GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-12-16 15:52:17
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST1500DL rev.CC32 1397,27GB
Running: gmer.exe; Driver: C:\Users\PAWE~1\AppData\Local\Temp\axddypoc.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                          fffff80003bec000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575                                                          fffff80003bec02f 18 bytes [00, 00, 00, 00, 00, 00, 00, ...]

---- User code sections - GMER 2.1 ----

.text     C:\Windows\SysWOW64\rundll32.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                              0000000075621465 2 bytes [62, 75]
.text     C:\Windows\SysWOW64\rundll32.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                             00000000756214bb 2 bytes [62, 75]
.text     ...                                                                                                                         * 2
.text     C:\Users\Paweł\AppData\Local\Lollipop\lollipop_12161133.exe[1388] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000075621465 2 bytes [62, 75]
.text     C:\Users\Paweł\AppData\Local\Lollipop\lollipop_12161133.exe[1388] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  00000000756214bb 2 bytes [62, 75]
.text     ...                                                                                                                         * 2
.text     C:\Program Files (x86)\AVG\AVG2014\avgui.exe[1080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000075621465 2 bytes [62, 75]
.text     C:\Program Files (x86)\AVG\AVG2014\avgui.exe[1080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                 00000000756214bb 2 bytes [62, 75]
.text     ...                                                                                                                         * 2

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                            
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                         C:\Program Files (x86)\Alcohol Soft\Alcohol 52\
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                         0
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                      0x64 0xC8 0x17 0x00 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                   
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                0xA0 0x02 0x00 0x00 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                             0x77 0xBD 0xE6 0x43 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                            
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                      0x6D 0xDF 0x82 0x7C ...
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                        
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                             C:\Program Files (x86)\Alcohol Soft\Alcohol 52\
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                             0
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                          0x64 0xC8 0x17 0x00 ...
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)               
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                    0xA0 0x02 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                 0x77 0xBD 0xE6 0x43 ...
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)        
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                          0x6D 0xDF 0x82 0x7C ...

---- Files - GMER 2.1 ----

File      C:\Users\Paweł\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UROOVLT\84679930[2].jpg                18481 bytes

---- EOF - GMER 2.1 ----
