Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ---------------------------------------
- Malwarebytes Anti-Rootkit BETA 1.09.3.1001
- (c) Malwarebytes Corporation 2011-2012
- OS version: 10.0.9200 Windows 10 x64
- Account is Administrative
- Internet Explorer version: 11.162.10586.0
- File system is: NTFS
- Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED
- CPU speed: 3.060000 GHz
- Memory total: 17076756480, free: 11107098624
- Downloaded database version: v2016.04.15.02
- Canceled update
- =======================================
- ---------------------------------------
- Malwarebytes Anti-Rootkit BETA 1.09.3.1001
- (c) Malwarebytes Corporation 2011-2012
- OS version: 10.0.9200 Windows 10 x64
- Account is Administrative
- Internet Explorer version: 11.162.10586.0
- File system is: NTFS
- Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED
- CPU speed: 3.060000 GHz
- Memory total: 17076756480, free: 11116199936
- Downloaded database version: v2016.04.15.02
- Downloaded database version: v2016.04.09.01
- Downloaded database version: v2016.04.12.01
- Initializing...
- =======================================
- Driver version: 0.3.0.4
- ------------ Kernel report ------------
- 04/15/2016 19:46:36
- ------------ Loaded modules -----------
- \SystemRoot\system32\ntoskrnl.exe
- \SystemRoot\system32\hal.dll
- \SystemRoot\system32\kd.dll
- \SystemRoot\system32\mcupdate_GenuineIntel.dll
- \SystemRoot\System32\drivers\werkernel.sys
- \SystemRoot\System32\drivers\CLFS.SYS
- \SystemRoot\System32\drivers\tm.sys
- \SystemRoot\system32\PSHED.dll
- \SystemRoot\system32\BOOTVID.dll
- \SystemRoot\System32\drivers\cmimcext.sys
- \SystemRoot\System32\drivers\ntosext.sys
- \SystemRoot\system32\CI.dll
- \SystemRoot\System32\drivers\msrpc.sys
- \SystemRoot\System32\drivers\FLTMGR.SYS
- \SystemRoot\System32\drivers\ksecdd.sys
- \SystemRoot\System32\drivers\clipsp.sys
- \SystemRoot\system32\drivers\Wdf01000.sys
- \SystemRoot\system32\drivers\WDFLDR.SYS
- \SystemRoot\System32\Drivers\acpiex.sys
- \SystemRoot\System32\Drivers\WppRecorder.sys
- \SystemRoot\System32\Drivers\cng.sys
- \SystemRoot\System32\drivers\ACPI.sys
- \SystemRoot\System32\drivers\WMILIB.SYS
- \SystemRoot\system32\drivers\WindowsTrustedRT.sys
- \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
- \SystemRoot\System32\drivers\pcw.sys
- \SystemRoot\System32\drivers\msisadrv.sys
- \SystemRoot\System32\drivers\pci.sys
- \SystemRoot\System32\drivers\vdrvroot.sys
- \SystemRoot\system32\drivers\pdc.sys
- \SystemRoot\system32\drivers\CEA.sys
- \SystemRoot\System32\drivers\partmgr.sys
- \SystemRoot\System32\drivers\spaceport.sys
- \SystemRoot\System32\drivers\volmgr.sys
- \SystemRoot\System32\drivers\volmgrx.sys
- \SystemRoot\System32\drivers\vmci.sys
- \SystemRoot\system32\drivers\vsock.sys
- \SystemRoot\System32\drivers\mountmgr.sys
- \SystemRoot\System32\drivers\storahci.sys
- \SystemRoot\System32\drivers\storport.sys
- \SystemRoot\System32\drivers\EhStorClass.sys
- \SystemRoot\System32\drivers\fileinfo.sys
- \SystemRoot\System32\Drivers\Wof.sys
- \SystemRoot\System32\Drivers\NTFS.sys
- \SystemRoot\System32\Drivers\Fs_Rec.sys
- \SystemRoot\system32\drivers\ndis.sys
- \SystemRoot\system32\drivers\NETIO.SYS
- \SystemRoot\System32\Drivers\ksecpkg.sys
- \SystemRoot\System32\drivers\tcpip.sys
