Gmer_First Log:
Gmer Log:Code:GMER 1.0.15.15281 - http://www.gmer.net Rootkit quick scan 2010-08-17 19:40:24 Windows 6.0.6002 Service Pack 2 Running: w8qrjbxq.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\pxlyqpob.sys ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs PGPfsfd.sys (PGP FSFD/PGP Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) Device -> \Driver\iaStor \Device\Harddisk0\DR0 84E7AEC5 ---- Files - GMER 1.0.15 ---- File C:\Windows\system32\drivers\iaStor.sys suspicious modification ---- EOF - GMER 1.0.15 ----
MBRCheck Log:Code:GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-08-17 20:38:58 Windows 6.0.6002 Service Pack 2 Running: w8qrjbxq.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\pxlyqpob.sys ---- Kernel code sections - GMER 1.0.15 ---- .rsrc C:\Windows\system32\drivers\ndis.sys entry point in ".rsrc" section [0x86577014] ---- User code sections - GMER 1.0.15 ---- .text C:\Windows\system32\svchost.exe[932] ntdll.dll!NtProtectVirtualMemory 76E24D34 5 Bytes JMP 0070000A .text C:\Windows\system32\svchost.exe[932] ntdll.dll!NtWriteVirtualMemory 76E25674 5 Bytes JMP 0071000A .text C:\Windows\system32\svchost.exe[932] ntdll.dll!KiUserExceptionDispatcher 76E25DC8 5 Bytes JMP 006F000A .text C:\Windows\system32\svchost.exe[932] ole32.dll!CoCreateInstance 76849EA6 5 Bytes JMP 00EC000A .text C:\Windows\Explorer.EXE[1576] ntdll.dll!NtProtectVirtualMemory 76E24D34 5 Bytes JMP 007E000A .text C:\Windows\Explorer.EXE[1576] ntdll.dll!NtWriteVirtualMemory 76E25674 5 Bytes JMP 007F000A .text C:\Windows\Explorer.EXE[1576] ntdll.dll!KiUserExceptionDispatcher 76E25DC8 5 Bytes JMP 007D000A ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73E07817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73E5A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73E0BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73DFF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73E075E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73DFE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73E38395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73E0DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73DFFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73DFFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73DF71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73E8CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73E2C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73DFD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73DF6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73DF687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1576] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73E02AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs PGPfsfd.sys (PGP FSFD/PGP Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) Device -> \Driver\iaStor \Device\Harddisk0\DR0 84E7AEC5 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016411f4ab6 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001a6b884a5e Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x82 0x69 0x4B 0xAB ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x06 0x04 0x01 0xF3 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x89 0x8C 0xFB 0xD5 ... Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0016411f4ab6 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001a6b884a5e (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x82 0x69 0x4B 0xAB ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x06 0x04 0x01 0xF3 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x89 0x8C 0xFB 0xD5 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib@Last Counter 200118 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib@Last Help 200119 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost@netsvc SPService? Reg HKLM\SOFTWARE\Classes\CLSID\{2DE89BFF-E132-853A-E20D-320167E63033}\InProcServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{2DE89BFF-E132-853A-E20D-320167E63033}\InProcServer32@kagolagpfbkoffmdpmjabl 0x62 0x61 0x67 0x6A ... Reg HKLM\SOFTWARE\Classes\CLSID\{2DE89BFF-E132-853A-E20D-320167E63033}\InProcServer32@jagogpodkogmhpijddca 0x63 0x61 0x62 0x6A ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{28FAB9E2-8056-C399-CA16-FD317BB72F73} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{28FAB9E2-8056-C399-CA16-FD317BB72F73}@iahajioljmcloppjcl 0x6A 0x61 0x65 0x63 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{28FAB9E2-8056-C399-CA16-FD317BB72F73}@hanaphjeohkoaiee 