Log Velky :
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-12-06 20:36:41
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 SAMSUNG_HD322HJ rev.1AG01118
Running: gmer.exe; Driver: C:\Users\user\AppData\Local\Temp\kxldapob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82C8FA49 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CC94D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\Drivers\sppm.sys Systém nemôže nájsť zadanú cestu. !
.text USBPORT.SYS!DllUnload 8E758DB9 5 Bytes JMP 860251D8
.text az74rj88.SYS 8E7C1000 12 Bytes [44, 08, C2, 82, EE, 06, C2, ...]
.text az74rj88.SYS 8E7C100D 9 Bytes [E7, C1, 82, 48, 0B, C2, 82, ...] {OUT 0xc1, EAX; OR BYTE [EAX+0xb], -0x3e; ADD BYTE [EAX], 0x0}
.text az74rj88.SYS 8E7C1017 47 Bytes [00, DE, B7, B9, 88, E6, B5, ...]
.text az74rj88.SYS 8E7C1047 109 Bytes [82, 8E, 2E, CD, 82, 04, C9, ...]
.text az74rj88.SYS 8E7C10B5 12 Bytes [D4, CC, 82, F0, B9, CC, 82, ...]
.text ...
.text autochk.exe 004311D1 73 Bytes [10, 08, FE, 75, 41, 8B, 4D, ...]
.text autochk.exe 0043121B 4 Bytes [0F, 84, C8, 00]
.text autochk.exe 00431220 129 Bytes [00, 83, 7D, 18, 00, 7E, 6D, ...]
.text autochk.exe 004312A2 1 Byte [00]
.text autochk.exe 004312A2 7 Bytes [00, 00, C7, 44, 01, 04, 00]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1668] kernel32.dll!SetUnhandledExceptionFilter 767CF4FB 4 Bytes [C2, 04, 00, 00]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88A9F042] \SystemRoot\System32\Drivers\sppm.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88A9F6D6] \SystemRoot\System32\Drivers\sppm.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88A9F800] \SystemRoot\System32\Drivers\sppm.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88A9F13E] \SystemRoot\System32\Drivers\sppm.sys
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortNotification] 00147880
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortQuerySystemTime] 78800C75
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortReadPortUchar] 06750015
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortStallExecution] C25DC033
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortWritePortUchar] 458B0008
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortWritePortUlong] 6A006A08
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 50056A24
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 005AB7E8
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortGetScatterGatherList] 0001B800
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortGetParentBusType] C25D0000
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortRequestCallback] CCCC0008
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortWritePortBufferUshort] CCCCCCCC
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortGetUnCachedExtension] CCCCCCCC
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortCompleteRequest] CCCCCCCC
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortCopyMemory] 53EC8B55
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortEtwTraceLog] 800C5D8B
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 7500117B
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 127B806A
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 80647500
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7500137B
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortInitialize] 157B805E
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortGetDeviceBase] 56587500
IAT \SystemRoot\System32\Drivers\az74rj88.SYS[ataport.SYS!AtaPortDeviceStateChange] 8008758B
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [748B24CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7489562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [748956EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [748B2546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [748A85AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [748A4D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [748A5105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [748A51DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [748A6707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [748A8301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [748A8850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [748A90B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [748AE254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [748A4C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\ole32.dll [msvcrt.dll!free] [69DD11EB] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1684] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\ole32.dll [msvcrt.dll!free] [69DD11EB] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\user\Desktop\gmer\gmer.exe[4532] @ C:\Windows\System32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85B1D1F8
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
Device \Driver\volmgr \Device\VolMgrControl 84E851F8
Device \Driver\usbuhci \Device\USBPDO-0 860281F8
Device \Driver\usbuhci \Device\USBPDO-1 860281F8
Device \Driver\usbuhci \Device\USBPDO-2 860281F8
Device \Driver\ACPI_HAL \Device\00000053 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-3 860281F8
Device \Driver\usbehci \Device\USBPDO-4 85FE1500
Device \Driver\volmgr \Device\HarddiskVolume1 84E851F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 85DC51F8
Device \Driver\volmgr \Device\HarddiskVolume2 84E851F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{81E0CF24-E213-489A-A05C-236B6C0C8AC3} 85FB51F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84E871F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 84E871F8
Device \Driver\atapi \Device\Ide\IdePort0 84E871F8
Device \Driver\atapi \Device\Ide\IdePort1 84E871F8
Device \Driver\atapi \Device\Ide\IdePort2 84E871F8
Device \Driver\atapi \Device\Ide\IdePort3 84E871F8
Device \Driver\cdrom \Device\CdRom1 85DC51F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 85FB51F8
Device \Driver\PCI_PNP1904 \Device\0000005b sppm.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{768E416E-DD00-494F-853D-21EF371ADE82} 85FB51F8
Device \Driver\sptd \Device\283383905 sppm.sys
Device \Driver\usbuhci \Device\USBFDO-0 860281F8
Device \Driver\usbuhci \Device\USBFDO-1 860281F8
Device \Driver\usbuhci \Device\USBFDO-2 860281F8
Device \Driver\usbuhci \Device\USBFDO-3 860281F8
Device \Driver\usbehci \Device\USBFDO-4 85FE1500
Device \Driver\NetBT \Device\NetBT_Tcpip_{B0F1A7FF-768D-4296-A888-BD531DE3E3D5} 85FB51F8
Device \Driver\az74rj88 \Device\Scsi\az74rj881Port4Path0Target0Lun0 860A81F8
Device \Driver\az74rj88 \Device\Scsi\az74rj881 860A81F8
Device Fs_Rec.sys (File System Recognizer Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x97 0x44 0xDB 0x04 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x25 0x85 0xAB 0xC5 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3E 0x54 0xFC 0x5C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x36 0x80 0x48 0xF1 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x97 0x44 0xDB 0x04 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x25 0x85 0xAB 0xC5 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3E 0x54 0xFC 0x5C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x36 0x80 0x48 0xF1 ...
---- EOF - GMER 1.0.15 ----