- \SystemRoot\System32\drivers\fwpkclnt.sys
- \SystemRoot\System32\drivers\wfplwfs.sys
- \SystemRoot\System32\drivers\asstor64.sys
- \SystemRoot\System32\DRIVERS\fvevol.sys
- \SystemRoot\System32\drivers\volsnap.sys
- \SystemRoot\System32\drivers\rdyboost.sys
- \SystemRoot\System32\Drivers\mup.sys
- \SystemRoot\system32\DRIVERS\iaStorF.sys
- \SystemRoot\System32\drivers\disk.sys
- \SystemRoot\System32\drivers\CLASSPNP.SYS
- \SystemRoot\System32\Drivers\crashdmp.sys
- \SystemRoot\System32\DRIVERS\cmderd.sys
- \SystemRoot\System32\drivers\cdrom.sys
- \SystemRoot\system32\drivers\filecrypt.sys
- \SystemRoot\system32\drivers\tbs.sys
- \SystemRoot\system32\DRIVERS\cmdguard.sys
- \SystemRoot\system32\DRIVERS\CFRMD.sys
- \SystemRoot\System32\Drivers\Null.SYS
- \SystemRoot\System32\Drivers\Beep.SYS
- \SystemRoot\System32\drivers\BasicDisplay.sys
- \SystemRoot\System32\drivers\watchdog.sys
- \SystemRoot\System32\drivers\dxgkrnl.sys
- \SystemRoot\System32\drivers\BasicRender.sys
- \SystemRoot\System32\Drivers\Npfs.SYS
- \SystemRoot\System32\Drivers\Msfs.SYS
- \SystemRoot\system32\DRIVERS\tdx.sys
- \SystemRoot\system32\DRIVERS\TDI.SYS
- \SystemRoot\system32\drivers\ws2ifsl.sys
- \SystemRoot\System32\DRIVERS\netbt.sys
- \SystemRoot\system32\DRIVERS\cmdhlp.sys
- \SystemRoot\system32\drivers\afd.sys
- \SystemRoot\system32\DRIVERS\inspect.sys
- \SystemRoot\System32\drivers\vwififlt.sys
- \SystemRoot\System32\drivers\pacer.sys
- \SystemRoot\system32\drivers\netbios.sys
- \SystemRoot\system32\DRIVERS\avkmgr.sys
- \SystemRoot\system32\DRIVERS\avipbb.sys
- \SystemRoot\system32\DRIVERS\rdbss.sys
- \SystemRoot\system32\drivers\nsiproxy.sys
- \SystemRoot\System32\drivers\npsvctrig.sys
- \SystemRoot\System32\drivers\mssmbios.sys
- \SystemRoot\System32\drivers\gpuenergydrv.sys
- \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys
- \SystemRoot\System32\Drivers\dfsc.sys
- \SystemRoot\SysWow64\drivers\AsIO.sys
- \SystemRoot\system32\DRIVERS\ahcache.sys
- \SystemRoot\System32\drivers\tap0901.sys
- \SystemRoot\system32\DRIVERS\vmnetadapter.sys
- \SystemRoot\system32\DRIVERS\VMNET.SYS
- \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_912dfdedc3d2f520\CompositeBus.sys
- \SystemRoot\System32\drivers\kdnic.sys
- \SystemRoot\System32\drivers\umbus.sys
- \SystemRoot\System32\drivers\intelppm.sys
- \SystemRoot\System32\drivers\wmiacpi.sys
- \SystemRoot\system32\DRIVERS\nvlddmkm.sys
- \SystemRoot\System32\drivers\HDAudBus.sys
- \SystemRoot\System32\drivers\portcls.sys
- \SystemRoot\System32\drivers\drmk.sys
- \SystemRoot\System32\drivers\ks.sys
- \SystemRoot\System32\drivers\USBXHCI.SYS
- \SystemRoot\system32\drivers\ucx01000.sys
- \SystemRoot\system32\DRIVERS\TeeDriverx64.sys
- \SystemRoot\System32\drivers\e1i63x64.sys
- \SystemRoot\System32\drivers\usbehci.sys
- \SystemRoot\System32\drivers\USBPORT.SYS
- \SystemRoot\system32\DRIVERS\bcmwl664.sys
- \SystemRoot\System32\drivers\vwifibus.sys
- \SystemRoot\system32\drivers\nvvad64v.sys
- \SystemRoot\system32\drivers\ksthunk.sys
- \SystemRoot\System32\drivers\NdisVirtualBus.sys
- \SystemRoot\System32\drivers\swenum.sys
- \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- \SystemRoot\system32\drivers\LGBusEnum.sys
- \SystemRoot\system32\drivers\LGJoyXlCore.sys
- \SystemRoot\System32\drivers\rdpbus.sys
