Odpoledne se u mě zastavil bratránek, trochu se v počítači "povrtal" a už všechno funguje. Říkal něco o mbrfix, smazal tempy a vypnul nějaké ovladače. Pro jistotu sem dávám logy z GMER:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit quick scan 2010-04-12 16:50:22
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\DVOK~1\LOCALS~1\Temp\uxrirpod.sys
---- System - GMER 1.0.15 ----
SSDT spbg.sys ZwEnumerateKey [0xF74F7CA2]
SSDT spbg.sys ZwEnumerateValueKey [0xF74F8030]
---- Devices - GMER 1.0.15 ----
Device 8A3D11F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device 89CED500
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IsDrv122.sys
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IsDrv122.sys
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-04-12 18:19:24
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\DVOK~1\LOCALS~1\Temp\uxrirpod.sys
---- System - GMER 1.0.15 ----
SSDT spbg.sys ZwEnumerateKey [0xF74F7CA2]
SSDT spbg.sys ZwEnumerateValueKey [0xF74F8030]
SSDT spbg.sys ZwOpenKey [0xF74DA0C0]
SSDT spbg.sys ZwQueryKey [0xF74F8108]
SSDT spbg.sys ZwQueryValueKey [0xF74F7F88]
SSDT spbg.sys ZwSetValueKey [0xF74F819A]
INT 0x62 ? 8A3D2BF8
INT 0x63 ? 8A12DBF8
INT 0x63 ? 8A12DBF8
INT 0x63 ? 8A12DBF8
INT 0x63 ? 8A12DBF8
INT 0x63 ? 8A12DBF8
INT 0x63 ? 8A12DBF8
INT 0x82 ? 8A3D2BF8
---- Kernel code sections - GMER 1.0.15 ----
? spbg.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload BA1348AC 5 Bytes JMP 8A12D1D8
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xBA045900]
.text HTTP.sys AE26331E 3 Bytes [AB, 27, AE] {STOSD ; DAA ; SCASB }
.text HTTP.sys AE26334D 3 Bytes [AB, 27, AE] {STOSD ; DAA ; SCASB }
.text HTTP.sys AE263373 3 Bytes [A8, 27, AE] {TEST AL, 0x27; SCASB }
.text HTTP.sys AE2633AE 3 Bytes [A8, 27, AE] {TEST AL, 0x27; SCASB }
.text HTTP.sys AE263405 3 Bytes [A8, 27, AE] {TEST AL, 0x27; SCASB }
.text ...
.text audlk6tu.SYS ADE47384 1 Byte [20]
.text audlk6tu.SYS ADE47384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text audlk6tu.SYS ADE473AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text audlk6tu.SYS ADE473C4 3 Bytes [00, 00, 00]
.text audlk6tu.SYS ADE473C9 1 Byte [00]
.text ...
? System32\Drivers\IsDrv122.sys Systém nemůže nalézt uvedenou cestu. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[2924] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8A3672D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F750A93C] spbg.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F750A990] spbg.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74DB040] spbg.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74DB13C] spbg.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74DB0BE] spbg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74DB7FC] spbg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74DB6D2] spbg.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8A12D2D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74EAD92] spbg.sys
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlInitUnicodeString] 000000A5
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!swprintf] 000000E5
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeSetEvent] 000000F1
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000071
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000D8
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00000031
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmFreeMappingAddress] 00000015
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000004
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 000000C7
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmUnmapIoSpace] 00000023
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 000000C3
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IofCompleteRequest] 00000018
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 00000096
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IofCallDriver] 00000005
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0000009A
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000007
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoConnectInterrupt] 00000012
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoDetachDevice] 00000080
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeWaitForSingleObject] 000000E2
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeInitializeEvent] 000000EB
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeCancelTimer] 00000027
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000B2
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000075
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000009
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoQueueWorkItem] 00000083
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmMapIoSpace] 0000002C
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0000001A
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoReportDetectedDevice] 0000001B
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0000006E
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 0000005A
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!NlsMbCodePageTag] 000000A0
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!PoRequestPowerIrp] 00000052
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 0000003B
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 000000D6
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!sprintf] 000000B3
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00000029
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ObfDereferenceObject] 000000E3
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 0000002F
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000084
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ZwClose] 00000053
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 000000D1
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000000
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 000000ED
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 00000020
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoCreateDevice] 000000FC
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B1
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 0000005B
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000006A
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ZwOpenKey] 000000CB
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 000000BE
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoStartTimer] 00000039
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeInitializeTimer] 0000004A
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoInitializeTimer] 0000004C
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeInitializeDpc] 00000058
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeInitializeSpinLock] 000000CF
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoInitializeIrp] 000000D0
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ZwCreateKey] 000000EF
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AA
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 000000FB
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ZwSetValueKey] 00000043
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeInsertQueueDpc] 0000004D
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000033
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoStartPacket] 00000085
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000045
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000F9
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoFreeMdl] 00000002
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmUnlockPages] 0000007F
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 00000050
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 0000003C
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 0000009F
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000A8
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000051
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoStartNextPacket] 000000A3
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeBugCheckEx] 00000040
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeSetTimer] 00000092
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!_allmul] 0000009D
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000038
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!_except_handler3] 000000F5
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!PoSetPowerState] 000000BC
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000B6
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000DA
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000021
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!_aulldiv] 00000010
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!strstr] 000000FF
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!_strupr] 000000F3
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000D2
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CD
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!KeTickCount] 0000000C
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000013
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoDeleteDevice] 000000EC
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000005F
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000097
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoAllocateIrp] 00000044
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoAllocateMdl] 00000017
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000C4
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000A7
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000007E
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 0000003D
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!ExFreePoolWithTag] 00000064
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoFreeIrp] 0000005D
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!IoFreeWorkItem] 00000019
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!RtlCompareMemory] 00000060
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!PoCallDriver] 00000081
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!memmove] 0000004F
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000DC
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\audlk6tu.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
---- Devices - GMER 1.0.15 ----
Device 8A3D11F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device 89CED500
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\sptd \Device\2330770526 spbg.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IsDrv122.sys
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IsDrv122.sys
Device \Driver\usbuhci \Device\USBPDO-0 8A1ED500
Device \Driver\usbuhci \Device\USBPDO-1 8A1ED500
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A3651F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A3651F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A3651F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A3651F8
Device \Driver\usbuhci \Device\USBPDO-2 8A1ED500
Device \Driver\usbuhci \Device\USBPDO-3 8A1ED500
Device \Driver\usbehci \Device\USBPDO-4 8A1F2500
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A3D31F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A3D31F8
Device \Driver\Cdrom \Device\CdRom0 8A13E1F8
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom4 8A13E1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 89D05500
Device \Driver\Cdrom \Device\CdRom6 8A13E1F8
Device \Driver\NetBT \Device\NetbiosSmb 89D05500
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBFDO-0 8A1ED500
Device \Driver\usbuhci \Device\USBFDO-1 8A1ED500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89D111F8
Device \Driver\usbuhci \Device\USBFDO-2 8A1ED500
Device 89D111F8
Device \Driver\usbuhci \Device\USBFDO-3 8A1ED500
Device \Driver\Ftdisk \Device\FtControl 8A3D31F8
Device \Driver\usbehci \Device\USBFDO-4 8A1F2500
Device \Driver\PCI_PNP4072 \Device\0000007f spbg.sys
Device \Driver\PCI_PNP4072 \Device\0000007f spbg.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{D984CAD8-AF1B-47E7-B4C7-9B03527C52C5} 89D05500
Device \Driver\audlk6tu \Device\Scsi\audlk6tu1 8923A500
Device \Driver\audlk6tu \Device\Scsi\audlk6tu1Port2Path0Target1Lun0 8923A500
Device \Driver\audlk6tu \Device\Scsi\audlk6tu1Port2Path0Target0Lun0 8923A500
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device 892CD1F8
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@EnableDHCP 1
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@IPAddress 0.0.0.0?
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@SubnetMask 0.0.0.0?
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@DefaultGateway
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@DhcpIPAddress 62.245.121.137
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@DhcpSubnetMask 255.255.255.0
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@DhcpServer 62.24.64.33
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@Lease 43200
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@LeaseObtainedTime 1138663121
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@T1 1138684721
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@T2 1138700921
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@LeaseTerminatesTime 1138706321
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@DhcpDefaultGateway 62.245.121.1?
Reg HKLM\SYSTEM\ControlSet001\Services\{38B18B9D-D46A-468F-91A1-F64B6CE60F3D}\Papameters\Tcpip@DhcpSubnetMaskOpt 255.255.255.0?
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC7 0x3E 0x22 0xA6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x48 0xA9 0xDD 0x0A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x53 0x9B 0x70 0x23 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0x46 0x37 0x7D 0x25 ...
---- EOF - GMER 1.0.15 ----