Kód: Vybrat vše
MBRScan v1.1.1
OS : Windows 7 Service Pack 1 (32 bit)
PROCESSOR : x86 Family 6 Model 28 Stepping 10, GenuineIntel
BOOT : Normal Boot
DATE : 2014/02/11 (ISO 8601) at 15:12:00
________________________________________________________________________________
DISK : Device\Harddisk0\DR0 __WDC WD3200BPVT-80ZEST0 (01.01A01)
BUS_TYPE : (0x0B) S-ATA
USE_PIO : NO
MAX_TRANSFER : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________
Device\Harddisk0\DR0 298.1 Go [Fixed] ==> Unknown MBR Code
MBR_MD5 : 1731404A7F86875FAC0045964D75999E
MBR_SHA1 : C5681D5D51560D0AB83564DDA12BA7D2F7EE0240
Device\Harddisk0\Partition1 100.0 Go 0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2 15.00 Go 0x0C FAT32 [LBA]
Device\Harddisk0\Partition3 134.2 Go 0x07 NTFS / HPFS
Device\Harddisk0\Partition4 48.84 Go 0x83 Linux
________________________________________________________________________________
############################### Additional scan ################################
DRIVER : C:\Windows\System32\Drivers\dump_dumpata.sys => Invisible on the disk
ADDRESS : 0x8EA2F000
SIZE : 44.0 Ko
DRIVER : C:\Windows\System32\Drivers\dump_msahci.sys => Invisible on the disk
ADDRESS : 0x8F3F6000
SIZE : 40.0 Ko
SystemStartOptions :
________________________________________________________________________________
_______MBR \Device\Harddisk0\DR0
0x00000000 33 C0 FA 8E D8 8E D0 BC 00 7C 89 E6 06 57 8E C0 3Àú.Ø.м.|.æ.W.À
0x00000010 FB FC BF 00 06 B9 00 01 F3 A5 EA 1F 06 00 00 52 ûü¿..¹..ó¥ê....R
0x00000020 52 B4 41 BB AA 55 31 C9 30 F6 F9 CD 13 72 13 81 R´A»ªU1É0öùÍ.r..
0x00000030 FB 55 AA 75 0D D1 E9 73 09 66 C7 06 8D 06 B4 42 ûUªu.Ñés.fÇ...´B
0x00000040 EB 15 5A B4 08 CD 13 83 E1 3F 51 0F B6 C6 40 F7 ë.Z´.Í..á?Q.¶Æ@÷
0x00000050 E1 52 50 66 31 C0 66 99 E8 66 00 E8 21 01 4D 69 áRPf1Àf.èf.è!.Mi
0x00000060 73 73 69 6E 67 20 6F 70 65 72 61 74 69 6E 67 20 ssing operating
0x00000070 73 79 73 74 65 6D 2E 0D 0A 66 60 66 31 D2 BB 00 system...f`f1Ò».
0x00000080 7C 66 52 66 50 06 53 6A 01 6A 10 89 E6 66 F7 36 |fRfP.Sj.j..æf÷6
0x00000090 F4 7B C0 E4 06 88 E1 88 C5 92 F6 36 F8 7B 88 C6 ô{Àä..á.Å.ö6ø{.Æ
0x000000A0 08 E1 41 B8 01 02 8A 16 FA 7B CD 13 8D 64 10 66 .áA¸....ú{Í..d.f
0x000000B0 61 C3 E8 C4 FF BE BE 7D BF BE 07 B9 20 00 F3 A5 aÃèÄ.¾¾}¿¾.¹ .ó¥
0x000000C0 C3 66 60 89 E5 BB BE 07 B9 04 00 31 C0 53 51 F6 Ãf`.廾.¹..1ÀSQö
0x000000D0 07 80 74 03 40 89 DE 83 C3 10 E2 F3 48 74 5B 79 ..t.@.Þ.Ã.âóHt[y
0x000000E0 39 59 5B 8A 47 04 3C 0F 74 06 24 7F 3C 05 75 22 9Y[.G.<.t.$.<.u"
0x000000F0 66 8B 47 08 66 8B 56 14 66 01 D0 66 21 D2 75 03 f.G.f.V.f.Ðf!Òu.