- \SystemRoot\System32\drivers\usbhub.sys
- \SystemRoot\System32\drivers\USBD.SYS
- \SystemRoot\system32\DRIVERS\USBPcap.sys
- \SystemRoot\System32\drivers\HIDCLASS.SYS
- \SystemRoot\System32\drivers\HIDPARSE.SYS
- \SystemRoot\system32\drivers\nvhda64v.sys
- \SystemRoot\System32\drivers\UsbHub3.sys
- \SystemRoot\system32\drivers\RTKVHD64.sys
- \SystemRoot\System32\drivers\mouhid.sys
- \SystemRoot\System32\drivers\mouclass.sys
- \SystemRoot\System32\drivers\kbdhid.sys
- \SystemRoot\System32\drivers\kbdclass.sys
- \SystemRoot\System32\drivers\xusb22.sys
- \SystemRoot\System32\drivers\hidusb.sys
- \SystemRoot\system32\drivers\bcbtums.sys
- \SystemRoot\System32\drivers\BTHUSB.sys
- \SystemRoot\System32\drivers\bthport.sys
- \SystemRoot\System32\drivers\usbccgp.sys
- \SystemRoot\System32\drivers\BthLEEnum.sys
- \SystemRoot\System32\drivers\rfcomm.sys
- \SystemRoot\System32\drivers\BthEnum.sys
- \SystemRoot\System32\drivers\bthpan.sys
- \SystemRoot\system32\drivers\usbaudio.sys
- \SystemRoot\System32\win32k.sys
- \SystemRoot\System32\win32kfull.sys
- \SystemRoot\System32\win32kbase.sys
- \SystemRoot\System32\Drivers\dump_diskdump.sys
- \SystemRoot\System32\Drivers\dump_storahci.sys
- \SystemRoot\System32\Drivers\dump_dumpfve.sys
- \SystemRoot\System32\drivers\dxgmms2.sys
- \SystemRoot\System32\drivers\monitor.sys
- \SystemRoot\System32\TSDDD.dll
- \SystemRoot\System32\ATMFD.DLL
- \SystemRoot\System32\cdd.dll
- \SystemRoot\system32\drivers\WudfPf.sys
- \SystemRoot\system32\drivers\luafv.sys
- \SystemRoot\system32\drivers\storqosflt.sys
- \SystemRoot\system32\DRIVERS\avgntflt.sys
- \SystemRoot\system32\DRIVERS\WUDFRd.sys
- \SystemRoot\System32\drivers\rdpvideominiport.sys
- \SystemRoot\System32\drivers\rdpdr.sys
- \SystemRoot\system32\DRIVERS\bowser.sys
- \SystemRoot\system32\DRIVERS\mrxsmb.sys
- \SystemRoot\system32\DRIVERS\mrxsmb20.sys
- \SystemRoot\system32\drivers\mmcss.sys
- \??\C:\Program Files\Sandboxie\SbieDrv.sys
- \SystemRoot\system32\DRIVERS\vmnetbridge.sys
- \SystemRoot\System32\DRIVERS\wanarp.sys
- \SystemRoot\system32\drivers\mslldp.sys
- \SystemRoot\system32\drivers\rspndr.sys
- \SystemRoot\system32\drivers\lltdio.sys
- \SystemRoot\system32\drivers\ndisuio.sys
- \SystemRoot\system32\DRIVERS\nwifi.sys
- \SystemRoot\system32\drivers\HTTP.sys
- \SystemRoot\System32\drivers\condrv.sys
- \SystemRoot\System32\drivers\mpsdrv.sys
- \??\C:\WINDOWS\system32\drivers\vmx86.sys
- \??\C:\WINDOWS\system32\drivers\hcmon.sys
- \??\C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys
- \SystemRoot\system32\DRIVERS\avnetflt.sys
- \SystemRoot\System32\DRIVERS\srvnet.sys
- \SystemRoot\System32\DRIVERS\srv2.sys
- \??\C:\WINDOWS\system32\drivers\vmnetuserif.sys
- \SystemRoot\system32\drivers\npf.sys
- \SystemRoot\system32\drivers\peauth.sys
- \SystemRoot\system32\DRIVERS\mrxsmb10.sys
- \SystemRoot\system32\drivers\Ndu.sys
- \SystemRoot\System32\drivers\tcpipreg.sys
- \SystemRoot\system32\drivers\mqac.sys
- \SystemRoot\System32\DRIVERS\srv.sys
- \??\C:\WINDOWS\system32\Drivers\iqvw64e.sys
- \SystemRoot\System32\drivers\tunnel.sys
- \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- \SystemRoot\system32\drivers\LGVirHid.sys
- \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
- \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
- ----------- End -----------
- Done!
