Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ---------------------------------------
- Malwarebytes Anti-Rootkit BETA 1.09.3.1001
- (c) Malwarebytes Corporation 2011-2012
- OS version: 6.1.7601 Windows 7 Service Pack 1 x64
- Account is Administrative
- Internet Explorer version: 11.0.9600.17959
- File system is: NTFS
- Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
- CPU speed: 2.261000 GHz
- Memory total: 3133714432, free: 1247191040
- =======================================
- ---------------------------------------
- Malwarebytes Anti-Rootkit BETA 1.09.3.1001
- (c) Malwarebytes Corporation 2011-2012
- OS version: 6.1.7601 Windows 7 Service Pack 1 x64
- Account is Administrative
- Internet Explorer version: 11.0.9600.17959
- File system is: NTFS
- Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
- CPU speed: 2.261000 GHz
- Memory total: 3133714432, free: 1628078080
- Downloaded database version: v2015.09.27.04
- Downloaded database version: v2015.09.22.01
- Downloaded database version: v2015.09.16.01
- =======================================
- Initializing...
- Driver version: 0.3.0.4
- ------------ Kernel report ------------
- 09/27/2015 20:32:50
- ------------ Loaded modules -----------
- \SystemRoot\system32\ntoskrnl.exe
- \SystemRoot\system32\hal.dll
- \SystemRoot\system32\kdcom.dll
- \SystemRoot\system32\mcupdate_GenuineIntel.dll
- \SystemRoot\system32\PSHED.dll
- \SystemRoot\system32\CLFS.SYS
- \SystemRoot\system32\CI.dll
- \SystemRoot\system32\drivers\Wdf01000.sys
- \SystemRoot\system32\drivers\WDFLDR.SYS
- \SystemRoot\system32\drivers\ACPI.sys
- \SystemRoot\system32\drivers\WMILIB.SYS
- \SystemRoot\system32\drivers\msisadrv.sys
- \SystemRoot\system32\drivers\pci.sys
- \SystemRoot\system32\drivers\vdrvroot.sys
- \SystemRoot\System32\drivers\partmgr.sys
- \SystemRoot\system32\DRIVERS\compbatt.sys
- \SystemRoot\system32\DRIVERS\BATTC.SYS
- \SystemRoot\system32\drivers\volmgr.sys
- \SystemRoot\System32\drivers\volmgrx.sys
- \SystemRoot\system32\drivers\pciide.sys
- \SystemRoot\system32\drivers\PCIIDEX.SYS
- \SystemRoot\System32\drivers\mountmgr.sys
- \SystemRoot\system32\DRIVERS\iaStor.sys
- \SystemRoot\system32\drivers\atapi.sys
- \SystemRoot\system32\drivers\ataport.SYS
- \SystemRoot\system32\drivers\msahci.sys
- \SystemRoot\system32\drivers\amdxata.sys
- \SystemRoot\system32\drivers\fltmgr.sys
- \SystemRoot\system32\drivers\fileinfo.sys
- \SystemRoot\System32\Drivers\AsDsm.sys
- \SystemRoot\System32\Drivers\Ntfs.sys
- \SystemRoot\System32\Drivers\msrpc.sys
- \SystemRoot\System32\Drivers\ksecdd.sys
- \SystemRoot\System32\Drivers\cng.sys
- \SystemRoot\System32\drivers\pcw.sys
- \SystemRoot\System32\Drivers\Fs_Rec.sys
- \SystemRoot\system32\drivers\ndis.sys
- \SystemRoot\system32\drivers\NETIO.SYS
- \SystemRoot\System32\Drivers\ksecpkg.sys
- \SystemRoot\System32\drivers\tcpip.sys
- \SystemRoot\System32\drivers\fwpkclnt.sys
- \SystemRoot\system32\drivers\volsnap.sys
- \SystemRoot\System32\Drivers\spldr.sys
- \SystemRoot\System32\drivers\rdyboost.sys
- \SystemRoot\System32\Drivers\mup.sys
- \SystemRoot\System32\drivers\hwpolicy.sys
- \SystemRoot\System32\DRIVERS\fvevol.sys
- \SystemRoot\system32\DRIVERS\disk.sys
- \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
- \SystemRoot\System32\Drivers\aswVmm.sys
- \SystemRoot\System32\Drivers\aswRvrt.sys
- \SystemRoot\system32\drivers\cdrom.sys
- \SystemRoot\system32\drivers\aswSnx.sys
- \SystemRoot\system32\drivers\aswSP.sys
- \SystemRoot\System32\Drivers\Null.SYS
- \SystemRoot\System32\Drivers\Beep.SYS
- \SystemRoot\System32\drivers\vga.sys
- \SystemRoot\System32\drivers\VIDEOPRT.SYS
- \SystemRoot\System32\drivers\watchdog.sys
- \SystemRoot\System32\DRIVERS\RDPCDD.sys
- \SystemRoot\system32\drivers\rdpencdd.sys
- \SystemRoot\system32\drivers\rdprefmp.sys
- \SystemRoot\System32\Drivers\Msfs.SYS
- \SystemRoot\System32\Drivers\Npfs.SYS
