
MBRScan v1.1.1
OS : Windows 8 (64 bit)
PROCESSOR : Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
BOOT : Normal Boot
DATE : 2014/03/31 (ISO 8601) at 10:24:49
________________________________________________________________________________
DISK : Device\Harddisk0\DR0 __Hitachi HTS547575A9E384 (JE4OA50A)
BUS_TYPE : (0x0B) S-ATA
USE_PIO : YES
MAX_TRANSFER : 128 Kb
ALIGNMENT_MASK : dword aligned
________________________________________________________________________________
Device\Harddisk0\DR0 698.6 Go [Fixed] ==> Unknown MBR Code...
MBR_MD5 : 1AB5D1150C10743F6C7BE08B4ADB286C
MBR_SHA1 : C61A2FFAA3BE065EBF7B84727F4653BFA0ED7EFA
Device\Harddisk0\Partition1 2.00 To 0xEE EFI GPT[1]
________________________________________________________________________________
############################### Additional scan ################################
DRIVER : C:\WINDOWS\system32\ntoskrnl.exe => Invisible on the disk
ADDRESS : 0x26A8C000
SIZE : 7.50 Mo
DRIVER : C:\WINDOWS\system32\hal.dll => Invisible on the disk
ADDRESS : 0x26A1D000
SIZE : 444.0 Ko
DRIVER : C:\WINDOWS\system32\kd.dll => Invisible on the disk
ADDRESS : 0x25EAB000
SIZE : 36.0 Ko
DRIVER : C:\WINDOWS\system32\mcupdate_GenuineIntel.dll => Invisible on the disk
ADDRESS : 0x000EB000
SIZE : 408.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\werkernel.sys => Invisible on the disk
ADDRESS : 0x00151000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\CLFS.SYS => Invisible on the disk
ADDRESS : 0x0015F000
SIZE : 392.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\tm.sys => Invisible on the disk
ADDRESS : 0x001C1000
SIZE : 136.0 Ko
DRIVER : C:\WINDOWS\system32\CI.dll => Invisible on the disk
ADDRESS : 0x0000A000
SIZE : 544.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\msrpc.sys => Invisible on the disk
ADDRESS : 0x00291000
SIZE : 372.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\Wdf01000.sys => Invisible on the disk
ADDRESS : 0x002EE000
SIZE : 828.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\WDFLDR.SYS => Invisible on the disk
ADDRESS : 0x003BD000
SIZE : 68.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\acpiex.sys => Invisible on the disk
ADDRESS : 0x003CE000
SIZE : 96.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\WppRecorder.sys => Invisible on the disk
ADDRESS : 0x003E6000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\ACPI.sys => Invisible on the disk
ADDRESS : 0x00200000
SIZE : 532.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\WMILIB.SYS => Invisible on the disk
ADDRESS : 0x00285000
SIZE : 40.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\cng.sys => Invisible on the disk
ADDRESS : 0x00490000
SIZE : 556.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\msisadrv.sys => Invisible on the disk
ADDRESS : 0x0051B000
SIZE : 40.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\pci.sys => Invisible on the disk
ADDRESS : 0x00525000
SIZE : 292.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\vdrvroot.sys => Invisible on the disk
ADDRESS : 0x0056E000
SIZE : 52.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\pdc.sys => Invisible on the disk
ADDRESS : 0x0057B000
SIZE : 112.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\partmgr.sys => Invisible on the disk
ADDRESS : 0x00597000
SIZE : 96.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\spaceport.sys => Invisible on the disk
ADDRESS : 0x00400000
SIZE : 376.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\volmgr.sys => Invisible on the disk
ADDRESS : 0x0045E000
SIZE : 84.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\volmgrx.sys => Invisible on the disk
ADDRESS : 0x00682000
SIZE : 380.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\mountmgr.sys => Invisible on the disk
ADDRESS : 0x006E1000
SIZE : 108.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\iaStorA.sys => Invisible on the disk
ADDRESS : 0x00890000
SIZE : 2.79 Mo
DRIVER : C:\WINDOWS\System32\drivers\storport.sys => Invisible on the disk
ADDRESS : 0x00B5A000
SIZE : 380.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\fltmgr.sys => Invisible on the disk
ADDRESS : 0x00800000
SIZE : 368.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\fileinfo.sys => Invisible on the disk
ADDRESS : 0x0085C000
SIZE : 88.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\Ntfs.sys => Invisible on the disk
ADDRESS : 0x00C7C000
SIZE : 1.96 Mo