0x6A 0x61 0x65 0x63 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2DE89BFF-E132-853A-E20D-320167E63033} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8923014A-46E6-8B98-1CD9-1623C5A77CEE} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8923014A-46E6-8B98-1CD9-1623C5A77CEE}@hanfgllpamcnhhgd 0x6A 0x61 0x6B 0x63 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8923014A-46E6-8B98-1CD9-1623C5A77CEE}@iapgihbadbmlihojgn 0x6A 0x61 0x6B 0x63 ... ---- Files - GMER 1.0.15 ---- File C:\Windows\system32\drivers\ndis.sys suspicious modification File C:\Windows\system32\drivers\iaStor.sys suspicious modification ---- EOF - GMER 1.0.15 ----
ps:Sound ist wieder da.Code:MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows Vista Home Basic Edition Windows Information: Service Pack 2 (build 6002), 32-bit Base Board Manufacturer: Hewlett-Packard BIOS Manufacturer: Hewlett-Packard System Manufacturer: Hewlett-Packard System Product Name: HP Compaq 6720s Logical Drives Mask: 0x000000bc Kernel Drivers (total 117): 0x81E4F000 \SystemRoot\system32\ntkrnlpa.exe 0x81E1C000 \SystemRoot\system32\hal.dll 0x80609000 \SystemRoot\system32\kdcom.dll 0x80610000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x80680000 \SystemRoot\system32\PSHED.dll 0x80691000 \SystemRoot\system32\BOOTVID.dll 0x80699000 \SystemRoot\system32\CLFS.SYS 0x806DA000 \SystemRoot\system32\CI.dll 0x8600E000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8608A000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x86097000 \SystemRoot\system32\drivers\acpi.sys 0x860DD000 \SystemRoot\system32\drivers\WMILIB.SYS 0x860E6000 \SystemRoot\system32\drivers\msisadrv.sys 0x860EE000 \SystemRoot\system32\drivers\pci.sys 0x86115000 \SystemRoot\System32\drivers\partmgr.sys 0x86124000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x86127000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x86131000 \SystemRoot\system32\drivers\volmgr.sys 0x86140000 \SystemRoot\System32\drivers\volmgrx.sys 0x8618A000 \SystemRoot\system32\DRIVERS\pciide.sys 0x86191000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x8619F000 \SystemRoot\System32\drivers\mountmgr.sys 0x86202000 \SystemRoot\system32\drivers\iastor.sys 0x862C9000 \SystemRoot\system32\drivers\atapi.sys 0x862D1000 \SystemRoot\system32\drivers\ataport.SYS 0x862EF000 \SystemRoot\system32\drivers\fltmgr.sys 0x86321000 \SystemRoot\system32\drivers\fileinfo.sys 0x86331000 \SystemRoot\System32\Drivers\PGPfsfd.sys 0x86358000 \SystemRoot\System32\Drivers\PGPwded.sys 0x86402000 \SystemRoot\System32\Drivers\ksecdd.sys 0x86473000 \SystemRoot\system32\drivers\ndis.sys 0x8657E000 \SystemRoot\system32\drivers\msrpc.sys 0x865A9000 \SystemRoot\system32\drivers\NETIO.SYS 0x8660E000 \SystemRoot\System32\drivers\tcpip.sys 0x866F8000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x86800000 \SystemRoot\System32\Drivers\Ntfs.sys 0x86910000 \SystemRoot\system32\drivers\volsnap.sys 0x86951000 \SystemRoot\System32\Drivers\mup.sys 0x86960000 \SystemRoot\System32\drivers\ecache.sys 0x86987000 \SystemRoot\system32\drivers\disk.sys 0x86998000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x869B9000 \SystemRoot\system32\drivers\crcdisk.sys 0x869CF000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x869DA000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x869E3000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x86393000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x869EE000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8A20A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8A297000 \SystemRoot\system32\DRIVERS\bcmwl6.sys 0x8A3DF000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x8A3F2000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys 0x867DA000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x861AF000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x8A3F7000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x867E5000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x865E4000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8A3F9000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0x8A200000 \SystemRoot\system32\DRIVERS\cpqbttn.sys 0x867F0000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x8A203000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x86600000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x863D1000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x807BA000 \SystemRoot\system32\DRIVERS\storport.sys 0x861DF000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8A603000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8A61A000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8A625000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8A648000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8A657000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8A66B000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8A680000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8A690000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8A692000 \SystemRoot\system32\DRIVERS\ks.sys 0x8A6BC000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8A6C6000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8A6D3000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8A708000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x8A711000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8A722000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8A72B000 \SystemRoot\System32\Drivers\Null.SYS 0x8A732000 \SystemRoot\System32\Drivers\Beep.SYS 0x8A739000 \SystemRoot\System32\drivers\vga.sys 0x8A745000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8A766000 \SystemRoot\System32\drivers\watchdog.sys 0x8A772000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8A77A000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8A785000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8A793000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x8A79C000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8A7B2000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8A7E4000 \SystemRoot\system32\DRIVERS\smb.sys 0x8AC05000 \SystemRoot\system32\drivers\afd.sys 0x8AC4D000 \SystemRoot\system32\drivers\ws2ifsl.sys 0x8AC56000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8AC6C000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8AC7A000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8ACB6000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8ACC0000 \SystemRoot\System32\Drivers\dfsc.sys 0x8ACD7000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8ACE4000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x814C0000 \SystemRoot\System32\win32k.sys 0x8ADAB000 \SystemRoot\System32\drivers\Dxapi.sys 0x816D0000 \SystemRoot\System32\drivers\dxg.sys 0x81700000 \SystemRoot\System32\TSDDD.dll 0x81780000 \SystemRoot\System32\framebuf.dll 0x81790000 \SystemRoot\System32\ATMFD.DLL 0x8ADB5000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x8ADDF000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x86713000 \SystemRoot\system32\DRIVERS\bowser.sys 0x8ADE9000 \SystemRoot\System32\drivers\mpsdrv.sys 0x8672C000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x8674B000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x86784000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x8679C000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x867B2000 \??\C:\Users\ADMINI~1\AppData\Local\Temp\pxlyqpob.sys 0x8AC00000 \SystemRoot\system32\DRIVERS\avmunet.sys 0x76DC0000 \WINDOWS\System32\ntdll.dll Processes (total 25): 0 System Idle Process 4 System 360 C:\WINDOWS\System32\smss.exe 420 csrss.exe 456 csrss.exe 464 C:\WINDOWS\System32\wininit.exe 492 C:\WINDOWS\System32\winlogon.exe 540 C:\WINDOWS\System32\services.exe 556 C:\WINDOWS\System32\lsass.exe 564 C:\WINDOWS\System32\lsm.exe 720 C:\WINDOWS\System32\svchost.exe 780 C:\WINDOWS\System32\svchost.exe 812 C:\WINDOWS\System32\svchost.exe 904 C:\WINDOWS\System32\svchost.exe 932 C:\WINDOWS\System32\svchost.exe 1016 C:\WINDOWS\System32\svchost.exe 1060 C:\WINDOWS\System32\svchost.exe 1084 C:\WINDOWS\System32\svchost.exe 1228 C:\WINDOWS\System32\svchost.exe 1576 C:\WINDOWS\explorer.exe 1976 C:\WINDOWS\System32\wbem\unsecapp.exe 252 WmiPrvSE.exe 1932 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe 648 C:\Program Files\Opera\opera.exe 1952 C:\Users\Administrator\Desktop\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\E: --> \\.\PhysicalDrive0 at offset 0x0000001b`8f300000 (NTFS) \\.\F: --> \\.\PhysicalDrive0 at offset 0x00000019`5cb00000 (NTFS) \\.\H: --> \\.\PhysicalDrive0 at offset 0x0000001b`15200000 (NTFS) PhysicalDrive0 Model Number: FUJITSUMHW2120BH, Rev: 8918 Size Device Name MBR Status -------------------------------------------- 111 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: 81C9386F0D1DB8420800B23A711B4B7BBA6C7045 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!





