Schnupsi | 27.01.2011 14:26 | Soooo....
Gmer Code:
GMER 1.0.15.15530 - hxxp://www.gmer.net
Rootkit scan 2011-01-27 14:15:28
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160815AS rev.4.AAB
Running: shrje9o2.exe; Driver: C:\Users\Spirit\AppData\Local\Temp\pgryqpob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C80599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CA4F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\Drivers\spol.sys Das System kann den angegebenen Pfad nicht finden. !
PAGE ataport.SYS!DllUnload + 1 8AEA7AD7 4 Bytes JMP 854971D9
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x90C2B000, 0x267978, 0xE8000020]
.text USBPORT.SYS!DllUnload 91456CA0 5 Bytes JMP 865924E0
.text a1vq0k3e.SYS 914CE000 12 Bytes [44, B8, C0, 82, EE, B6, C0, ...]
.text a1vq0k3e.SYS 914CE00D 9 Bytes [97, C0, 82, 48, BB, C0, 82, ...]
.text a1vq0k3e.SYS 914CE017 170 Bytes [00, DE, 27, D2, 8A, E6, 25, ...]
.text a1vq0k3e.SYS 914CE0C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text a1vq0k3e.SYS 914CE0CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text D:\Programme\ESET\Smart Security\ekrn.exe[2556] kernel32.dll!SetUnhandledExceptionFilter 75993162 4 Bytes [C2, 04, 00, 00]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8AC26042] \SystemRoot\System32\Drivers\spol.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8AC266D6] \SystemRoot\System32\Drivers\spol.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8AC26800] \SystemRoot\System32\Drivers\spol.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8AC2613E] \SystemRoot\System32\Drivers\spol.sys
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortNotification] 00147880
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortQuerySystemTime] 78800C75
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortReadPortUchar] 06750015
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortStallExecution] C25DC033
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortWritePortUchar] 458B0008
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortWritePortUlong] 6A006A08
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 50056A24
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 005AB7E8
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortGetScatterGatherList] 0001B800
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortGetParentBusType] C25D0000
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortRequestCallback] CCCC0008
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortWritePortBufferUshort] CCCCCCCC
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortGetUnCachedExtension] CCCCCCCC
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortCompleteRequest] CCCCCCCC
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortCopyMemory] 53EC8B55
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortEtwTraceLog] 800C5D8B
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 7500117B
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 127B806A
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 80647500
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7500137B
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortInitialize] 157B805E
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortGetDeviceBase] 56587500
IAT \SystemRoot\System32\Drivers\a1vq0k3e.SYS[ataport.SYS!AtaPortDeviceStateChange] 8008758B
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8549D1F8
Device \Driver\volmgr \Device\VolMgrControl 854991F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{A2D2733D-A666-4CAE-A21D-38F83BFA0264} 864D51F8
Device \Driver\usbohci \Device\USBPDO-0 865A91F8
Device \Driver\usbohci \Device\USBPDO-1 865A91F8
Device \Driver\usbohci \Device\USBPDO-2 865A91F8
Device \Driver\usbohci \Device\USBPDO-3 865A91F8
Device \Driver\usbohci \Device\USBPDO-4 865A91F8
Device \Driver\usbehci \Device\USBPDO-5 865A8500
Device \Driver\PCI_PNP1003 \Device\00000062 spol.sys
Device \Driver\volmgr \Device\HarddiskVolume1 854991F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\volmgr \Device\HarddiskVolume2 854991F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 863A21F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8549B1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3 8549B1F8
Device \Driver\atapi \Device\Ide\IdePort0 8549B1F8
Device \Driver\atapi \Device\Ide\IdePort1 8549B1F8
Device \Driver\atapi \Device\Ide\IdePort2 8549B1F8
Device \Driver\atapi \Device\Ide\IdePort3 8549B1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-6 8549B1F8
Device \Driver\cdrom \Device\CdRom1 863A21F8
Device \Driver\cdrom \Device\CdRom2 863A21F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 864D51F8
Device \Driver\ACPI_HAL \Device\0000005b halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\sptd \Device\1037387005 spol.sys
Device \Driver\usbohci \Device\USBFDO-0 865A91F8
Device \Driver\usbohci \Device\USBFDO-1 865A91F8
Device \Driver\usbohci \Device\USBFDO-2 865A91F8
Device \Driver\usbohci \Device\USBFDO-3 865A91F8
Device \Driver\usbohci \Device\USBFDO-4 865A91F8
Device \Driver\usbehci \Device\USBFDO-5 865A8500
Device \Driver\a1vq0k3e \Device\Scsi\a1vq0k3e1Port4Path0Target0Lun0 8663F500
Device \Driver\a1vq0k3e \Device\Scsi\a1vq0k3e1 8663F500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xDE 0x33 0x93 0x39 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD2 0xA0 0x5B 0x91 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3D 0x11 0x29 0x0F ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Programme\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xDE 0x33 0x93 0x39 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD2 0xA0 0x5B 0x91 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3D 0x11 0x29 0x0F ...
