Beruflich Dokumente
Kultur Dokumente
Account is Administrative
Scan started
Database versions:
main: v2020.01.04.04
rootkit: v2020.01.04.03
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffe60f9925d0a0, DeviceName: \Device\Harddisk0\DR0\,
DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffe60f991b18f0, DeviceName: Unknown, DriverName:
\Driver\partmgr\
DevicePointer: 0xffffe60f9925d0a0, DeviceName: \Device\Harddisk0\DR0\,
DriverName: \Driver\disk\
DevicePointer: 0xffffe60f9906cde0, DeviceName: Unknown, DriverName:
\Driver\EhStorClass\
DevicePointer: 0xffffe60f938fc060, DeviceName: \Device\00000044\, DriverName:
\Driver\stornvme\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096
bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096
bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 45263FB6
Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xffffe60f9925e060, DeviceName: \Device\Harddisk1\DR1\,
DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffe60f9906f8d0, DeviceName: Unknown, DriverName:
\Driver\partmgr\
DevicePointer: 0xffffe60f9925e060, DeviceName: \Device\Harddisk1\DR1\,
DriverName: \Driver\disk\
DevicePointer: 0xffffe60f9906e8d0, DeviceName: Unknown, DriverName:
\Driver\hpdskflt\
DevicePointer: 0xffffe60f938fb260, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffe60f961020a0, DeviceName: \Device\00000045\, DriverName:
\Driver\iaStorAC\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: E7EC73A9
Done!
File "C:\ProgramData\Microsoft\Network\Downloader\qmgr.db" is sparse (flags =
32768)
File "C:\Users\Atif Khan\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags
= 32768)
File
"C:\Windows\System32\config\SYSTEMPROFILE\AppData\Local\DataSharing\Storage\DSToken
DB2.dat" is sparse (flags = 32768)
Infected: HKLM\SOFTWARE\MICROSOFT\bestavicampaign563 --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\campaign9961 --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\multitimercampaign84170 --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\Speedycar --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\TechnologyDesktopnew --> [Adware.ICLoader]
Scan finished
Creating System Restore point...
Cleaning up...
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
Account is Administrative
=======================================