0x00000100 66 89 C2 E8 AC FF 72 03 E8 B6 FF 66 8B 46 1C E8 f.Âè¬.r.è¶.f.F.è
0x00000110 A0 FF 83 C3 10 E2 CC 66 61 C3 E8 62 00 4D 75 6C ...Ã.âÌfaÃèb.Mul
0x00000120 74 69 70 6C 65 20 61 63 74 69 76 65 20 70 61 72 tiple active par
0x00000130 74 69 74 69 6F 6E 73 2E 0D 0A 66 8B 44 08 66 03 titions...f.D.f.
0x00000140 46 1C 66 89 44 08 E8 30 FF 72 13 81 3E FE 7D 55 F.f.D.è0.r..>þ}U
0x00000150 AA 0F 85 06 FF BC FA 7B 5A 5F 07 FA FF E4 E8 1E ª....¼ú{Z_.ú.äè.
0x00000160 00 4F 70 65 72 61 74 69 6E 67 20 73 79 73 74 65 .Operating syste
0x00000170 6D 20 6C 6F 61 64 20 65 72 72 6F 72 2E 0D 0A 5E m load error...^
0x00000180 AC B4 0E 8A 3E 62 04 B3 07 CD 10 3C 0A 75 F1 CD ¬´..>b.³.Í.<.uñÍ
0x00000190 18 F4 EB FD 00 00 00 00 00 00 00 00 00 00 00 00 .ôëý............
0x000001A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000001B0 00 00 00 00 00 00 00 00 18 47 24 E2 00 00 80 20 .........G$â...
0x000001C0 21 00 07 FE FF FF 00 08 00 00 00 00 80 0C 00 FE !..þ...........þ
0x000001D0 FF FF 0C FE FF FF 00 08 80 0C 00 00 E0 01 00 FE ...þ........à..þ
0x000001E0 FF FF 0F FE FF FF 65 2C 60 0E 4B BE E2 16 00 00 ...þ..e,`.K¾â...
0x000001F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA ..............Uª
__________________________16_BIT_ASM_CODE
0x0000 33c0 XOR AX, AX
0x0002 fa CLI
0x0003 8ed8 MOV DS, AX
0x0005 8ed0 MOV SS, AX
0x0007 bc 007c MOV SP, 0x7c00
0x000A 89e6 MOV SI, SP
0x000C 06 PUSH ES
0x000D 57 PUSH DI
0x000E 8ec0 MOV ES, AX
0x0010 fb STI
0x0011 fc CLD
0x0012 bf 0006 MOV DI, 0x600
0x0015 b9 0001 MOV CX, 0x100
0x0018 f3 a5 REP MOVSW
0x001A ea 1f06 0000 JMP FAR 0x0:0x61f
0x001F 52 PUSH DX
0x0020 52 PUSH DX
0x0021 b4 41 MOV AH, 0x41
0x0023 bb aa55 MOV BX, 0x55aa
0x0026 31c9 XOR CX, CX
0x0028 30f6 XOR DH, DH
0x002A f9 STC
0x002B cd 13 INT 0x13
0x002D 72 13 JB 0x42
0x002F 81fb 55aa CMP BX, 0xaa55
0x0033 75 0d JNZ 0x42
0x0035 d1e9 SHR CX, 0x1
0x0037 73 09 JAE 0x42
0x0039 66 c706 8d06 b442eb15MOV DWORD [0x68d], 0x15eb42b4
0x0042 5a POP DX
0x0043 b4 08 MOV AH, 0x8
0x0045 cd 13 INT 0x13
0x0047 83e1 3f AND CX, 0x3f
0x004A 51 PUSH CX
0x004B 0fb6c6 MOVZX AX, DH
0x004E 40 INC AX
0x004F f7e1 MUL CX
0x0051 52 PUSH DX
0x0052 50 PUSH AX
0x0053 66 31c0 XOR EAX, EAX
0x0056 66 99 CDQ
0x0058 e8 6600 CALL 0xc1
0x005B e8 2101 CALL 0x17f
0x005E 4d DEC BP
0x005F 6973 73 696e IMUL SI, [BP+DI+0x73], 0x6e69
0x0064 67 206f 70 AND [EDI+0x70], CH
0x0068 65 DB 0x65
0x0068 65 72 61 JB 0xcc
0x006B 74 69 JZ 0xd6
0x006D 6e OUTSB
0x006E 67 2073 79 AND [EBX+0x79], DH
0x0072 73 74 JAE 0xe8
0x0074 65 6d INS WORD GS:[DI], DX
0x0076 2e DB 0x2e
0x0076 2e 0d 0a66 OR AX, 0x660a
0x007A 60 PUSHA
0x007B 66 31d2 XOR EDX, EDX
0x007E bb 007c MOV BX, 0x7c00
0x0081 66 52 PUSH EDX
0x0083 66 50 PUSH EAX
0x0085 06 PUSH ES
0x0086 53 PUSH BX
0x0087 6a 01 PUSH 0x1
0x0089 6a 10 PUSH 0x10
0x008B 89e6 MOV SI, SP
0x008D 66 f736 f47b DIV DWORD [0x7bf4]
0x0092 c0e4 06 SHL AH, 0x6
0x0095 88e1 MOV CL, AH
0x0097 88c5 MOV CH, AL
0x0099 92 XCHG DX, AX
0x009A f636 f87b DIV BYTE [0x7bf8]
0x009E 88c6 MOV DH, AL
0x00A0 08e1 OR CL, AH
0x00A2 41 INC CX
0x00A3 b8 0102 MOV AX, 0x201
0x00A6 8a16 fa7b MOV DL, [0x7bfa]
0x00AA cd 13 INT 0x13
0x00AC 8d64 10 LEA SP, [SI+0x10]
0x00AF 66 61 POPAD
0x00B1 c3 RET
0x00B2 e8 c4ff CALL 0x79
0x00B5 be be7d MOV SI, 0x7dbe
0x00B8 bf be07 MOV DI, 0x7be
0x00BB b9 2000 MOV CX, 0x20
0x00BE f3 a5 REP MOVSW
0x00C0 c3 RET
0x00C1 66 60 PUSHAD
0x00C3 89e5 MOV BP, SP
0x00C5 bb be07 MOV BX, 0x7be
0x00C8 b9 0400 MOV CX, 0x4
0x00CB 31c0 XOR AX, AX
0x00CD 53 PUSH BX
0x00CE 51 PUSH CX
0x00CF f607 80 TEST BYTE [BX], 0x80
0x00D2 74 03 JZ 0xd7
0x00D4 40 INC AX
0x00D5 89de MOV SI, BX
0x00D7 83c3 10 ADD BX, 0x10
0x00DA e2 f3 LOOP 0xcf
0x00DC 48 DEC AX
0x00DD 74 5b JZ 0x13a
0x00DF 79 39 JNS 0x11a
0x00E1 59 POP CX
0x00E2 5b POP BX
0x00E3 8a47 04 MOV AL, [BX+0x4]
0x00E6 3c 0f CMP AL, 0xf
0x00E8 74 06 JZ 0xf0
0x00EA 24 7f AND AL, 0x7f
0x00EC 3c 05 CMP AL, 0x5
0x00EE 75 22 JNZ 0x112
0x00F0 66 8b47 08 MOV EAX, [BX+0x8]
0x00F4 66 8b56 14 MOV EDX, [BP+0x14]
0x00F8 66 01d0 ADD EAX, EDX
0x00FB 66 21d2 AND EDX, EDX
0x00FE 75 03 JNZ 0x103
0x0100 66 89c2 MOV EDX, EAX
0x0103 e8 acff CALL 0xb2
0x0106 72 03 JB 0x10b
0x0108 e8 b6ff CALL 0xc1
0x010B 66 8b46 1c MOV EAX, [BP+0x1c]
0x010F e8 a0ff CALL 0xb2
0x0112 83c3 10 ADD BX, 0x10
0x0115 e2 cc LOOP 0xe3
0x0117 66 61 POPAD
0x0119 c3 RET
0x011A e8 6200 CALL 0x17f
0x011D 4d DEC BP
0x011E 75 6c JNZ 0x18c
0x0120 74 69 JZ 0x18b
0x0122 70 6c JO 0x190
0x0124 65 2061 63 AND GS:[BX+DI+0x63], AH
0x0128 74 69 JZ 0x193
0x012A 76 65 JBE 0x191
0x012C 2070 61 AND [BX+SI+0x61], DH
0x012F 72 74 JB 0x1a5
0x0131 6974 69 6f6e IMUL SI, [SI+0x69], 0x6e6f
0x0136 73 2e JAE 0x166
0x0138 0d 0a66 OR AX, 0x660a
0x013B 8b44 08 MOV AX, [SI+0x8]
0x013E 66 0346 1c ADD EAX, [BP+0x1c]
0x0142 66 8944 08 MOV [SI+0x8], EAX
0x0146 e8 30ff CALL 0x79
0x0149 72 13 JB 0x15e
0x014B 813e fe7d 55aa CMP WORD [0x7dfe], 0xaa55
0x0151 0f85 06ff JNZ 0x5b
0x0155 bc fa7b MOV SP, 0x7bfa
0x0158 5a POP DX
0x0159 5f POP DI
0x015A 07 POP ES
0x015B fa CLI
0x015C ffe4 JMP SP
0x015E e8 1e00 CALL 0x17f
0x0161 4f DEC DI
0x0162 70 65 JO 0x1c9
0x0164 72 61 JB 0x1c7
0x0166 74 69 JZ 0x1d1
0x0168 6e OUTSB
0x0169 67 2073 79 AND [EBX+0x79], DH
0x016D 73 74 JAE 0x1e3
0x016F 65 6d INS WORD GS:[DI], DX
0x0171 206c 6f AND [SI+0x6f], CH
0x0174 61 POPA
0x0175 64 2065 72 AND FS:[DI+0x72], AH
0x0179 72 6f JB 0x1ea
0x017B 72 2e JB 0x1ab
0x017D 0d 0a5e OR AX, 0x5e0a
0x0180 ac LODSB
0x0181 b4 0e MOV AH, 0xe
0x0183 8a3e 6204 MOV BH, [0x462]
0x0187 b3 07 MOV BL, 0x7
0x0189 cd 10 INT 0x10
0x018B 3c 0a CMP AL, 0xa
0x018D 75 f1 JNZ 0x180
0x018F cd 18 INT 0x18
0x0191 f4 HLT
0x0192 eb fd JMP 0x191
0x0194 0000 ADD [BX+SI], AL
0x0196 0000 ADD [BX+SI], AL
0x0198 0000 ADD [BX+SI], AL
0x019A 0000 ADD [BX+SI], AL
0x019C 0000 ADD [BX+SI], AL
0x019E 0000 ADD [BX+SI], AL
0x01A0 0000 ADD [BX+SI], AL
0x01A2 0000 ADD [BX+SI], AL
0x01A4 0000 ADD [BX+SI], AL
0x01A6 0000 ADD [BX+SI], AL
0x01A8 0000 ADD [BX+SI], AL
0x01AA 0000 ADD [BX+SI], AL
0x01AC 0000 ADD [BX+SI], AL
0x01AE 0000 ADD [BX+SI], AL
0x01B0 0000 ADD [BX+SI], AL
0x01B2 0000 ADD [BX+SI], AL
0x01B4 0000 ADD [BX+SI], AL
0x01B6 0000 ADD [BX+SI], AL
0x01B8 1847 24 SBB [BX+0x24], AL
0x01BB e2 00 LOOP 0x1bd
0x01BD 0080 2021 ADD [BX+SI+0x2120], AL
0x01C1 0007 ADD [BX], AL
0x01C3 fe DB 0xfe
0x01C4 ff DB 0xff
0x01C5 ff00 INC WORD [BX+SI]
0x01C7 0800 OR [BX+SI], AL
0x01C9 0000 ADD [BX+SI], AL
0x01CB 0080 0c00 ADD [BX+SI+0xc], AL
0x01CF fe DB 0xfe
0x01D0 ff DB 0xff
0x01D1 ff0c DEC WORD [SI]
0x01D3 fe DB 0xfe
0x01D4 ff DB 0xff
0x01D5 ff00 INC WORD [BX+SI]
0x01D7 0880 0c00 OR [BX+SI+0xc], AL
0x01DB 00e0 ADD AL, AH
0x01DD 0100 ADD [BX+SI], AX
0x01DF fe DB 0xfe
0x01E0 ff DB 0xff
0x01E1 ff0f DEC WORD [BX]
0x01E3 fe DB 0xfe
0x01E4 ff DB 0xff
0x01E5 ff65 2c JMP [DI+0x2c]
0x01E8 60 PUSHA
0x01E9 0e PUSH CS
0x01EA 4b DEC BX
0x01EB be e216 MOV SI, 0x16e2
0x01EE 0000 ADD [BX+SI], AL
0x01F0 0000 ADD [BX+SI], AL
0x01F2 0000 ADD [BX+SI], AL
0x01F4 0000 ADD [BX+SI], AL
0x01F6 0000 ADD [BX+SI], AL
0x01F8 0000 ADD [BX+SI], AL
0x01FA 0000 ADD [BX+SI], AL
0x01FC 0000 ADD [BX+SI], AL
0x01FE 55 PUSH BP
0x01FF aa STOSB