- \SystemRoot\system32\DRIVERS\tdx.sys
- \SystemRoot\system32\DRIVERS\TDI.SYS
- \SystemRoot\system32\drivers\afd.sys
- \SystemRoot\system32\drivers\aswRdr2.sys
- \SystemRoot\System32\DRIVERS\netbt.sys
- \SystemRoot\system32\DRIVERS\wfplwf.sys
- \SystemRoot\system32\DRIVERS\pacer.sys
- \SystemRoot\system32\DRIVERS\vwififlt.sys
- \SystemRoot\system32\DRIVERS\netbios.sys
- \SystemRoot\system32\DRIVERS\wanarp.sys
- \SystemRoot\system32\drivers\termdd.sys
- \SystemRoot\system32\DRIVERS\rdbss.sys
- \SystemRoot\system32\drivers\nsiproxy.sys
- \SystemRoot\system32\drivers\mssmbios.sys
- \SystemRoot\System32\drivers\discache.sys
- \SystemRoot\System32\Drivers\dfsc.sys
- \SystemRoot\system32\DRIVERS\blbdrive.sys
- \SystemRoot\system32\DRIVERS\tunnel.sys
- \SystemRoot\system32\DRIVERS\atikmpag.sys
- \SystemRoot\system32\DRIVERS\atikmdag.sys
- \SystemRoot\System32\drivers\dxgkrnl.sys
- \SystemRoot\System32\drivers\dxgmms1.sys
- \SystemRoot\system32\drivers\HDAudBus.sys
- \SystemRoot\system32\DRIVERS\HECIx64.sys
- \SystemRoot\system32\drivers\usbehci.sys
- \SystemRoot\system32\drivers\USBPORT.SYS
- \SystemRoot\system32\DRIVERS\athrx.sys
- \SystemRoot\system32\DRIVERS\vwifibus.sys
- \SystemRoot\system32\DRIVERS\jmcr.sys
- \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
- \SystemRoot\system32\DRIVERS\JME.sys
- \SystemRoot\system32\DRIVERS\i8042prt.sys
- \SystemRoot\system32\DRIVERS\ETD.sys
- \SystemRoot\system32\DRIVERS\mouclass.sys
- \SystemRoot\system32\DRIVERS\kbfiltr.sys
- \SystemRoot\system32\DRIVERS\kbdclass.sys
- \SystemRoot\system32\DRIVERS\CmBatt.sys
- \SystemRoot\system32\DRIVERS\intelppm.sys
- \SystemRoot\system32\DRIVERS\ATK64AMD.sys
- \SystemRoot\system32\drivers\CompositeBus.sys
- \SystemRoot\system32\DRIVERS\AgileVpn.sys
- \SystemRoot\system32\DRIVERS\rasl2tp.sys
- \SystemRoot\system32\DRIVERS\ndistapi.sys
- \SystemRoot\system32\DRIVERS\ndiswan.sys
- \SystemRoot\system32\DRIVERS\raspppoe.sys
- \SystemRoot\system32\DRIVERS\raspptp.sys
- \SystemRoot\system32\DRIVERS\rassstp.sys
- \SystemRoot\system32\drivers\swenum.sys
- \SystemRoot\system32\drivers\ks.sys
- \SystemRoot\system32\drivers\umbus.sys
- \SystemRoot\system32\DRIVERS\usbhub.sys
- \SystemRoot\System32\Drivers\NDProxy.SYS
- \SystemRoot\system32\drivers\AtihdW76.sys
- \SystemRoot\system32\drivers\portcls.sys
- \SystemRoot\system32\drivers\drmk.sys
- \SystemRoot\system32\drivers\ksthunk.sys
- \SystemRoot\system32\drivers\CHDRT64.sys
- \SystemRoot\system32\DRIVERS\usbccgp.sys
- \SystemRoot\system32\DRIVERS\USBD.SYS
- \SystemRoot\system32\DRIVERS\snp2uvc.sys
- \SystemRoot\system32\DRIVERS\STREAM.SYS
- \SystemRoot\system32\DRIVERS\sncduvc.SYS
- \SystemRoot\system32\DRIVERS\hidusb.sys
- \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
- \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
- \SystemRoot\system32\DRIVERS\mouhid.sys
- \SystemRoot\System32\Drivers\crashdmp.sys
- \SystemRoot\System32\Drivers\dump_iaStor.sys
- \SystemRoot\System32\Drivers\dump_dumpfve.sys
- \SystemRoot\System32\win32k.sys
- \SystemRoot\System32\drivers\Dxapi.sys
- \SystemRoot\system32\DRIVERS\monitor.sys
- \SystemRoot\System32\TSDDD.dll
- \SystemRoot\System32\cdd.dll
- \SystemRoot\system32\drivers\luafv.sys
- \SystemRoot\system32\drivers\aswMonFlt.sys
- \??\C:\Windows\system32\drivers\mbam.sys
- \SystemRoot\system32\drivers\aswStm.sys
- \SystemRoot\system32\DRIVERS\lltdio.sys
- \SystemRoot\system32\DRIVERS\nwifi.sys
- \SystemRoot\system32\DRIVERS\ndisuio.sys
- \SystemRoot\system32\DRIVERS\rspndr.sys
- \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
- \SystemRoot\system32\drivers\HTTP.sys
- \SystemRoot\system32\DRIVERS\bowser.sys
- \SystemRoot\System32\drivers\mpsdrv.sys
- \SystemRoot\system32\DRIVERS\mrxsmb.sys
- \SystemRoot\system32\DRIVERS\mrxsmb10.sys
- \SystemRoot\system32\DRIVERS\mrxsmb20.sys
- \SystemRoot\system32\drivers\aswHwid.sys