DRIVER : C:\WINDOWS\System32\Drivers\ksecdd.sys => Invisible on the disk
ADDRESS : 0x00E72000
SIZE : 112.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\pcw.sys => Invisible on the disk
ADDRESS : 0x00E8E000
SIZE : 64.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\Fs_Rec.sys => Invisible on the disk
ADDRESS : 0x00E9E000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\ndis.sys => Invisible on the disk
ADDRESS : 0x00EA9000
SIZE : 1.09 Mo
DRIVER : C:\WINDOWS\system32\drivers\NETIO.SYS => Invisible on the disk
ADDRESS : 0x00C00000
SIZE : 484.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\ksecpkg.sys => Invisible on the disk
ADDRESS : 0x00FC1000
SIZE : 208.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\tcpip.sys => Invisible on the disk
ADDRESS : 0x010BF000
SIZE : 2.48 Mo
DRIVER : C:\WINDOWS\System32\drivers\fwpkclnt.sys => Invisible on the disk
ADDRESS : 0x0133B000
SIZE : 432.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\wfplwfs.sys => Invisible on the disk
ADDRESS : 0x013A7000
SIZE : 148.0 Ko
DRIVER : C:\WINDOWS\System32\DRIVERS\fvevol.sys => Invisible on the disk
ADDRESS : 0x01000000
SIZE : 588.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\volsnap.sys => Invisible on the disk
ADDRESS : 0x006FC000
SIZE : 320.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\rdyboost.sys => Invisible on the disk
ADDRESS : 0x0074C000
SIZE : 276.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\mup.sys => Invisible on the disk
ADDRESS : 0x01093000
SIZE : 92.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\intelpep.sys => Invisible on the disk
ADDRESS : 0x010AA000
SIZE : 60.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\disk.sys => Invisible on the disk
ADDRESS : 0x013D8000
SIZE : 112.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\CLASSPNP.SYS => Invisible on the disk
ADDRESS : 0x00791000
SIZE : 344.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\aswVmm.sys => Invisible on the disk
ADDRESS : 0x00600000
SIZE : 212.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\aswRvrt.sys => Invisible on the disk
ADDRESS : 0x00872000
SIZE : 76.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\crashdmp.sys => Invisible on the disk
ADDRESS : 0x00BD3000
SIZE : 84.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\cdrom.sys => Invisible on the disk
ADDRESS : 0x01920000
SIZE : 184.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys => Invisible on the disk
ADDRESS : 0x0194E000
SIZE : 184.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\aswSnx.sys => Invisible on the disk
ADDRESS : 0x01A85000
SIZE : 1.00 Mo
DRIVER : C:\WINDOWS\system32\drivers\aswSP.sys => Invisible on the disk
ADDRESS : 0x01B86000
SIZE : 436.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\Null.SYS => Invisible on the disk
ADDRESS : 0x01BF3000
SIZE : 36.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\Beep.SYS => Invisible on the disk
ADDRESS : 0x01A00000
SIZE : 32.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\BasicRender.sys => Invisible on the disk
ADDRESS : 0x01A08000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\dxgkrnl.sys => Invisible on the disk
ADDRESS : 0x01C8E000
SIZE : 1.48 Mo
DRIVER : C:\WINDOWS\System32\drivers\watchdog.sys => Invisible on the disk
ADDRESS : 0x01E08000
SIZE : 72.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\dxgmms1.sys => Invisible on the disk
ADDRESS : 0x01E1A000
SIZE : 388.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\BasicDisplay.sys => Invisible on the disk
ADDRESS : 0x01E7B000
SIZE : 72.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\Npfs.SYS => Invisible on the disk
ADDRESS : 0x01E8D000
SIZE : 80.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\Msfs.SYS => Invisible on the disk
ADDRESS : 0x01EA1000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\tdx.sys => Invisible on the disk
ADDRESS : 0x01EAD000
SIZE : 128.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\TDI.SYS => Invisible on the disk
ADDRESS : 0x01ECD000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\System32\DRIVERS\netbt.sys => Invisible on the disk
ADDRESS : 0x01EDB000
SIZE : 304.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\aswRdr2.sys => Invisible on the disk
ADDRESS : 0x01F27000
SIZE : 104.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\afd.sys => Invisible on the disk
ADDRESS : 0x01F41000
SIZE : 588.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\pacer.sys => Invisible on the disk
ADDRESS : 0x01FD4000
SIZE : 168.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\vwififlt.sys => Invisible on the disk
ADDRESS : 0x01C00000
SIZE : 96.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\netbios.sys => Invisible on the disk
ADDRESS : 0x01C18000
SIZE : 68.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\rdbss.sys => Invisible on the disk
ADDRESS : 0x0197C000
SIZE : 448.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\nsiproxy.sys => Invisible on the disk
ADDRESS : 0x01C29000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\npsvctrig.sys => Invisible on the disk
ADDRESS : 0x01C37000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\mssmbios.sys => Invisible on the disk
ADDRESS : 0x01C43000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\dfsc.sys => Invisible on the disk
ADDRESS : 0x01C4F000
SIZE : 152.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys => Invisible on the disk
ADDRESS : 0x01A16000
SIZE : 104.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\ahcache.sys => Invisible on the disk
ADDRESS : 0x01C75000
SIZE : 92.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\CompositeBus.sys => Invisible on the disk
ADDRESS : 0x01A30000
SIZE : 60.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\kdnic.sys => Invisible on the disk
ADDRESS : 0x01A3F000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\umbus.sys => Invisible on the disk
ADDRESS : 0x01A4A000
SIZE : 68.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\atikmpag.sys => Invisible on the disk
ADDRESS : 0x02009000
SIZE : 632.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\atikmdag.sys => Invisible on the disk
ADDRESS : 0x02271000
SIZE : 12.29 Mo
DRIVER : C:\WINDOWS\system32\DRIVERS\igdkmd64.sys => Invisible on the disk
ADDRESS : 0x0308C000
SIZE : 4.13 Mo
DRIVER : C:\WINDOWS\System32\Drivers\fastfat.SYS => Invisible on the disk
ADDRESS : 0x034AE000
SIZE : 228.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\USBXHCI.SYS => Invisible on the disk
ADDRESS : 0x034E7000
SIZE : 340.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\ucx01000.sys => Invisible on the disk
ADDRESS : 0x0353C000
SIZE : 200.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\HECIx64.sys => Invisible on the disk
ADDRESS : 0x0356E000
SIZE : 76.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\usbehci.sys => Invisible on the disk
ADDRESS : 0x03581000
SIZE : 96.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\USBPORT.SYS => Invisible on the disk
ADDRESS : 0x03000000
SIZE : 444.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\HDAudBus.sys => Invisible on the disk
ADDRESS : 0x0306F000
SIZE : 100.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\Rt630x64.sys => Invisible on the disk
ADDRESS : 0x02EBA000
SIZE : 592.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\athw8x.sys => Invisible on the disk
ADDRESS : 0x03612000
SIZE : 3.54 Mo
DRIVER : C:\WINDOWS\System32\drivers\vwifibus.sys => Invisible on the disk
ADDRESS : 0x0399B000
SIZE : 52.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\i8042prt.sys => Invisible on the disk
ADDRESS : 0x039A8000
SIZE : 124.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\SynTP.sys => Invisible on the disk
ADDRESS : 0x02F4E000
SIZE : 468.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\USBD.SYS => Invisible on the disk
ADDRESS : 0x039C7000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\mouclass.sys => Invisible on the disk
ADDRESS : 0x039D3000
SIZE : 64.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\kbdclass.sys => Invisible on the disk
ADDRESS : 0x039E3000
SIZE : 64.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\CmBatt.sys => Invisible on the disk
ADDRESS : 0x039F3000
SIZE : 28.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\BATTC.SYS => Invisible on the disk
ADDRESS : 0x03600000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\wmiacpi.sys => Invisible on the disk
ADDRESS : 0x03599000
SIZE : 40.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\intelppm.sys => Invisible on the disk
ADDRESS : 0x035A3000
SIZE : 120.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\RadioHIDMini.sys => Invisible on the disk
ADDRESS : 0x035C1000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\mshidkmdf.sys => Invisible on the disk
ADDRESS : 0x035CC000
SIZE : 36.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\HIDCLASS.SYS => Invisible on the disk
