

GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-03-25 23:51:06
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 FUJITSU_MHZ2160BH_G2 rev.00000009 149,05GB
Running: v1t3zlzp.exe; Driver: C:\Users\martula\AppData\Local\Temp\pxliifow.sys
---- System - GMER 2.1 ----
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwAddBootEntry [0x9027FACC]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwAdjustPrivilegesToken [0xB213FE36]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwAlpcConnectPort [0xB2142074]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwAlpcCreatePort [0xB21422EE]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwAlpcSendWaitReceivePort [0xB2142564]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x902805AA]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwClose [0xB214074A]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwConnectPort [0xB214157E]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateEvent [0xB2141AC8]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateEventPair [0x9028C6DE]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateFile [0xB2140A26]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x9028C878]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateMutant [0xB21419AE]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateNamedPipeFile [0xB213FA24]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreatePort [0xB2141882]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateProcess [0xDF0F5B60]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateProcessEx [0xDF0F5E28]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateSection [0xB213FBCC]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateSemaphore [0xB2141BE8]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateThread [0xB21403D0]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateTimer [0x9028C832]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateWaitablePort [0xB2141918]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwDebugActiveProcess [0xB21432D6]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x9027FB32]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwDeviceIoControlFile [0xB2140EA8]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwDuplicateObject [0xB21444E4]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwFsControlFile [0xB2140CB6]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwLoadDriver [0xB21433C8]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwMapViewOfSection [0xB2143B30]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x9027FB98]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x90284FDA]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x90281EDE]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenEvent [0xB2141B5E]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenEventPair [0x9028C700]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenFile [0xB21407CC]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x9028C89C]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenMutant [0xB2141A3E]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenProcess [0xB2140074]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenSection [0xB21438CA]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenSemaphore [0xB2141C7E]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwOpenThread [0xB213FF64]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenTimer [0x9028C856]
SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x903A92AA]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwQueryDirectoryObject [0xB2142868]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwQueryObject [0x90281CF4]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwQuerySection [0xB2143E6A]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwQueueApcThread [0xB214375C]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwReplaceKey [0xB213E6DE]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwReplyPort [0xB2141FE2]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwReplyWaitReceivePort [0xB2141EA8]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwRequestWaitReplyPort [0xB2143070]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwRestoreKey [0xB213EA56]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwResumeThread [0xB2144386]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSaveKey [0xB213E676]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSecureConnectPort [0xB21412C4]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x9027FBFE]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetBootOptions [0x9027FC64]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSetContextThread [0xB21405EC]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSetInformationToken [0xB214290A]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSetSecurityObject [0xB2143566]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSetSystemInformation [0xB2143FBA]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x9027F98A]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwShutdownSystem [0x9027F918]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSuspendProcess [0xB21440AC]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSuspendThread [0xB21441E6]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwSystemDebugControl [0xB21431FA]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwTerminateProcess [0xDF0F575E]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwTerminateThread [0xB2140170]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwUnmapViewOfSection [0xB2143D0E]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwVdmControl [0x9027FCCA]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwWriteVirtualMemory [0xB2140306]
SSDT \SystemRoot\system32\DRIVERS\1472345drv.sys ZwCreateThreadEx [0xB21404CE]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateUserProcess [0xDF0F6124]
INT 0x62 ? 871C4F00
INT 0x82 ? 871C4F00
INT 0x92 ? 85A42CB8
INT 0x92 ? 85A42CB8
INT 0x92 ? 85A42CB8
INT 0x92 ? 85A42CB8
INT 0x92 ? 871C4F00
INT 0x92 ? 871C4F00
INT 0x92 ? 871C4F00
INT 0x92 ? 85A42CB8
INT 0xA2 ? 871C4F00
INT 0xB2 ? 871C4F00
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 82CE0758 4 Bytes [CC, FA, 27, 90] {INT 3 ; CLI ; DAA ; NOP }
.text ntkrnlpa.exe!KeSetEvent + 119 82CE0764 4 Bytes [36, FE, 13, B2]
.text ntkrnlpa.exe!KeSetEvent + 13D 82CE0788 8 Bytes [74, 20, 14, B2, EE, 22, 14, ...] {JZ 0x22; ADC AL, 0xb2; OUT DX, AL; AND DL, [EDX+ESI*4]}
.text ntkrnlpa.exe!KeSetEvent + 181 82CE07CC 4 Bytes [64, 25, 14, B2]
.text ntkrnlpa.exe!KeSetEvent + 191 82CE07DC 4 Bytes [AA, 05, 28, 90]
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82E6E00F 4 Bytes CALL 902825C5 \??\C:\Windows\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82E71C83 4 Bytes CALL 902825DB \??\C:\Windows\system32\drivers\aswSnx.sys
.text sptd.sys 8329E000 32 Bytes [EC, 85, C0, 82, 60, 4F, C0, ...]
.text sptd.sys 8329E024 4 Bytes [D2, A3, 3C, 83]
.text sptd.sys 8329E02C 116 Bytes [97, 4D, D9, 82, 08, 95, C7, ...]
.text sptd.sys 8329E0A1 211 Bytes [9B, C7, 82, E3, 0D, CA, 82, ...]
.text sptd.sys 8329E175 36 Bytes [A9, CD, 82, 80, A9, CD, 82, ...]
.text ...
.sptd2 C:\Windows\System32\Drivers\sptd.sys entry point in ".sptd2" section [0x833780AD]
? C:\Windows\System32\Drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
.xreloc C:\Windows\System32\drivers\sfsync04.sys unknown last section [0x83849000, 0xC5E, 0x40000040]
.sfreloc˙˙˙˙sfsync03unknown last section [0x838CD000, 0xA20, 0x40000040] C:\Windows\System32\drivers\sfsync03.sys unknown last section [0x838CD000, 0xA20, 0x40000040]
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xB2AE8300, 0x3AF78, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xB2B2D300, 0x1BCE, 0xE8000020]
? system32\DRIVERS\1472345drv.sys System nie może odnaleźć określonej ścieżki. !
? system32\DRIVERS\63629863.sys System nie może odnaleźć określonej ścieżki. !
? system32\drivers\pctDS.sys System nie może odnaleźć określonej ścieżki. !
? system32\drivers\pctEFA.sys System nie może odnaleźć określonej ścieżki. !
? system32\drivers\PCTCore.sys System nie może odnaleźć określonej ścieżki. !
? C:\Windows\System32\drivers\pctgntdi.sys Nie można odnaleźć określonego pliku. !
? \Device\Harddisk0\Partition2\Windows\system32\drivers\PctWfpFilter.sys System nie może odnaleźć określonej ścieżki. !
? System32\Drivers\PCTBD.sys System nie może odnaleźć określonej ścieżki. !
? \Program Files\DAEMON Tools Lite\Engine.dll System nie może odnaleźć określonej ścieżki. !
? \Program Files\DAEMON Tools Lite\daemon.dll System nie może odnaleźć określonej ścieżki. !
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[356] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[568] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\csrss.exe[596] KERNEL32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\wininit.exe[636] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\csrss.exe[648] KERNEL32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text ...
.text C:\Windows\RtHDVCpl.exe[1344] kernel32.dll!LoadLibraryExW + 173 764D93DF 4 Bytes JMP 01CE000A
.text C:\Windows\RtHDVCpl.exe[1344] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\IoctlSvc.exe[1356] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1504] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1604] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text ...
.text C:\Windows\system32\Dwm.exe[3028] kernel32.dll!LoadLibraryExW + 173 764D93DF 4 Bytes JMP 0199000A
.text C:\Windows\system32\Dwm.exe[3028] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[3056] kernel32.dll!LoadLibraryExW + 173 764D93DF 4 Bytes JMP 01AC000A
.text C:\Windows\system32\taskeng.exe[3056] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Windows\Explorer.EXE[3152] kernel32.dll!LoadLibraryExW + 173 764D93DF 4 Bytes JMP 02AB000A
.text C:\Windows\Explorer.EXE[3152] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Users\martula\Downloads\v1t3zlzp.exe[3776] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
.text C:\Program Files\Alwil Software\Avast5\AvastUI.exe[3880] kernel32.dll!GetBinaryTypeW + 70 76502447 1 Byte [62]
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\system32\services.exe[684] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 001B0002
IAT C:\Windows\system32\services.exe[684] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 001B0000
---- Devices - GMER 2.1 ----
Device \FileSystem\Ntfs \Ntfs 85A4A1E8
Device \Driver\usbuhci \Device\USBPDO-0 871C01E8
Device \Driver\usbuhci \Device\USBPDO-1 871C01E8
Device \Driver\usbuhci \Device\USBPDO-2 871C01E8
Device \Driver\usbehci \Device\USBPDO-3 871C61E8
Device \Driver\usbuhci \Device\USBPDO-4 871C01E8
Device \Driver\tdx \Device\Tcp pctgntdi.sys
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.sys
Device \Driver\PCI_PNP5733 \Device\00000062 sptd.sys
Device \Driver\PCI_PNP5733 \Device\00000062 sptd.sys
Device \Driver\usbuhci \Device\USBPDO-5 871C01E8
Device \Driver\usbuhci \Device\USBPDO-6 871C01E8
Device \Driver\usbehci \Device\USBPDO-7 871C61E8
Device \Driver\cdrom \Device\CdRom0 871B11E8
Device \Driver\netbt \Device\NetBT_Tcpip_{D1292E95-4071-4858-BC72-0F04E305B61E} 87FCF430
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85A471E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 86A07560
Device \Driver\atapi \Device\Ide\IdePort0 85A471E8
Device \Driver\atapi \Device\Ide\IdePort0 86A07560
Device \Driver\atapi \Device\Ide\IdePort1 85A471E8
Device \Driver\atapi \Device\Ide\IdePort1 86A07560
Device \Driver\atapi \Device\Ide\IdePort2 85A471E8
Device \Driver\atapi \Device\Ide\IdePort2 86A07560
Device \Driver\atapi \Device\Ide\IdePort3 85A471E8
Device \Driver\atapi \Device\Ide\IdePort3 86A07560
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 85A471E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 86A07560
Device \Driver\msahci \Device\Ide\PciIde0Channel0 85A481E8
Device \Driver\msahci \Device\Ide\PciIde0Channel1 85A481E8
Device \Driver\msahci \Device\Ide\PciIde0Channel4 85A481E8
Device \Driver\msahci \Device\Ide\PciIde0Channel5 85A481E8
Device \Driver\tdx \Device\RawIp6 pctgntdi.sys
Device \Driver\cdrom \Device\CdRom2 871B11E8
Device \Driver\tdx \Device\Tcp6 pctgntdi.sys
Device \Driver\netbt \Device\NetBt_Wins_Export 87FCF430
Device \Driver\Smb \Device\NetbiosSmb 87FB31E8
Device \Driver\tdx \Device\Tdx pctgntdi.sys
Device \Driver\iScsiPrt \Device\RaidPort0 8740E1E8
Device \Driver\tdx \Device\Udp pctgntdi.sys
AttachedDevice \Driver\tdx \Device\Udp aswTdi.sys
Device \Driver\tdx \Device\RawIp pctgntdi.sys
Device \Driver\usbuhci \Device\USBFDO-0 871C01E8
Device \Driver\usbuhci \Device\USBFDO-1 871C01E8
Device \Driver\tdx \Device\Udp6 pctgntdi.sys
Device \Driver\usbuhci \Device\USBFDO-2 871C01E8
Device \Driver\usbehci \Device\USBFDO-3 871C61E8
Device \Driver\usbuhci \Device\USBFDO-4 871C01E8
Device \Driver\usbuhci \Device\USBFDO-5 871C01E8
Device \Driver\netbt \Device\NetBT_Tcpip_{E6AA8429-10E9-409A-905C-C4EFC07FEB64} 87FCF430
Device \Driver\usbuhci \Device\USBFDO-6 871C01E8
Device \Driver\usbehci \Device\USBFDO-7 871C61E8
Device \Driver\alruasiz \Device\Scsi\alruasiz1 871A11E8
Device \Driver\alruasiz \Device\Scsi\alruasiz1 sfsync03.sys
Device \Driver\alruasiz \Device\Scsi\alruasiz1Port6Path0Target0Lun0 871A11E8
Device \Driver\alruasiz \Device\Scsi\alruasiz1Port6Path0Target0Lun0 sfsync03.sys
Device \FileSystem\cdfs \Cdfs 85D0E388
---- Trace I/O - GMER 2.1 ----
Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86a07560]<< 86a07560
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86a0aac8] 86a0aac8
Trace 3 CLASSPNP.SYS[8afc48b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86452b70] 86452b70
Trace \Driver\atapi[0x86441b78] -> IRP_MJ_CREATE -> 0x85a471e8 85a471e8
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x4B 0xAC 0x01 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA3 0x54 0x2C 0xF0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xEF 0x0E 0x88 0x15 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF3 0x63 0xC0 0xBB ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9B 0x4B 0xAC 0x01 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC1 0x80 0x83 0xB0 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x4F 0xE0 0x11 0x94 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x1B 0xED 0x92 0xB5 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA3 0x54 0x2C 0xF0 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xEF 0x0E 0x88 0x15 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF3 0x63 0xC0 0xBB ...
---- Files - GMER 2.1 ----
File C:\Users\martula\Music\BearShare\Dj Fritzy, Dee Dee, Styles 'N' Breeze, Karaja, Faithless, Kate Ryan, Dj Red 5, Dj Milano, Cheeky Trax, Public Domain, Paul Van Dyke, Milk Inc, Dj Tiesto, Sylver, Dirt Devils, Dj Mark, Dj Puddy, Eiffel 65, Flip 'N' Fill, Lasgo, ATB, Mauro Picotto, Dana Ray\Unknown Album 0 bytes
File 43899755 bytes
---- EOF - GMER 2.1 ----
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 17 gości