- \SystemRoot\system32\drivers\peauth.sys
- \SystemRoot\System32\Drivers\secdrv.SYS
- \SystemRoot\System32\DRIVERS\srvnet.sys
- \SystemRoot\System32\drivers\tcpipreg.sys
- \SystemRoot\System32\DRIVERS\srv2.sys
- \SystemRoot\System32\DRIVERS\srv.sys
- \SystemRoot\System32\Drivers\fastfat.SYS
- \??\C:\Program Files (x86)\BatteryCare\WinRing0x64.sys
- \SystemRoot\system32\drivers\spsys.sys
- \??\C:\Windows\system32\drivers\mbamchameleon.sys
- \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
- \Windows\System32\ntdll.dll
- \Windows\System32\smss.exe
- \Windows\System32\apisetschema.dll
- \Windows\System32\autochk.exe
- ----------- End -----------
- Done!
- Scan started
- Database versions:
- main: v2015.09.27.04
- rootkit: v2015.09.22.01
- <<<2>>>
- Physical Sector Size: 512
- Drive: 0, DevicePointer: 0xfffffa800354b060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
- --------- Disk Stack ------
- DevicePointer: 0xfffffa800354bb20, DeviceName: Unknown, DriverName: \Driver\partmgr\
- DevicePointer: 0xfffffa800354b060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
- DevicePointer: 0xfffffa8003297b20, DeviceName: Unknown, DriverName: \Driver\ACPI\
- DevicePointer: 0xfffffa800329d050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
- ------------ End ----------
- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
- Upper DeviceData: 0x0, 0x0, 0x0
- Lower DeviceData: 0x0, 0x0, 0x0
- <<<3>>>
- Volume: C:
- File system type: NTFS
- SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
- <<<2>>>
- <<<3>>>
- Volume: C:
- File system type: NTFS
- SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
- Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
- Done!
- Drive 0
- This is a System drive
- Scanning MBR on drive 0...
- Inspecting partition table:
- MBR Signature: 55AA
- Disk Signature: 27CD9A7B
- Partition information:
- Partition 0 type is Other (0x1c)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 64 Numsec = 45056000
- Partition is not bootable
- Partition file system is FAT32
- Partition 1 type is Primary (0x7)
- Partition is ACTIVE.
- Partition starts at LBA: 45056064 Numsec = 150443659
- Partition is bootable
- Partition file system is NTFS
- Partition 2 type is Extended with LBA (0xf)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 195499723 Numsec = 429642725
- Partition is not bootable
- Partition 3 type is Empty (0x0)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 0 Numsec = 0
- Partition is not bootable
- Disk Size: 320072933376 bytes
- Sector size: 512 bytes
- Done!
- File "C:\ProgramData\AVAST Software\Avast\log\AvastSvc.log" is compressed (flags = 1)
- File "C:\ProgramData\AVAST Software\Avast\log\AvastUI.log" is compressed (flags = 1)
- File "C:\ProgramData\AVAST Software\Avast\log\GrimeFighter2.log" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VF" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE0" is compressed (flags = 1)
- File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1CB7397E69C70C51001D1B4B10FF3FB700887C47.bin.VE1" is compressed (flags = 1)
- Scan finished
- =======================================
- Removal queue found; removal started
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-64-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-1-45056064-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-2-195499723-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
- Removal finished
- ---------------------------------------
- Malwarebytes Anti-Rootkit BETA 1.09.3.1001
- (c) Malwarebytes Corporation 2011-2012
- OS version: 6.1.7601 Windows 7 Service Pack 1 x64
- Account is Administrative
- Internet Explorer version: 11.0.9600.17959
- File system is: NTFS
- Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
- CPU speed: 2.261000 GHz
- Memory total: 3133714432, free: 1280425984
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement