## aswSnx private storage\snx_rhive.LOG1 5120 bytes
File C:\## aswSnx private storage\snx_rhive.LOG2 0 bytes
File C:\## aswSnx private storage\snx_rhive{3208742a-5eef-11e0-8eb0-001060d10d32}.TM.blf 65536 bytes
File C:\## aswSnx private storage\snx_rhive{3208742a-5eef-11e0-8eb0-001060d10d32}.TMContainer00000000000000000001.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\snx_rhive{3208742a-5eef-11e0-8eb0-001060d10d32}.TMContainer00000000000000000002.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\webStorage 0 bytes
File C:\## aswSnx private storage\webStorage\attrib 0 bytes
File C:\## aswSnx private storage\webStorage\image 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Prefetch 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Prefetch\CONHOST.EXE-3218E401.pf 11514 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Prefetch\IEXPLORE.EXE-BC8A94AF.pf 32968 bytes
File C:\## aswSnx private storage\webStorage\snx_fs.dat 612 bytes
---- EOF - GMER 1.0.15 ---- OSAM Log: Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:18:26 on 05.04.2011
OS: Windows 7 Ultimate Edition (Build 7600), 32-bit
Default Browser: Mozilla Corporation Firefox 3.5.18
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"PhysX.cpl" - "NVIDIA Corporation" - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AnyDVD" (AnyDVD) - ? - C:\Windows\System32\Drivers\AnyDVD.sys (File not found)
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\Windows\system32\drivers\aswFsBlk.sys
"aswMonFlt" (aswMonFlt) - "AVAST Software" - C:\Windows\system32\drivers\aswMonFlt.sys
"aswRdr" (aswRdr) - "AVAST Software" - C:\Windows\system32\drivers\aswRdr.sys
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys
"aswSP" (aswSP) - "AVAST Software" - C:\Windows\system32\drivers\aswSP.sys
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\Windows\system32\drivers\aswTdi.sys
"awk0y679" (awk0y679) - "Advanced Micro Devices" - C:\Windows\system32\drivers\awk0y679.sys (Hidden registry entry, rootkit activity | File signed by Microsoft)
"catchme" (catchme) - ? - C:\Users\Vee\AppData\Local\Temp\catchme.sys (File not found)
"Dynamically loaded UxdDrv" (uxddrv) - ? - d:\DIAGNOSE\WSTGER32\2PART\uxddrv86.sys (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - ? - C:\Windows\System32\Drivers\ElbyCDIO.sys (File not found)
"pfldypow" (pfldypow) - ? - C:\Users\Vee\AppData\Local\Temp\pfldypow.sys (Hidden registry entry, rootkit activity | File not found)
"sptd" (sptd) - "Duplex Secure Ltd." - C:\Windows\System32\Drivers\sptd.sys (File is exclusively opened, access blocked)
[Explorer]
-----( HKCU\Software\Classes\Folder\shellex\ColumnHandlers )-----
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Program Files\Alwil Software\Avast5\ashShell.dll
{A70C977A-BF00-412C-90B7-034C51DA2439} "DesktopContext Class" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} "NVIDIA CPL Context Menu Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvshext.dll
{FFB699E0-306A-11d3-8BD1-00104B6F7516} "NVIDIA CPL Extension" - "NVIDIA Corporation" - C:\Windows\system32\nvcpl.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - (File not found | COM-object registry key not found)
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - (File not found | COM-object registry key not found)
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - (File not found | COM-object registry key not found)
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - (File not found | COM-object registry key not found)
{52B87208-9CCF-42C9-B88E-069281105805} "Trojan Remover Shell Extension" - ? - (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_16" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} "Java Plug-in 1.6.0_16" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_16" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_16.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10d.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{30F9B915-B755-4826-820B-08FBA6BD249D} "{30F9B915-B755-4826-820B-08FBA6BD249D}" - ? - (File not found | COM-object registry key not found)
{c2db4fe6-8409-45ce-8010-189a7b5cce86} "{c2db4fe6-8409-45ce-8010-189a7b5cce86}" - ? - (File not found | COM-object registry key not found)
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Vee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"OpenOffice.org 3.1.lnk" - ? - C:\Users\Vee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk (Shortcut exists | File not found)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"DAEMON Tools Pro Agent" - "DT Soft Ltd" - "C:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"avast5" - "AVAST Software" - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Java\jre6\bin\jusched.exe"
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"NVIDIA Display Driver Service" (nvsvc) - "NVIDIA Corporation" - C:\Windows\system32\nvvsvc.exe
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru MBR Log: Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Notebook
BIOS Manufacturer: Phoenix Technologies LTD
System Manufacturer: Notebook
System Product Name: MIM2280
Logical Drives Mask: 0x00000074
Kernel Drivers (total 174):
0x82A3E000 \SystemRoot\system32\ntkrnlpa.exe
0x82A07000 \SystemRoot\system32\halmacpi.dll
0x80BAD000 \SystemRoot\system32\kdcom.dll
0x88810000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x88888000 \SystemRoot\system32\PSHED.dll
0x88899000 \SystemRoot\system32\BOOTVID.dll
0x888A1000 \SystemRoot\system32\CLFS.SYS
0x888E3000 \SystemRoot\system32\CI.dll
0x8898E000 \SystemRoot\system32\drivers\Wdf01000.sys
0x88800000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x88A19000 \SystemRoot\System32\Drivers\spsl.sys
0x88B12000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x88B1B000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x88B41000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x88B89000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x88B91000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x88B9C000 \SystemRoot\system32\DRIVERS\pci.sys
0x88BC6000 \SystemRoot\System32\drivers\partmgr.sys
0x88BD7000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x88BDF000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x88BEA000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x88C0E000 \SystemRoot\System32\drivers\volmgrx.sys
0x88C59000 \SystemRoot\system32\DRIVERS\intelide.sys
0x88C60000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x88C6E000 \SystemRoot\system32\DRIVERS\pciide.sys
0x88C75000 \SystemRoot\System32\drivers\mountmgr.sys
0x88C8B000 \SystemRoot\system32\DRIVERS\atapi.sys
0x88C94000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x88CB7000 \SystemRoot\system32\DRIVERS\msahci.sys
0x88CC1000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x88CCA000 \SystemRoot\system32\drivers\fltmgr.sys
0x88CFE000 \SystemRoot\system32\drivers\fileinfo.sys
0x88E25000 \SystemRoot\System32\Drivers\Ntfs.sys
0x88F54000 \SystemRoot\System32\Drivers\msrpc.sys
0x88F7F000 \SystemRoot\System32\Drivers\ksecdd.sys
0x88F92000 \SystemRoot\System32\Drivers\cng.sys
0x88FEF000 \SystemRoot\System32\drivers\pcw.sys
0x88E00000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x88D0F000 \SystemRoot\system32\drivers\ndis.sys
0x89013000 \SystemRoot\system32\drivers\NETIO.SYS
0x89051000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x89076000 \SystemRoot\System32\drivers\tcpip.sys
0x891BF000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x891F0000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x89234000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x89273000 \SystemRoot\System32\Drivers\spldr.sys
0x8927B000 \SystemRoot\System32\drivers\rdyboost.sys
0x892A8000 \SystemRoot\System32\Drivers\mup.sys
0x892B8000 \SystemRoot\System32\drivers\hwpolicy.sys
0x892C0000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x892F2000 \SystemRoot\system32\DRIVERS\disk.sys
0x89303000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8935B000 \SystemRoot\System32\Drivers\awk0y679.SYS
0x89393000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8DC3A000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x8DC98000 \SystemRoot\System32\Drivers\Null.SYS
0x8DC9F000 \SystemRoot\System32\Drivers\Beep.SYS
0x8DCA6000 \SystemRoot\System32\drivers\vga.sys
0x8DCB2000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8DCD3000 \SystemRoot\System32\drivers\watchdog.sys
0x8DCE0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8DCE8000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8DCF0000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8DCF8000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8DD03000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8DD11000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8DD28000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8DD33000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x8DD3D000 \SystemRoot\system32\drivers\afd.sys
0x8DD97000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x8DD9C000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8DDCE000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8DDD5000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8DC00000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8DC0E000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8DC21000 \SystemRoot\system32\DRIVERS\termdd.sys
0x893B2000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8DDF4000 \SystemRoot\system32\drivers\nsiproxy.sys
0x893F3000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x89200000 \SystemRoot\System32\drivers\discache.sys
0x8EA06000 \SystemRoot\system32\drivers\csc.sys
0x8EA6A000 \SystemRoot\System32\Drivers\dfsc.sys
0x8EA82000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x8EA90000 \SystemRoot\System32\Drivers\aswSP.SYS
0x8EAD8000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8EAF9000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8F207000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8FD01000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x8FD03000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8FDBA000 \SystemRoot\System32\drivers\dxgmms1.sys
0x8EB0B000 \SystemRoot\System32\Drivers\fastfat.SYS
0x8FDF3000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8EB35000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8EB80000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8EB8F000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x90608000 \SystemRoot\system32\DRIVERS\netw5v32.sys
0x90A1B000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x90A40000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x90A58000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x90A65000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x90A72000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x90A76000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x90A83000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x90A95000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x90AAD000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x90AB8000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x90ADA000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x90AF2000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x90B09000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x90B20000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x90B2A000 \SystemRoot\system32\DRIVERS\swenum.sys
0x90B2C000 \SystemRoot\system32\DRIVERS\ks.sys
0x90B60000 \SystemRoot\system32\DRIVERS\umbus.sys
0x90B6E000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x90BB2000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8EBAE000 \SystemRoot\system32\drivers\HdAudio.sys
0x90BC3000 \SystemRoot\system32\drivers\portcls.sys
0x8920C000 \SystemRoot\system32\drivers\drmk.sys
0x93E03000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x93F09000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x93F0B000 \SystemRoot\system32\drivers\modem.sys
0x95CC0000 \SystemRoot\System32\win32k.sys
0x93F18000 \SystemRoot\System32\drivers\Dxapi.sys
0x93F22000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x93F39000 \SystemRoot\System32\Drivers\crashdmp.sys
0x93F46000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x93F51000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x93F5B000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x93F6C000 \SystemRoot\system32\DRIVERS\monitor.sys
0x95F20000 \SystemRoot\System32\TSDDD.dll
0x95F50000 \SystemRoot\System32\cdd.dll
0x93F77000 \SystemRoot\system32\DRIVERS\usbgene.sys
0x93F98000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0x93FA6000 \SystemRoot\system32\DRIVERS\USBCAMD2.SYS
0x93FAD000 \SystemRoot\system32\DRIVERS\USBGENE0.SYS
0x81E1C000 \SystemRoot\system32\DRIVERS\USBGENE1.SYS
0x81E9A000 \SystemRoot\system32\DRIVERS\USBGENE2.SYS
0x81EBC000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x81ECE000 \SystemRoot\System32\Drivers\bthport.sys
0x81F32000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x81F56000 \SystemRoot\system32\DRIVERS\BthEnum.sys
0x81F63000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x81F7E000 \SystemRoot\system32\drivers\luafv.sys
0x81F99000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x81FD1000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x81FD4000 \SystemRoot\system32\drivers\WudfPf.sys
0x81FEE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x8EC1C000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8EC62000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x8EC72000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8EC85000 \SystemRoot\system32\drivers\HTTP.sys
0x8ED0A000 \SystemRoot\system32\DRIVERS\bowser.sys
0x8ED23000 \SystemRoot\System32\drivers\mpsdrv.sys
0x8ED35000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x8ED58000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x8ED93000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9DE0C000 \SystemRoot\system32\drivers\peauth.sys
0x9DEA3000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9DEAD000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9DECE000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9DEDB000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9DF2A000 \SystemRoot\System32\DRIVERS\srv.sys
0x9DF7B000 \??\C:\Users\Vee\AppData\Local\Temp\pfldypow.sys
0x77AE0000 \Windows\System32\ntdll.dll
0x47E00000 \Windows\System32\smss.exe
0x77D20000 \Windows\System32\apisetschema.dll
0x00F20000 \Windows\System32\autochk.exe
0x77CE0000 \Windows\System32\imagehlp.dll
0x77C80000 \Windows\System32\difxapi.dll
0x77A60000 \Windows\System32\comdlg32.dll
0x77C70000 \Windows\System32\psapi.dll
0x77C50000 \Windows\System32\imm32.dll
0x77860000 \Windows\System32\iertutil.dll
0x77700000 \Windows\System32\ole32.dll
Processes (total 41):
0 System Idle Process
4 System
308 C:\Windows\System32\smss.exe
396 csrss.exe
448 C:\Windows\System32\wininit.exe
468 csrss.exe
516 C:\Windows\System32\services.exe
524 C:\Windows\System32\lsass.exe
536 C:\Windows\System32\lsm.exe
608 C:\Windows\System32\winlogon.exe
692 C:\Windows\System32\svchost.exe
768 C:\Windows\System32\nvvsvc.exe
808 C:\Windows\System32\svchost.exe
864 C:\Windows\System32\svchost.exe
940 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1136 C:\Windows\System32\svchost.exe
1240 C:\Windows\System32\nvvsvc.exe
1264 C:\Windows\System32\svchost.exe
1404 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
1532 C:\Windows\System32\dwm.exe
1556 C:\Windows\explorer.exe
1712 C:\Program Files\Java\jre6\bin\jusched.exe
1780 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
1892 C:\Program Files\iTunes\iTunesHelper.exe
2036 C:\Windows\System32\spoolsv.exe
460 C:\Windows\System32\svchost.exe
360 C:\Windows\System32\taskhost.exe
1972 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
148 C:\Program Files\Bonjour\mDNSResponder.exe
2196 C:\Windows\System32\svchost.exe
2820 C:\Windows\System32\SearchIndexer.exe
2876 C:\Program Files\iPod\bin\iPodService.exe
2928 C:\Windows\System32\svchost.exe
2996 C:\Windows\System32\svchost.exe
3052 C:\Windows\System32\svchost.exe
3848 C:\Windows\System32\svchost.exe
1672 C:\Windows\System32\audiodg.exe
380 C:\Users\Vee\Desktop\MBRCheck.exe
1884 C:\Windows\System32\conhost.exe
3824 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000033`72f7e000 (FAT32)
PhysicalDrive0 Model Number: WDCWD2500BEVS-22UST0, Rev: 01.01A01
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done! |