---- EOF - GMER 1.0.15 ----
OSAM Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 14:20:38 on 27.01.2011
OS: Windows 7 Ultimate Edition (Build 7600), 32-bit
Default Browser: Mozilla Corporation Firefox 3.6.13
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"a1vq0k3e" (a1vq0k3e) - "Microsoft Corporation" - C:\Windows\system32\drivers\a1vq0k3e.sys (Hidden registry entry, rootkit activity | File signed by Microsoft)
"Apple Mobile USB Driver" (USBAAPL) - "Apple, Inc." - C:\Windows\System32\Drivers\usbaapl.sys
"ASPI32" (ASPI32) - ? - C:\Windows\system32\drivers\ASPI32.sys (File not found)
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys
"catchme" (catchme) - ? - C:\Users\Spirit\AppData\Local\Temp\catchme.sys (File not found)
"CFcatchme" (CFcatchme) - ? - C:\Users\Spirit\AppData\Local\Temp\CFcatchme.sys (File not found)
"dgderdrv" (dgderdrv) - "Devguru Co., Ltd" - C:\Windows\System32\drivers\dgderdrv.sys
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys (File not found)
"FsUsbExDisk" (FsUsbExDisk) - ? - C:\Windows\system32\FsUsbExDisk.SYS (File found, but it contains no detailed information)
"pgryqpob" (pgryqpob) - ? - C:\Users\Spirit\AppData\Local\Temp\pgryqpob.sys (Hidden registry entry, rootkit activity | File not found)
"sptd" (sptd) - "Duplex Secure Ltd." - C:\Windows\System32\Drivers\sptd.sys (File is exclusively opened, access blocked)
[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler )-----
{E31004D1-A431-41B8-826F-E902F9D95C81} "Windows DreamScene" - "Microsoft Corporation" - C:\Windows\System32\DreamScene.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{B089FE88-FB52-11D3-BDF1-0050DA34150D} "ESET Smart Security - Context Menu Shell Extension" - "ESET" - D:\Programme\ESET\Smart Security\shellExt.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
{ACBA0BA3-ACED-4E02-9221-794F7588DD9C} "MP3Ext Class" - "TODO: <Company name>" - D:\Programme\All To MP3 Converter\MP3ShellExt.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - D:\Programme\OpenOffice\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? - (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? - (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_22.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" - "Adobe Systems, Inc." - C:\Windows\system32\Macromed\Flash\Flash10e.ocx / hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "@C:\Windows\WindowsMobile\INetRepl.dll,-222" - "Microsoft Corporation" - C:\Windows\WindowsMobile\INetRepl.dll
{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} "ClsidExtension" - "Microsoft Corporation" - C:\Windows\WindowsMobile\INetRepl.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{593DDEC6-7468-4cdd-90E1-42DADAA222E9} "DivX HiQ" - "DivX, LLC" - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live Anmelde-Hilfsprogramm" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Spirit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"egui" - "ESET" - "D:\Programme\ESET\Smart Security\egui.exe" /hide /waitservice
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Akamai NetSession Interface" (Akamai) - ? - c:\program files\common files\akamai\netsession_win_dbc0250.dll (File found, but it contains no detailed information)
"Ati External Event Utility" (Ati External Event Utility) - ? - C:\Windows\system32\Ati2evxx.exe (File not found)
"Device Error Recovery Service" (dgdersvc) - "Devguru Co., Ltd." - C:\Windows\system32\dgdersvc.exe
"ESET HTTP Server" (EhttpSrv) - "ESET" - D:\Programme\ESET\Smart Security\EHttpSrv.exe
"ESET Service" (ekrn) - "ESET" - D:\Programme\ESET\Smart Security\ekrn.exe
"FsUsbExService" (FsUsbExService) - "Teruten" - C:\Windows\system32\FsUsbExService.Exe
"nProtect GameGuard Service" (npggsvc) - "INCA Internet Co., Ltd." - C:\Windows\system32\GameMon.des
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe (File found, but it contains no detailed information)
"TeamViewer 6" (TeamViewer6) - "TeamViewer GmbH" - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
"Winstep Xtreme Service" (Winstep Xtreme Service) - "Winstep Software Technologies" - D:\Programme\Winstep\WsxService.exe