- Scan started
- Database versions:
- main: v2016.04.15.02
- rootkit: v2016.04.09.01
- <<<2>>>
- Physical Sector Size: 512
- Drive: 1, DevicePointer: 0xffffe0015409f310, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
- --------- Disk Stack ------
- DevicePointer: 0xffffe00154000b10, DeviceName: Unknown, DriverName: \Driver\partmgr\
- DevicePointer: 0xffffe0015409f310, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
- DevicePointer: 0xffffe00153ffdc50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
- DevicePointer: 0xffffe00153df9060, DeviceName: \Device\0000003f\, DriverName: \Driver\storahci\
- ------------ End ----------
- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
- Upper DeviceData: 0x0, 0x0, 0x0
- Lower DeviceData: 0x0, 0x0, 0x0
- <<<3>>>
- Volume: C:
- File system type: NTFS
- SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
- <<<2>>>
- <<<3>>>
- Volume: C:
- File system type: NTFS
- SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
- Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
- Done!
- Physical Sector Size: 512
- Drive: 0, DevicePointer: 0xffffe001540d1310, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
- --------- Disk Stack ------
- DevicePointer: 0xffffe00153ff5b10, DeviceName: Unknown, DriverName: \Driver\partmgr\
- DevicePointer: 0xffffe001540d1310, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
- DevicePointer: 0xffffe00153ff6ab0, DeviceName: Unknown, DriverName: \Driver\iaStorF\
- DevicePointer: 0xffffe00153dfb060, DeviceName: \Device\0000003e\, DriverName: \Driver\storahci\
- ------------ End ----------
- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
- Upper DeviceData: 0x0, 0x0, 0x0
- Lower DeviceData: 0x0, 0x0, 0x0
- Drive 0
- Scanning MBR on drive 0...
- Inspecting partition table:
- MBR Signature: 55AA
- Disk Signature: EE53509A
- Partition information:
- Partition 0 type is Primary (0x7)
- Partition is ACTIVE.
- Partition starts at LBA: 2048 Numsec = 4294963200
- Partition is bootable
- Partition file system is NTFS
- Partition 1 type is Empty (0x0)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 0 Numsec = 0
- Partition is not bootable
- Partition 2 type is Empty (0x0)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 0 Numsec = 0
- Partition is not bootable
- Partition 3 type is Empty (0x0)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 0 Numsec = 0
- Partition is not bootable
- Disk Size: 4000787030016 bytes
- Sector size: 512 bytes
- Done!
- Drive 1
- This is a System drive
- Scanning MBR on drive 1...
- Inspecting partition table:
- MBR Signature: 55AA
- Disk Signature: EE535082
- Partition information:
- Partition 0 type is Primary (0x7)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 2048 Numsec = 499191808
- Partition is not bootable
- Partition file system is NTFS
- Partition 1 type is Other (0x27)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 499193856 Numsec = 921600
- Partition is not bootable
- Partition file system is NTFS
- Partition 2 type is Empty (0x0)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 0 Numsec = 0
- Partition is not bootable
- Partition 3 type is Empty (0x0)
- Partition is NOT ACTIVE.
- Partition starts at LBA: 0 Numsec = 0
- Partition is not bootable
- Disk Size: 256060514304 bytes
- Sector size: 512 bytes
- Done!
- File "C:\Users\Being\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768)
- File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768)
- Scan finished
- =======================================
- Removal queue found; removal started
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-0-2048-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-1-499193856-i.mbam...
- Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
- Removal finished
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement