pro lepší přehlednost přikládám logy z GMERu zde:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit quick scan 2010-09-05 15:41:17
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\HALLKI~1\AppData\Local\Temp\uxlyiuod.sys
---- System - GMER 1.0.15 ----
Code 891CCC4C ZwTraceEvent
Code 891CCC4B NtTraceEvent
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
a nyní ten větší
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-09-06 16:53:47
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\HALLKI~1\AppData\Local\Temp\uxlyiuod.sys
---- System - GMER 1.0.15 ----
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C41AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C41104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C413F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C29634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C29898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C411DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C41958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C416F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C41F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83C421A8
Code 896A0C4C ZwTraceEvent
Code 896A0C4B NtTraceEvent
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!NtTraceEvent 83849E34 5 Bytes JMP 896A0C50
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 8385A599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8387EF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 2 83A8C0E5 5 Bytes JMP 896A0E30
PAGE ntkrnlpa.exe!NtRequestWaitReplyPort + 2 83A8DB0D 5 Bytes JMP 896A0D90
PAGE ntkrnlpa.exe!NtRequestPort + 2 83AA1D73 5 Bytes JMP 896A0CF0
.text win32k.sys!XFORMOBJ_iGetXform + 331A 9B124C57 5 Bytes JMP 896A0610
.text win32k.sys!EngAllocMem + 7E47 9B135142 5 Bytes JMP 896A0750
.text win32k.sys!PATHOBJ_bEnum + 7A2F 9B14782E 5 Bytes JMP 896A06B0
.text win32k.sys!PATHOBJ_bEnum + 8714 9B148513 5 Bytes JMP 896A0930
.text win32k.sys!EngCreateSemaphore + CB9F 9B16638F 5 Bytes JMP 896A09D0
.text win32k.sys!EngCreateSemaphore + CEDB 9B1666CB 5 Bytes JMP 896A0570
.text win32k.sys!EngCopyBits + 1F22 9B1689B4 3 Bytes JMP 896A04D0
.text win32k.sys!EngCopyBits + 1F26 9B1689B8 1 Byte [EE]
.text win32k.sys!EngBitBlt + 23D2 9B17179D 2 Bytes JMP 896A0430
.text win32k.sys!EngBitBlt + 23D5 9B1717A0 2 Bytes [52, EE] {PUSH EDX; OUT DX, AL }
.text win32k.sys!EngLpkInstalled + 6119 9B187842 5 Bytes JMP 896A0A70
.text win32k.sys!PATHOBJ_vGetBounds + EB7 9B205C81 5 Bytes JMP 896A0890
.text win32k.sys!EngCTGetCurrentGamma + 1C7A 9B209C9C 5 Bytes JMP 896A07F0
.text win32k.sys!CLIPOBJ_cEnumStart + 6CE0 9B2155A5 5 Bytes JMP 896A0B10
.text win32k.sys!CLIPOBJ_cEnumStart + 71E8 9B215AAD 5 Bytes JMP 896A0BB0
.text peauth.sys A4612C9D 28 Bytes [84, 92, F1, EB, 96, 39, 9C, ...]
.text peauth.sys A4612CC1 28 Bytes [84, 92, F1, EB, 96, 39, 9C, ...]
PAGE peauth.sys A4618B9B 1 Byte [49]
PAGE peauth.sys A4618B9B 9 Bytes [49, E4, 87, A3, B3, A5, BB, ...] {DEC ECX; IN AL, 0x87; MOV [0xcfbba5b3], EAX; INC EDX}
PAGE peauth.sys A4618BA9 1 Byte [AC]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[400] kernel32.dll!SetUnhandledExceptionFilter 762F3142 4 Bytes [C2, 04, 00, 00]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73C62494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73C45624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73C456E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73C6250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73C58573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73C54D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73C550CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73C551A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73C566D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73C582CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73C58819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73C5907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73C5E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1928] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73C54C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
Device \Driver\ACPI_HAL \Device\000000cf halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat eamon.sys (Amon monitor/ESET)
---- Threads - GMER 1.0.15 ----
Thread System [4:3584] A4729F2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001fe2f626d4
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001fe2f626d4@f81edf01ad02 0x2F 0x77 0x62 0xF1 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001fe2f626d4@001d28c9f74c 0x99 0xA3 0x17 0xAF ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001fe2f626d4@60d0a984eccc 0x03 0x57 0xFB 0xD1 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????Microsoft???????????? ???????m?????m?m???????m??6to4mp.ndi?E65???????????e??IO???????????2??\D???????????h??sy??6to4mp.ndi?l?l??6to4mp.ndi?sp_??? ?????????????????????1????????????????????????el??ip??? ?????????????????????-?????????????????f??? ?????????????????????1??L????????? ????????v??? ?????????????????????1????????????&????????????????????8??? ?????????????????????1??????????????????????z??????}??De???????????9??6-??? ?????????????????????-??????????????????????sD46??6.1.7600.16385?E4E???????&??? ??????????????x???? ?????????????????????-?????????????????f??? ?????????????????????1??L????????? ???????AB??????????????????????? ?????????????????????1????????????&????????????????????.??????????? ?????????????????????1????????????????????????????? ?????????????????????1????????z???????????? ???????????????????g?1????????.???????????? ???????0???????????????????????????????????????????????s??????????????????????????????????? ?????????????????????1????????????????????? ?????????????????????1???????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ?????B??? ?????????????????????1??????*?8??? ???????? ??????????? ?????????????????????1????????????&????????????????????"??? ?????????????????????1??????*?8??? ???????????????????????????????de??????I????3??????????{3cbadd38-3049-5c8e-9d4c-6c6c19aef2fa}?4?7???????????????????????????}??"T??????????????????? ???????.?????.0????????????d???d???????????????????????????"??{F???????????7??2E??2E??????????*6to4mp?-F????:??????-??25??{e9d59a36-d468-5a09-b5d5-36cd803c1a5b}?Tcp??????????????????????????????????????????????? ??????????????????????????????`????????e??{90386914-D935-47FB-881F-8467C2BD145F}??01??\Device\{90386914-D935-47FB-881F-8467C2BD145F}??91??? ??????????????????????????????<??????i??????<??????E??????Microsoft 6to4 Adapter Driver???? ??????????????????????????????"??? ???????????? ???????D?????17-??? "?????????????????ndis5_ip6_tunnel????????????? ??????????????????????????????????????????? ??????????????????????????????????????????????????????????????????S??ov? adresa????????????????t???? ????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????ve??????Net?p???6-21-2006????????????????????????????????????????????????p???????l???&????????????????:??????????e??Net??????????5????????????:??????????????????????????????????????????????????o???????s???????|???????????????????|???e??Net???????????????????????????????????????????????X?????????????? ???????????????????n?-??????0???????????????s?? ??????????????????????????? ?????????????????????-?????????????????f??????????????? ?????????????????????1??L????????? ??????:????????????????????????? ?????????????????????1????????????&???????????????????? ??? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????????????????????????????????????????????????????? ?????????????????????1????????????&???????????????????????input.inf???? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????????????????????????????????HID_Inst????????????????????input.inf:Standard.NTx86:HID_Inst:6.1.7600.16385::generic_hid_devic
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ????????????*6to4mp?????? ???????????????????s?1??????*?:??? ???????????????5-??????????*6to4mp??C??? ?????????????????????1????????????&???????????????????????????????????@???? ????????????8?????????? ??P?ipojen? k m?stn? s?ti* 64?"????????????T????????????6P?ipojen? k m?stn? s?ti* 64??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????4Microsoft 6to4 Adapter #28????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ????????? ???????@????????????????????$?N?6????????????????????????????????? ????2?????s-4???????????-??9F??9F???????????????????????????????????????6???????????????????e??????????????? ???????Z?????????????1????????????&???????????????????????? ?????????????????????1??????*?8??? ??????_{8???????????B??????????dB??????A????A????????????8??????5??1}??P?ipojen? k m?stn? s?ti* 65?0-??????????? ?????????????????????1????????????&???????????????????????????????? ?????????????????????1??????????????????????N??????T????D" "??Microsoft???? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????????????????????????????7??AA??2E??? ?????????????????????1??????????????????????,?????????????????? ?????????????????????1????????.???????????{533c5b84-ec70-11d2-9505-00c04f79deaf}????????:??????B???B??????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????????????????????4.0.424.0???????????? ?????????????????????1???
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ????;E??tunnel??????tunnel???7???????????5??????-C????$??????1???????4??????????????? ?????????????????????:????????????????pN??? ???????_?????3B1??? ???????????????????~?:????????????,???????????????????????C7??????????????????????????????? ???????5?????????????1??L????????? ??????OEM??? ?????????????????????1????????????&????????????????????R??? ?????????????????????1??L????????? ????????????????????s??????ol???????????????????i?????sOO??? ?????????????????????1????????????&???????????????????????? ?????????????????????-?????????????????????????????!?????sC:??????????????????? ???????:?????????????-??"???*?????????????????????????????????????????? ??????????????????UMB\UMBUS????????????????????~??????????? ??????????????s?????N????????????D????{00000000-0000-0000-ffff-ffffffffffff}???????????????????????????????????0????????N???????????D?????{36fc9e60-c465-11cf-8056-444553540000}?????????????????g????????? ???????????????? ??????????? ?J??????????????????????????s?????????????#?????????????????????????3???
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Export ????????? ???????Z?????????????1????????????&???????????????????????? ?????????????????????1??????*?<??? ????????????????????e??????????P?ipojen? k m?stn? s?ti* 1194???? ???????Z?????????????1????????????&????????????????????-??? ?????????????????????1??????*?4??? ???????????????????? ??????????????????????????????????P?ipojen? k m?stn? s?ti 4????????????_???????????????????-???????????????????r???????????????????r???????????????????o???????????????????????????????????????_???????????????????????????????????????P???????????????????s???????????????????|???????????????????p???????????????????n???????????????????T???????????????????n???????????????????n???????????????????&???????????????????o???????????????????P???????????????????P???????????????????n???????????????????????????????????????_???????????????????????????????????????w???????????????????????????????????????n???????????????????n???????????????????????????????????}???????????????h???????????????????????????????????????????????????????????????????????3?
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9C 0x9B 0x30 0xA7 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x65 0x5D 0x13 0x8E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0x62 0xCA 0xE9 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001fe2f626d4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001fe2f626d4@f81edf01ad02 0x2F 0x77 0x62 0xF1 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001fe2f626d4@001d28c9f74c 0x99 0xA3 0x17 0xAF ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001fe2f626d4@60d0a984eccc 0x03 0x57 0xFB 0xD1 ...
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???p?p???????????????p??? ???????o??????????????????????R?K??????????????????????????????????????????p?p?p??system32\drivers\HTTP.sys????????????????????????????????????????????p??RpcSs????????????p???-??25??@%systemroot%\system32\drivers\hwpolicy.sys,-101????????p????? ??o?????????t????? ??????????????????@%SystemRoot%\system32\drivers\http.sys,-1????????<??p????????h??????????p???0??e2???????????????????????v?v?u???????????????p????????????????????????p????????????????????????g???????????????????????????????????g??????R??p?????????e?????????????????????????p??? ???????p???????????p??????????????????????????????4?? ?????????? ????\???????????????????? ??????????????????????????? ??????? ????????p?????o???o???p????????? ???????o??????????????????????T?0??????????????p??????p????p??System32\drivers\hwpolicy.sys???system32\DRIVERS\i8042prt.sys?8042prt.sys?????<??p????????h???????<??p????????h????????p?????????????5????????m??????????????}?}?}??? ???????o??????????????????????P?2??????????o?o?p?p?p?p?p??Keyboar
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???p?????????????5????????m??????????????}?}?}??? ???????o??????????????????????P?2??????????o?o?p?p?p?p?p??Keyboard Port???system32\DRIVERS\intelppm.sys?ntelppm.sys???Ovlada? procesoru Intel?????system32\DRIVERS\ipfltdrv.sys???????@??????g?????p???????v???p???????v???????s???????????p?????p?????p????0??p?????????e?????????????????v??????????????t???????????????t??????????????g????.NT??????????z???{??? ???????o?????p?????p??????????Z?3???????????????????????????????????????????????T??p????????h?????\SystemRoot\system32\DRIVERS\BrFiltLo.sys?????Z??p?????????e????Brother USB Mass-Storage Lower Filter Driver?????????p??????p???extended base????p?p?p?p?p?p?p????T??p???????????d??brmfcsto.inf_x86_neutral_39ae61431a44cded???? ???????p???????????p??????????,??? ?????????????,??p???????????s??/GR=OFF /TO=10 /OW=30???? ???????o???????????p??????????Z?4?????????????????????t?????????????????????????????????????????T??p????????h????????p???p??????Z??p?????????e???????p?????p??????????????\SystemRoot\system32\DRIVERS\Br
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???p?p?????????????g?????? ??k??????p????????????v???????{???????????????????????v???????????????????z???z???????t??????????????????????????????t????????????v???????v???????????????????????????p???????e???????v???u???|???????v??? ???????o?????p????????????????:?=??????T??? ???????p???????????o????&???(????? ???????????? ???????p?????p???????????????????????????B????? ???????p?????p?????????????????????????s??? ???????p???????????p?,???????????? ????????????????????????????p???p??? ???????p???????????p?,???????????? ???????????????????????????RpcSs???????? ???????p???????????p?,???????????? ????????????????????????????????????????????p??? ???????p???????????p?,???????????? ???????????????????????????? ???????p???????????p?,???????????? ??????????????????????????????p???p???p???p???p???p????????? ???????p???????????p?,???????????? ???????????? ???????o?????p?????p????????$???>??????v????P??p?????????e????@%SystemRoot%\System32\bthserv.dll,-101???????????????????????????Z??p????????h?????%SystemRoot%\system32\s
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???k?p?????????????????s??????X??????????m??Fs_Rec??????{4d36e966-e325-11ce-bfc1-08002be10318}??????{4d36e966-e325-11ce-bfc1-08002be10318}\0000?????CompositeBus????????????????????eset_epfwndismp??????????k???????e??????????????????DETECTEDInternal\ACPI_HAL?DETECTED\ACPI_HAL?????? ~?????????????????????????? ???????1??????????????pi????F??k?????g?????????f???????e???????????????4???k?k?k???????????3??????? ??{00000000-0000-0000-FFFF-FFFFFFFFFFFF}???????k?l?o??????????? ??????????????????Psched?4?4???????k???????????????k???0??02??RDPENCDD?4??? x???????????????????N??k????????D???????N??k????????D??????????????????????????????????4???????????D???_??????????????ms??NDIS?????????k???????????????????????P??\0??Base?????????e??????s???????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????eset_epfwndismp?????NDIS?;???k??? "??k???????????????k??tcpipreg???????????????g????@oem17.inf,%ndis5desc%;Sony Ericsson Device 117 USB Ethernet Emulation (NDIS 5)?"????????????????????????????5??89?????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ???l?p????N????????????????n?5??{00000000-0000-0000-0000-000000000000}???????????l???????????l?l?l????X??l???&???&???????????????????????????????????.???????????????l???1???????????????n??or??????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0002?? ????N??l?????????D?????l?l?l?????o?|??????????6.1.7600.16385??6.????(??l???????????????????n???????????????1???1???l?????l?&???l???l???????????????????????????????????????????????l??? ???????k?????l?????k?-??????????A?????????D?????N??l???4???????h??? ???????l???????????l?-????????P????????/??umbus.inf????????????????????????i????N??????????????????????????m??????????HIDClass????LegacyDriver???????|?????????l??????????????11??-9???????????????????????????????????????????????m?m?????k?l?l?l?l???l???????}???????l??????????????????? ???????k?????l?????k?-??????????B? ???????D?????N??l????????D?????? ???????l???????????l?-????????^????????????l?l?l?l?l?l?l?????????????????????l?&???????l??? ???4????????????????????N???????????D?????? L????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???p?p???????v??????????????t???????????????????LDDM Graphics Subsystem??????????????c???????S????P??s?????????e????File system??????????|???o???????y???????????\??ea??????????????????FSFilter Bottom???????2??z????????h?????????????acpi.inf?????????????????????zp??p???p??? ???????o?????????????,????????8?c??????????????????1??t-???????????????????????????|???????????-?g14??????????????t??????????????g?????????o???q??5??????????????g?????????|???????????????o???0???2??????????????????????????s_????????????????????<??o????????h?????????????????????????????????????????????????????? ???????o?????o????????????????6?g??????????????????m??tc??system32\DRIVERS\Epfwndis.sys???Eset Personal Firewall???????????????????????????????}???????????????????????????????a??in?????????????g??????N??u?????????e?????????k??????p????????????????????v?|.i??????? ???????o???????????o??????????V??? ???????????? R??o??????????????C:\ProgramData\ESET\ESET Smart Security\????? V??o??????????????C:\Program Files\ESET\ESET Smart Security\?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export ??????????????????????B??????s????h??????????????r???m???l?m??????????N??????????????????????????????????????????o??tk???o?p????????.NT?????????????????????text????????????????????? ???????q??????????????????????N?k???????????N??????-??????????{CF3F502E-B40D-4071-996F-00981EDF938E}??????? ???????q???????????o?,?????? ?B?t?????????????? ???????????2???????_????????B??????8??????????%SystemRoot%\System32\appmgr.dll?_??? ???????q???????????o??????????h?????????????????????????????????h??????-??????%SystemRoot%\System32\winevt\Logs\Media Center.evtx??????????????s????n32\??? ?q???q???q???q???????q???q???q???q???s????????? ???????????????????q???????? ?@?????????t?????%SystemRoot%\ehome\ehepgres.dll?08??????????? ???????????????????????????? ?>????????r????>??????\??????????%SystemRoot%\ehome\ehRecvr.exe?20???????????????????????? ???????????????????????????? ?>????????d????>?????????????????%SystemRoot%\ehome\ehSched.exe?YS_????@?????????????????? ???????????????????????????? ?@?????????????@??????I??????????%Sy
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9C 0x9B 0x30 0xA7 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x65 0x5D 0x13 0x8E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0x62 0xCA 0xE9 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D39E6332-4321-4B36-9D29-42FFF3E2C40F}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D39E6332-4321-4B36-9D29-42FFF3E2C40F}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D39E6332-4321-4B36-9D29-42FFF3E2C40F}@Path \Microsoft\Windows Defender\MP Scheduled Scan
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D39E6332-4321-4B36-9D29-42FFF3E2C40F}@Triggers 0x15 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D39E6332-4321-4B36-9D29-42FFF3E2C40F}@DynamicInfo 0x03 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan@Id {D39E6332-4321-4B36-9D29-42FFF3E2C40F}
---- EOF - GMER 1.0.15 ----
snad ti to řekne více než mě

a Díky