[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - ? - none (File not found)
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
MBRCheck Code:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: FOXCONN
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: FOXCONN
System Product Name: A6VMX
Logical Drives Mask: 0x0000007c
Kernel Drivers (total 200):
0x82C3D000 \SystemRoot\system32\ntkrnlpa.exe
0x82C06000 \SystemRoot\system32\halmacpi.dll
0x80BD4000 \SystemRoot\system32\kdcom.dll
0x8323B000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x83246000 \SystemRoot\system32\PSHED.dll
0x83257000 \SystemRoot\system32\BOOTVID.dll
0x8325F000 \SystemRoot\system32\CLFS.SYS
0x832A1000 \SystemRoot\system32\CI.dll
0x8334C000 \SystemRoot\system32\drivers\Wdf01000.sys
0x833BD000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8AC24000 \SystemRoot\System32\Drivers\spol.sys
0x8AD17000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8AD20000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x8AD46000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8AD8E000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8AD96000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x8ADA1000 \SystemRoot\system32\DRIVERS\pci.sys
0x8ADCB000 \SystemRoot\System32\drivers\partmgr.sys
0x8ADDC000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8ADE4000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8ADEF000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x8AE13000 \SystemRoot\System32\drivers\volmgrx.sys
0x8AE5E000 \SystemRoot\system32\DRIVERS\pciide.sys
0x8AE65000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8AE73000 \SystemRoot\System32\drivers\mountmgr.sys
0x8AE89000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8AE92000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x8AEB5000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8AEBE000 \SystemRoot\system32\drivers\fltmgr.sys
0x8AEF2000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B018000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B147000 \SystemRoot\System32\Drivers\msrpc.sys
0x8B172000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B185000 \SystemRoot\System32\Drivers\cng.sys
0x8B1E2000 \SystemRoot\System32\drivers\pcw.sys
0x8B1F0000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8AF03000 \SystemRoot\system32\drivers\ndis.sys
0x8AFBA000 \SystemRoot\system32\drivers\NETIO.SYS
0x833CB000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8B221000 \SystemRoot\System32\drivers\tcpip.sys
0x8B36A000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B39B000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8B3A4000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8B3E3000 \SystemRoot\System32\Drivers\spldr.sys
0x83200000 \SystemRoot\System32\drivers\rdyboost.sys
0x8B3EB000 \SystemRoot\System32\Drivers\mup.sys
0x8B200000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8B435000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8B467000 \SystemRoot\system32\DRIVERS\disk.sys
0x8B478000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8B4CF000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8B54A000 \SystemRoot\System32\Drivers\Null.SYS
0x8B551000 \SystemRoot\System32\Drivers\Beep.SYS
0x8B558000 \SystemRoot\system32\DRIVERS\ehdrv.sys
0x8B577000 \SystemRoot\System32\drivers\vga.sys
0x8B583000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8B5A4000 \SystemRoot\System32\drivers\watchdog.sys
0x8B5B1000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8B5B9000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8B5C1000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8B5C9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8B5D4000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8B5E2000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8B400000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8B4EE000 \SystemRoot\system32\drivers\afd.sys
0x90224000 \SystemRoot\System32\DRIVERS\netbt.sys
0x90256000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x9025D000 \SystemRoot\system32\DRIVERS\pacer.sys
0x9027C000 \SystemRoot\system32\DRIVERS\netbios.sys
0x9028A000 \SystemRoot\system32\DRIVERS\serial.sys
0x902A4000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x902B7000 \SystemRoot\system32\DRIVERS\termdd.sys
0x902C7000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90308000 \SystemRoot\system32\drivers\nsiproxy.sys
0x90312000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x9031C000 \SystemRoot\System32\drivers\discache.sys
0x90328000 \SystemRoot\system32\drivers\csc.sys
0x9038C000 \SystemRoot\System32\Drivers\dfsc.sys
0x903A4000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x903B2000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x903D3000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x90C2A000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x910BB000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x91172000 \SystemRoot\System32\drivers\dxgmms1.sys
0x911AB000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x911D0000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x91432000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x9147D000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x9148C000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x914AB000 \SystemRoot\system32\DRIVERS\serenum.sys
0x914B5000 \SystemRoot\system32\DRIVERS\parport.sys
0x914CD000 \SystemRoot\System32\Drivers\a1vq0k3e.SYS
0x91506000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x9151E000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x91530000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x91548000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x91553000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x91575000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x9158D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x915A4000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x915BB000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x915C5000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x915D2000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x915DF000 \SystemRoot\system32\DRIVERS\swenum.sys
0x95012000 \SystemRoot\system32\DRIVERS\ks.sys
0x95046000 \SystemRoot\system32\DRIVERS\umbus.sys
0x95054000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x95098000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x950A9000 \SystemRoot\system32\drivers\HdAudio.sys
0x950F9000 \SystemRoot\system32\drivers\portcls.sys
0x95128000 \SystemRoot\system32\drivers\drmk.sys
0x96C90000 \SystemRoot\System32\win32k.sys
0x95141000 \SystemRoot\System32\drivers\Dxapi.sys
0x9514B000 \SystemRoot\System32\Drivers\crashdmp.sys
0x95158000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x95163000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x9516C000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x9517D000 \SystemRoot\system32\DRIVERS\monitor.sys
0x96EF0000 \SystemRoot\System32\TSDDD.dll
0x96F20000 \SystemRoot\System32\cdd.dll
0x95188000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x9519F000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x951A1000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x951AC000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x951BF000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x951C6000 \SystemRoot\system32\DRIVERS\KMWDFILTER.sys
0x951CF000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x951DB000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x915E1000 \SystemRoot\system32\drivers\luafv.sys
0x8201F000 \SystemRoot\system32\DRIVERS\eamonm.sys
0x820C5000 \SystemRoot\system32\drivers\WudfPf.sys
0x820DF000 \SystemRoot\system32\DRIVERS\epfw.sys
0x82101000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x82111000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x82157000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x82167000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8217A000 \SystemRoot\system32\drivers\HTTP.sys
0x82000000 \SystemRoot\system32\DRIVERS\bowser.sys
0x951E6000 \SystemRoot\System32\drivers\mpsdrv.sys
0x91400000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9C224000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9C25F000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9C27A000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x9C28F000 \SystemRoot\system32\drivers\peauth.sys
0x9C326000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9C330000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9C351000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9C35E000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9C3AD000 \SystemRoot\System32\DRIVERS\srv.sys
0x98896000 \SystemRoot\System32\drivers\rdpdr.sys
0x988BB000 \SystemRoot\system32\drivers\tdtcp.sys
0x988C5000 \SystemRoot\System32\DRIVERS\tssecsrv.sys
0x988D2000 \SystemRoot\System32\Drivers\RDPWD.SYS
0x98903000 \??\C:\Windows\system32\FsUsbExDisk.SYS
0x9890C000 \SystemRoot\System32\drivers\dgderdrv.sys
0x9890F000 \SystemRoot\System32\Drivers\ov519vid.sys
0x98938000 \SystemRoot\System32\Drivers\STREAM.SYS
0x98946000 \SystemRoot\System32\Drivers\ov519cmd.sys
0x9894C000 \SystemRoot\system32\drivers\usbaudio.sys
0x98960000 \??\C:\Users\Spirit\AppData\Local\Temp\pgryqpob.sys
0x771E0000 \Windows\System32\ntdll.dll
0x48560000 \Windows\System32\smss.exe
0x77420000 \Windows\System32\apisetschema.dll
0x10000000 \Programme\DAEMON Tools Lite\Engine.dll
0x00FD0000 \Windows\System32\autochk.exe
0x770A0000 \Windows\System32\urlmon.dll
0x77400000 \Windows\System32\psapi.dll
0x773F0000 \Windows\System32\nsi.dll
0x77340000 \Windows\System32\msvcrt.dll
0x77320000 \Windows\System32\imm32.dll
0x76F00000 \Windows\System32\setupapi.dll
0x76E00000 \Windows\System32\wininet.dll
0x76CA0000 \Windows\System32\ole32.dll
0x76C50000 \Windows\System32\gdi32.dll
0x76C00000 \Windows\System32\Wldap32.dll
0x76B80000 \Windows\System32\comdlg32.dll
0x76980000 \Windows\System32\iertutil.dll
0x76940000 \Windows\System32\ws2_32.dll
0x76870000 \Windows\System32\msctf.dll
0x76810000 \Windows\System32\shlwapi.dll
0x75BC0000 \Windows\System32\shell32.dll
0x75BB0000 \Windows\System32\normaliz.dll
0x75B10000 \Windows\System32\usp10.dll
0x75AE0000 \Windows\System32\imagehlp.dll
0x75AC0000 \Windows\System32\sechost.dll
0x75A30000 \Windows\System32\oleaut32.dll
0x75A20000 \Windows\System32\lpk.dll
0x75940000 \Windows\System32\kernel32.dll
0x758A0000 \Windows\System32\advapi32.dll
0x75840000 \Windows\System32\difxapi.dll
0x757B0000 \Windows\System32\clbcatq.dll
0x75700000 \Windows\System32\rpcrt4.dll
0x75630000 \Windows\System32\user32.dll
0x755E0000 \Windows\System32\KernelBase.dll
0x755B0000 \Windows\System32\wintrust.dll
0x75590000 \Windows\System32\devobj.dll
0x75470000 \Windows\System32\crypt32.dll
0x753E0000 \Windows\System32\comctl32.dll
0x753B0000 \Windows\System32\cfgmgr32.dll
0x753A0000 \Windows\System32\msasn1.dll
Processes (total 38):
0 System Idle Process
4 SYSTEM
244 C:\Windows\System32\smss.exe
340 csrss.exe
416 C:\Windows\System32\wininit.exe
424 csrss.exe
480 C:\Windows\System32\winlogon.exe
508 C:\Windows\System32\services.exe
528 C:\Windows\System32\lsass.exe
536 C:\Windows\System32\lsm.exe
648 C:\Windows\System32\svchost.exe
708 C:\Windows\System32\svchost.exe
756 C:\Windows\System32\svchost.exe
832 C:\Windows\System32\svchost.exe
868 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\svchost.exe
1204 C:\Windows\System32\svchost.exe
1336 C:\Windows\System32\spoolsv.exe
1372 C:\Windows\System32\svchost.exe
1476 C:\Windows\System32\taskhost.exe
1576 C:\Windows\System32\svchost.exe
1584 C:\Windows\System32\dwm.exe
1604 C:\Windows\explorer.exe
1660 C:\Windows\System32\dgdersvc.exe
2024 C:\Windows\System32\svchost.exe
100 C:\Windows\System32\FsUsbExService.Exe
288 C:\Windows\System32\PnkBstrA.exe
1116 C:\Windows\System32\svchost.exe
2680 C:\Windows\System32\svchost.exe
2852 C:\Program Files\Windows Media Player\wmpnetwk.exe
3428 C:\Windows\System32\svchost.exe
3160 C:\Windows\System32\svchost.exe
2556 D:\Programme\ESET\Smart Security\ekrn.exe
1976 C:\Windows\System32\audiodg.exe
3016 C:\Program Files\Mozilla Firefox\firefox.exe
1568 C:\Users\Spirit\Desktop\MBRCheck.exe
2096 C:\Windows\System32\conhost.exe
2896 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000007`52c65e00 (NTFS)
PhysicalDrive0 Model Number: ST3160815AS, Rev: 4.AAB
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
Nur so aus Neugier, sind wir denn bald durch? :) |