ADDRESS : 0x035D5000
SIZE : 124.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\HIDPARSE.SYS => Invisible on the disk
ADDRESS : 0x035F4000
SIZE : 32.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\NdisVirtualBus.sys => Invisible on the disk
ADDRESS : 0x02FC3000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\swenum.sys => Invisible on the disk
ADDRESS : 0x0360C000
SIZE : 8.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\ks.sys => Invisible on the disk
ADDRESS : 0x02200000
SIZE : 304.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\iwdbus.sys => Invisible on the disk
ADDRESS : 0x0224C000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\rdpbus.sys => Invisible on the disk
ADDRESS : 0x02258000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\RTKVHD64.sys => Invisible on the disk
ADDRESS : 0x03A34000
SIZE : 3.91 Mo
DRIVER : C:\WINDOWS\system32\drivers\portcls.sys => Invisible on the disk
ADDRESS : 0x03E1D000
SIZE : 284.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\drmk.sys => Invisible on the disk
ADDRESS : 0x03E64000
SIZE : 112.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\ksthunk.sys => Invisible on the disk
ADDRESS : 0x03E80000
SIZE : 24.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\IntcDAud.sys => Invisible on the disk
ADDRESS : 0x03E86000
SIZE : 352.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\usbhub.sys => Invisible on the disk
ADDRESS : 0x03EDE000
SIZE : 428.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\UsbHub3.sys => Invisible on the disk
ADDRESS : 0x03F49000
SIZE : 480.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\dump_diskdump.sys => Invisible on the disk
ADDRESS : 0x03FC1000
SIZE : 48.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\dump_iaStorA.sys => Invisible on the disk
ADDRESS : 0x01600000
SIZE : 2.79 Mo
DRIVER : C:\WINDOWS\System32\Drivers\dump_dumpfve.sys => Invisible on the disk
ADDRESS : 0x03FCD000
SIZE : 88.0 Ko
DRIVER : C:\WINDOWS\System32\win32k.sys => Invisible on the disk
ADDRESS : 0x00188000
SIZE : 4.10 Mo
DRIVER : C:\WINDOWS\system32\DRIVERS\btfilter.sys => Invisible on the disk
ADDRESS : 0x020A7000
SIZE : 648.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\BTHUSB.sys => Invisible on the disk
ADDRESS : 0x03A00000
SIZE : 100.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\bthport.sys => Invisible on the disk
ADDRESS : 0x040DA000
SIZE : 1.17 Mo
DRIVER : C:\WINDOWS\System32\drivers\usbccgp.sys => Invisible on the disk
ADDRESS : 0x04206000
SIZE : 168.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\usbvideo.sys => Invisible on the disk
ADDRESS : 0x04230000
SIZE : 208.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys => Invisible on the disk
ADDRESS : 0x04264000
SIZE : 244.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\rfcomm.sys => Invisible on the disk
ADDRESS : 0x042A1000
SIZE : 184.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\BthEnum.sys => Invisible on the disk
ADDRESS : 0x042CF000
SIZE : 72.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\bthpan.sys => Invisible on the disk
ADDRESS : 0x042E1000
SIZE : 132.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\btath_rcp.sys => Invisible on the disk
ADDRESS : 0x04302000
SIZE : 304.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\btath_hcrp.sys => Invisible on the disk
ADDRESS : 0x04000000
SIZE : 304.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\btath_hid.sys => Invisible on the disk
ADDRESS : 0x04064000
SIZE : 368.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\monitor.sys => Invisible on the disk
ADDRESS : 0x040C0000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\System32\TSDDD.dll => Invisible on the disk
ADDRESS : 0x00663000
SIZE : 36.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\luafv.sys => Invisible on the disk
ADDRESS : 0x0434E000
SIZE : 144.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\aswMonFlt.sys => Invisible on the disk
ADDRESS : 0x04372000
SIZE : 132.0 Ko
DRIVER : C:\windows\system32\drivers\mbam.sys => Invisible on the disk
ADDRESS : 0x04393000
SIZE : 40.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\lltdio.sys => Invisible on the disk
ADDRESS : 0x0439D000
SIZE : 80.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\nwifi.sys => Invisible on the disk
ADDRESS : 0x02149000
SIZE : 456.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\ndisuio.sys => Invisible on the disk
ADDRESS : 0x043B1000
SIZE : 80.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\rspndr.sys => Invisible on the disk
ADDRESS : 0x043C5000
SIZE : 96.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\condrv.sys => Invisible on the disk
ADDRESS : 0x043DD000
SIZE : 64.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\vwifimp.sys => Invisible on the disk
ADDRESS : 0x043ED000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\HTTP.sys => Invisible on the disk
ADDRESS : 0x04C40000
SIZE : 1000.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\bowser.sys => Invisible on the disk
ADDRESS : 0x04D3A000
SIZE : 128.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\mpsdrv.sys => Invisible on the disk
ADDRESS : 0x04D5A000
SIZE : 92.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\mrxsmb.sys => Invisible on the disk
ADDRESS : 0x04D71000
SIZE : 432.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys => Invisible on the disk
ADDRESS : 0x04C00000
SIZE : 228.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys => Invisible on the disk
ADDRESS : 0x018CA000
SIZE : 300.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\Ndu.sys => Invisible on the disk
ADDRESS : 0x04DDD000
SIZE : 116.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\peauth.sys => Invisible on the disk
ADDRESS : 0x04EAA000
SIZE : 676.0 Ko
DRIVER : C:\WINDOWS\System32\Drivers\secdrv.SYS => Invisible on the disk
ADDRESS : 0x04F53000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\System32\DRIVERS\srvnet.sys => Invisible on the disk
ADDRESS : 0x04F5E000
SIZE : 268.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\tcpipreg.sys => Invisible on the disk
ADDRESS : 0x04FA1000
SIZE : 72.0 Ko
DRIVER : C:\WINDOWS\System32\DRIVERS\srv2.sys => Invisible on the disk
ADDRESS : 0x05E0D000
SIZE : 692.0 Ko
DRIVER : C:\WINDOWS\System32\DRIVERS\srv.sys => Invisible on the disk
ADDRESS : 0x05EBA000
SIZE : 608.0 Ko
DRIVER : C:\WINDOWS\system32\DRIVERS\tunnel.sys => Invisible on the disk
ADDRESS : 0x05F52000
SIZE : 180.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\aswStm.sys => Invisible on the disk
ADDRESS : 0x05F7F000
SIZE : 92.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\rdpvideominiport.sys => Invisible on the disk
ADDRESS : 0x05F96000
SIZE : 44.0 Ko
DRIVER : C:\WINDOWS\System32\cdd.dll => Invisible on the disk
ADDRESS : 0x00880000
SIZE : 236.0 Ko
DRIVER : C:\WINDOWS\system32\drivers\WudfPf.sys => Invisible on the disk
ADDRESS : 0x04FB3000
SIZE : 132.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\hidusb.sys => Invisible on the disk
ADDRESS : 0x05FE2000
SIZE : 56.0 Ko
DRIVER : C:\WINDOWS\System32\drivers\mouhid.sys => Invisible on the disk
ADDRESS : 0x05FF0000
SIZE : 52.0 Ko
DRIVER : C:\Users\brzenka\AppData\Local\Temp\pxldypob.sys => Invisible on the disk
ADDRESS : 0x05FA1000
SIZE : 64.0 Ko
BCD EmsSettings {0CE4991B-E6B3-4B16-B23C-5E0D9250E5D9} => BcdLibraryBoolean_EmsEnabled (16000020)
SystemStartOptions : NOEXECUTE=OPTIN NOVGA
________________________________________________________________________________
_______MBR \Device\Harddisk0\DR0
0x00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000080 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000090 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000000A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000000B0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000000C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000000D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000000E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000000F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000100 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000110 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000120 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000130 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000140 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000150 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000160 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000170 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x00000190 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000001A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000001B0 00 00 00 00 00 00 00 00 AD 46 82 00 00 00 00 00 ........F......
0x000001C0 02 00 EE FF FF FF 01 00 00 00 FF FF FF FF 00 00 ..î.............
0x000001D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000001F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA ..............Uª
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-03-31 12:38:56
-----------------------------
12:38:56.678 OS Version: Windows x64 6.2.9200
12:38:56.678 Number of processors: 4 586 0x3A09
12:38:56.678 ComputerName: SZEF UserName:
12:38:57.100 Initialze error 1
12:39:01.522 AVAST engine defs: 14033100
12:39:02.865 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002e
12:39:02.865 Disk 0 Vendor: Hitachi_HTS547575A9E384 JE4OA50A Size: 715404MB BusType: 11
12:39:02.881 Disk 0 MBR read successfully
12:39:02.881 Disk 0 MBR scan
12:39:02.881 Disk 0 unknown MBR code
12:39:02.881 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
12:39:02.881 Disk 0 scanning C:\WINDOWS\system32\drivers
12:39:02.897 Service scanning
12:39:03.490 Modules scanning
12:39:03.490 Disk 0 trace - called modules:
12:39:03.490 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys
12:39:03.506 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000029925e0]
12:39:03.506 3 CLASSPNP.SYS[fffff80000792abb] -> nt!IofCallDriver -> [0xffffe00000ff12d0]
12:39:03.506 5 ACPI.sys[fffff800002025f1] -> nt!IofCallDriver -> \Device\0000002e[0xffffe00000ff3060]
12:39:03.522 AVAST engine scan C:\WINDOWS
12:39:03.522 AVAST engine scan C:\WINDOWS\system32
12:39:03.522 AVAST engine scan C:\WINDOWS\system32\drivers
12:39:03.537 AVAST engine scan C:\Users\brzenka
12:39:03.537 AVAST engine scan C:\ProgramData
12:39:03.537 Scan finished successfully
12:39:19.491 Disk 0 MBR has been saved successfully to "C:\Users\brzenka\Desktop\MBR.dat"
12:39:19.507 The log file has been saved successfully to "C:\Users\brzenka\Desktop\aswMBR.txt"
RogueKiller V8.8.15 _x64_ [Mar 27 2014] od Adlice Software
mail : http://www.adlice.com/contact/
Dodaj opinię : http://forum.adlice.com
Strona internetowa : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
System Operacyjny : Windows 8.1 (6.3.9200 ) 64 bits version
Uruchomiono z : Tryb normalny
Użytkownik : brzenka [Uprawnienia Administratora]
Tryb : Skanuj -- Data : 04/04/2014 07:42:46
| ARK || FAK || MBR |
¤¤¤ Szkodliwe procesy : 2 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [x] -> ZWOLNIONY
[SUSP PATH] SWMAgent.exe -- C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [-] -> ZAKOŃCZONO [TermProc]
¤¤¤ Wpisy w Rejestrze : 4 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : GG ("C:\Users\brzenka\AppData\Local\GG\Application\gghub.exe" [7]) -> ZNALEZIONO
[RUN][SUSP PATH] HKUS\S-1-5-21-1577275202-546194520-1271563289-1001\[...]\Run : GG ("C:\Users\brzenka\AppData\Local\GG\Application\gghub.exe" [7]) -> ZNALEZIONO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> ZNALEZIONO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> ZNALEZIONO
¤¤¤ Zaplanowane zadania : 0 ¤¤¤
¤¤¤ Wpisy startowe : 0 ¤¤¤
¤¤¤ przeglądarki internetowe : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Pliki / Foldery: ¤¤¤
¤¤¤ Sterownik : [NIEZAŁADOWANY 0x0] ¤¤¤
[Address] EAT @explorer.exe (AccConvertAccessMaskToActrlAccess) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0FA0C)
[Address] EAT @explorer.exe (AccConvertAccessToSD) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0FB80)
[Address] EAT @explorer.exe (AccConvertAccessToSecurityDescriptor) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0FD3C)
[Address] EAT @explorer.exe (AccConvertAclToAccess) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0FE90)
[Address] EAT @explorer.exe (AccConvertSDToAccess) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0FF2C)
[Address] EAT @explorer.exe (AccFreeIndexArray) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D00D80)
[Address] EAT @explorer.exe (AccGetAccessForTrustee) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D101A8)
[Address] EAT @explorer.exe (AccGetExplicitEntries) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D10288)
[Address] EAT @explorer.exe (AccGetInheritanceSource) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D00EA0)
[Address] EAT @explorer.exe (AccLookupAccountName) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D10348)
[Address] EAT @explorer.exe (AccLookupAccountSid) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D10648)
[Address] EAT @explorer.exe (AccLookupAccountTrustee) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D109CC)
[Address] EAT @explorer.exe (AccProvCancelOperation) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0CAFC)
[Address] EAT @explorer.exe (AccProvGetAccessInfoPerObjectType) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0CB74)
[Address] EAT @explorer.exe (AccProvGetAllRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0CC1C)
[Address] EAT @explorer.exe (AccProvGetCapabilities) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF8100)
[Address] EAT @explorer.exe (AccProvGetOperationResults) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0CDF8)
[Address] EAT @explorer.exe (AccProvGetTrusteesAccess) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0CF38)
[Address] EAT @explorer.exe (AccProvGrantAccessRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D040)
[Address] EAT @explorer.exe (AccProvHandleGetAccessInfoPerObjectType) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D1B0)
[Address] EAT @explorer.exe (AccProvHandleGetAllRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D298)
[Address] EAT @explorer.exe (AccProvHandleGetTrusteesAccess) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D410)
[Address] EAT @explorer.exe (AccProvHandleGrantAccessRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0C4D0)
[Address] EAT @explorer.exe (AccProvHandleIsAccessAudited) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D48C)
[Address] EAT @explorer.exe (AccProvHandleIsObjectAccessible) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D524)
[Address] EAT @explorer.exe (AccProvHandleRevokeAccessRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D660)
[Address] EAT @explorer.exe (AccProvHandleRevokeAuditRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D738)
[Address] EAT @explorer.exe (AccProvHandleSetAccessRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D810)
[Address] EAT @explorer.exe (AccProvIsAccessAudited) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0D910)
[Address] EAT @explorer.exe (AccProvIsObjectAccessible) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0DA24)
[Address] EAT @explorer.exe (AccProvRevokeAccessRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0DE74)
[Address] EAT @explorer.exe (AccProvRevokeAuditRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0DFB0)
[Address] EAT @explorer.exe (AccProvSetAccessRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D0E0EC)
[Address] EAT @explorer.exe (AccRewriteGetExplicitEntriesFromAcl) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF7BD4)
[Address] EAT @explorer.exe (AccRewriteGetHandleRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D01510)
[Address] EAT @explorer.exe (AccRewriteGetNamedRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D01680)
[Address] EAT @explorer.exe (AccRewriteSetEntriesInAcl) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF3070)
[Address] EAT @explorer.exe (AccRewriteSetHandleRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF2270)
[Address] EAT @explorer.exe (AccRewriteSetNamedRights) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF3BA0)
[Address] EAT @explorer.exe (AccSetEntriesInAList) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97D10AD4)
[Address] EAT @explorer.exe (AccTreeResetNamedSecurityInfo) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF58A0)
[Address] EAT @explorer.exe (EventGuidToName) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CFDE68)
[Address] EAT @explorer.exe (EventNameFree) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CFDEF4)
[Address] EAT @explorer.exe (GetExplicitEntriesFromAclW) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF7BCC)
[Address] EAT @explorer.exe (GetMartaExtensionInterface) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF3600)
[Address] EAT @explorer.exe (GetNamedSecurityInfoW) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF2680)
[Address] EAT @explorer.exe (GetSecurityInfo) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF1390)
[Address] EAT @explorer.exe (SetEntriesInAclW) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF3060)
[Address] EAT @explorer.exe (SetNamedSecurityInfoW) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF3E64)
[Address] EAT @explorer.exe (SetSecurityInfo) : NInput.dll -> HOOKED (C:\WINDOWS\SYSTEM32\ntmarta.dll @ 0x97CF21B0)
[Address] EAT @firefox.exe (DllMain) : Secur32.dll -> HOOKED (C:\WINDOWS\SysWOW64\napinsp.dll @ 0x74761B4C)
[Address] EAT @firefox.exe (NSPStartup) : Secur32.dll -> HOOKED (C:\WINDOWS\SysWOW64\napinsp.dll @ 0x74761675)
¤¤¤ Gałąź rejestru (offline): ¤¤¤
¤¤¤ Infekcja : ¤¤¤
¤¤¤ Plik HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Sprawdzenie MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS547575A9E384 +++++
--- User ---
[MBR] 1ab5d1150c10743f6c7be08b4adb286c
[BSP] b422185b91aebf1d67962fabb2d4b66c : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK!
User = LL2 ... OK!
Zakończono : << RKreport[0]_S_04042014_074246.txt >>
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 4 gości