Re: Prosím o kontolu - problém s Windows Update
Napsal: 24 kvě 2016 19:33
GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2016-05-24 20:31:12
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000036 TOSHIBA_MQ01ABD100 rev.AX0C3H 931,51GB
Running: xfl029ri.exe; Driver: C:\Users\Dana\AppData\Local\Temp\uxldapog.sys
---- User code sections - GMER 2.2 ----
? C:\WINDOWS\SYSTEM32\iertutil.dll [5296] entry point in ".rdata" section 0000000072dfcaf0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 00007ffdde535220 5 bytes JMP 00007ffd5e670480
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject 00007ffdde5352c0 5 bytes JMP 00007ffd5e670470
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess 00007ffdde535580 5 bytes JMP 00007ffd5e670360
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 00007ffdde535620 5 bytes JMP 00007ffd5e670490
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ffdde535640 1 byte JMP 00007ffd5e6703d0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess + 2 00007ffdde535642 3 bytes {JMP 0xffffffff8013ad90}
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ffdde5357a0 5 bytes JMP 00007ffd5e670310
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffdde535800 5 bytes JMP 00007ffd5e6703a0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject 00007ffdde535840 5 bytes JMP 00007ffd5e670380
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent 00007ffdde5358c0 5 bytes JMP 00007ffd5e6702d0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ffdde5359c0 5 bytes JMP 00007ffd5e6702c0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ffdde535a00 5 bytes JMP 00007ffd5e670300
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ffdde535a80 5 bytes JMP 00007ffd5e6703b0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtResumeThread 00007ffdde535b00 5 bytes JMP 00007ffd5e670440
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ffdde535b20 5 bytes JMP 00007ffd5e6703e0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry 00007ffdde535db0 5 bytes JMP 00007ffd5e670220
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ffdde5361b0 5 bytes JMP 00007ffd5e6704a0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 00007ffdde536210 5 bytes JMP 00007ffd5e670390
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ffdde536490 5 bytes JMP 00007ffd5e6702e0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion 00007ffdde5364d0 5 bytes JMP 00007ffd5e670340
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ffdde5365b0 5 bytes JMP 00007ffd5e670280
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ffdde5366f0 5 bytes JMP 00007ffd5e6702a0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffdde536730 1 byte JMP 00007ffd5e6703c0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx + 2 00007ffdde536732 3 bytes {JMP 0xffffffff80139c90}
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer 00007ffdde536750 5 bytes JMP 00007ffd5e670320
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess 00007ffdde5368b0 5 bytes JMP 00007ffd5e670410
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry 00007ffdde536910 5 bytes JMP 00007ffd5e670230
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffdde536d30 5 bytes JMP 00007ffd5e6703f0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ffdde536f90 5 bytes JMP 00007ffd5e6701d0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry 00007ffdde537150 5 bytes JMP 00007ffd5e670240
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey 00007ffdde5371b0 5 bytes JMP 00007ffd5e6704b0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 00007ffdde5371d0 5 bytes JMP 00007ffd5e6704c0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair 00007ffdde537230 5 bytes JMP 00007ffd5e6702f0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion 00007ffdde537250 5 bytes JMP 00007ffd5e670350
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant 00007ffdde537310 5 bytes JMP 00007ffd5e670290
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore 00007ffdde5373d0 5 bytes JMP 00007ffd5e6702b0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread 00007ffdde537430 5 bytes JMP 00007ffd5e670370
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer 00007ffdde537450 5 bytes JMP 00007ffd5e670330
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 00007ffdde537a70 5 bytes JMP 00007ffd5e670460
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtResumeProcess 00007ffdde537d30 5 bytes JMP 00007ffd5e670420
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 00007ffdde537e90 5 bytes JMP 00007ffd5e670250
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions 00007ffdde537eb0 5 bytes JMP 00007ffd5e670260
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffdde537ef0 5 bytes JMP 00007ffd5e670400
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ffdde5382d0 5 bytes JMP 00007ffd5e6701e0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState 00007ffdde5382f0 5 bytes JMP 00007ffd5e670200
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ffdde538410 5 bytes JMP 00007ffd5e6701f0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess 00007ffdde5384f0 5 bytes JMP 00007ffd5e670430
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread 00007ffdde538510 5 bytes JMP 00007ffd5e670450
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ffdde538530 5 bytes JMP 00007ffd5e670210
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl 00007ffdde538750 5 bytes JMP 00007ffd5e670270
? C:\WINDOWS\SYSTEM32\iertutil.dll [7884] entry point in ".rdata" section 0000000072dfcaf0
? C:\WINDOWS\SYSTEM32\iertutil.dll [8732] entry point in ".rdata" section 0000000072dfcaf0
---- Threads - GMER 2.2 ----
Thread C:\WINDOWS\system32\csrss.exe [6556:8668] fffff961a09e4060
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [6088:1124] 00007ffdb4ac838c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [6088:7152] 00007ffdb545c680
---- Services - GMER 2.2 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] MessagingService_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] OneSyncSvc_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] PimIndexMaintenanceSvc_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [MANUAL] UnistoreSvc_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] UserDataSvc_8dbfcd <-- ROOTKIT !!!
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\MS_002515_00_07D2_60^823CB2ED9AB6B9C849287EE9C9AEA149@Timestamp 0xEC 0x4B 0x2F 0xCC ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\bf566a8d-4d48-4a62-aefa-26597c0d5105\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\bf566a8d-4d48-4a62-aefa-26597c0d5105\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 1477862540
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 4022
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 3954
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@TotalResumeTime 14625
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeBootMgrTime 469
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeAppTime 1682
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeAppStartTimestamp 4507
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeHiberFileTime 1082
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeRestoreImageStartTimestamp 4964
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeIoTime 862
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeDecompressTime 267
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeKernelSwitchTimestamp 6189
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelReturnFromHandlerTimestamp 6245
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@SleeperThreadEndTimestamp 13173
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@TimeStampCounterAtSwitchTime 6218
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelReturnSystemPowerState 14616
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberHiberFileTime 5740
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberInitTime 90
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@TotalHibernateTime 12997
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeHiberFileTime 5196
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeInitTime 71
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeSharedBufferTime 9
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@DeviceResumeTime 1410
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelAnimationTime 108
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelPagesProcessed 426473
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelPagesWritten 0x0A 0x1D 0x02 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@BootPagesProcessed 34806
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@BootPagesWritten 0x24 0x3F 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeDecompressRate 73
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberChecksumTime 134
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberChecksumIoTime 20
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelChecksumTime 99
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelChecksumIoTime 35
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeIoCpuTime 4224
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberIoCpuTime 814
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HybridBootAnimationTime 6958
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeCompleteTimestamp 0x45 0xFB 0x10 0x04 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@GlassSessionId 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\c8f7337894a6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@Bluetooth_UniqueID {00000000-0000-0000-0000-000000000000}#907F61048447_00000000
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@ConnectionCount 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0003
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0003@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0003@ConnectionCount 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0005
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0005@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0005@ConnectionCount 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@DisplayName Slu?ba zas?l?n? zpr?v_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Type 7
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Action 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Guid 0x16 0x28 0x7A 0x2D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Data0 0x75 0x18 0xBC 0xA3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@DataType0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@DisplayName Hostitel synchronizace_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@DisplayName Data kontakt?_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 6779
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 1664
Reg HKLM\SYSTEM\CurrentControlSet\Services\SynTP\Parameters@DetectTimeMS 447
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@LeaseObtainedTime 1463985219
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@T1 1464028419
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@T2 1464060819
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@LeaseTerminatesTime 1464071619
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@ImagePath C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@DisplayName ?lo?i?t? u?ivatelsk?ch dat_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@DisplayName P??stup k u?ivatelsk?m dat?m_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated 0xFE 0x9E 0xA0 0x20 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh 0xFE 0x06 0x65 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow 0xFE 0x36 0xDC 0xBE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeTickCount 0xD1 0xF0 0x29 0x06 ...
Reg HKLM\SYSTEM\Setup\Upgrade\NsiMigrationRoot\62\0@Rw 0x64 0x62 0x03 0x00 ...
Reg HKLM\SYSTEM\Setup\Upgrade\NsiMigrationRoot\62\0@RwMask 0x64 0x62 0x03 0x00 ...
Reg HKLM\SYSTEM\Setup\Upgrade\Pnp\CurrentControlSet\Control\DeviceMigration\Devices\SWD\DAFUPNPPROVIDER\UUID:59AA9DE9-7EF0-F0CB-9D7A-D735B3185F7A\Interfaces\{d0875fb4-2196-4c7a-a63d-e416addd60a1}\Properties\{88ad39db-0d0c-4a38-8435-4043826b5c91}\000E@ 0x64 0x62 0x02 0x00 ...
Reg HKLM\SYSTEM\Setup\Upgrade\Pnp\CurrentControlSet\Control\DeviceMigration\Devices\SWD\DAFUPNPPROVIDER\UUID:59AA9DE9-7EF0-F0CB-9D7A-D735B3185F7A\Properties\{88ad39db-0d0c-4a38-8435-4043826b5c91}\000E@ 0x64 0x62 0x02 0x00 ...
---- Disk sectors - GMER 2.2 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.2 ----
Rootkit scan 2016-05-24 20:31:12
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000036 TOSHIBA_MQ01ABD100 rev.AX0C3H 931,51GB
Running: xfl029ri.exe; Driver: C:\Users\Dana\AppData\Local\Temp\uxldapog.sys
---- User code sections - GMER 2.2 ----
? C:\WINDOWS\SYSTEM32\iertutil.dll [5296] entry point in ".rdata" section 0000000072dfcaf0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 00007ffdde535220 5 bytes JMP 00007ffd5e670480
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryObject 00007ffdde5352c0 5 bytes JMP 00007ffd5e670470
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenProcess 00007ffdde535580 5 bytes JMP 00007ffd5e670360
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 00007ffdde535620 5 bytes JMP 00007ffd5e670490
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ffdde535640 1 byte JMP 00007ffd5e6703d0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess + 2 00007ffdde535642 3 bytes {JMP 0xffffffff8013ad90}
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ffdde5357a0 5 bytes JMP 00007ffd5e670310
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffdde535800 5 bytes JMP 00007ffd5e6703a0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDuplicateObject 00007ffdde535840 5 bytes JMP 00007ffd5e670380
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEvent 00007ffdde5358c0 5 bytes JMP 00007ffd5e6702d0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ffdde5359c0 5 bytes JMP 00007ffd5e6702c0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ffdde535a00 5 bytes JMP 00007ffd5e670300
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ffdde535a80 5 bytes JMP 00007ffd5e6703b0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtResumeThread 00007ffdde535b00 5 bytes JMP 00007ffd5e670440
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ffdde535b20 5 bytes JMP 00007ffd5e6703e0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAddBootEntry 00007ffdde535db0 5 bytes JMP 00007ffd5e670220
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ffdde5361b0 5 bytes JMP 00007ffd5e6704a0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 00007ffdde536210 5 bytes JMP 00007ffd5e670390
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ffdde536490 5 bytes JMP 00007ffd5e6702e0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateIoCompletion 00007ffdde5364d0 5 bytes JMP 00007ffd5e670340
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ffdde5365b0 5 bytes JMP 00007ffd5e670280
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ffdde5366f0 5 bytes JMP 00007ffd5e6702a0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffdde536730 1 byte JMP 00007ffd5e6703c0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx + 2 00007ffdde536732 3 bytes {JMP 0xffffffff80139c90}
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateTimer 00007ffdde536750 5 bytes JMP 00007ffd5e670320
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDebugActiveProcess 00007ffdde5368b0 5 bytes JMP 00007ffd5e670410
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtDeleteBootEntry 00007ffdde536910 5 bytes JMP 00007ffd5e670230
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffdde536d30 5 bytes JMP 00007ffd5e6703f0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ffdde536f90 5 bytes JMP 00007ffd5e6701d0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtModifyBootEntry 00007ffdde537150 5 bytes JMP 00007ffd5e670240
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeKey 00007ffdde5371b0 5 bytes JMP 00007ffd5e6704b0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 00007ffdde5371d0 5 bytes JMP 00007ffd5e6704c0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenEventPair 00007ffdde537230 5 bytes JMP 00007ffd5e6702f0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenIoCompletion 00007ffdde537250 5 bytes JMP 00007ffd5e670350
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenMutant 00007ffdde537310 5 bytes JMP 00007ffd5e670290
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSemaphore 00007ffdde5373d0 5 bytes JMP 00007ffd5e6702b0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenThread 00007ffdde537430 5 bytes JMP 00007ffd5e670370
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenTimer 00007ffdde537450 5 bytes JMP 00007ffd5e670330
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 00007ffdde537a70 5 bytes JMP 00007ffd5e670460
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtResumeProcess 00007ffdde537d30 5 bytes JMP 00007ffd5e670420
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 00007ffdde537e90 5 bytes JMP 00007ffd5e670250
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetBootOptions 00007ffdde537eb0 5 bytes JMP 00007ffd5e670260
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffdde537ef0 5 bytes JMP 00007ffd5e670400
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ffdde5382d0 5 bytes JMP 00007ffd5e6701e0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemPowerState 00007ffdde5382f0 5 bytes JMP 00007ffd5e670200
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ffdde538410 5 bytes JMP 00007ffd5e6701f0
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendProcess 00007ffdde5384f0 5 bytes JMP 00007ffd5e670430
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSuspendThread 00007ffdde538510 5 bytes JMP 00007ffd5e670450
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ffdde538530 5 bytes JMP 00007ffd5e670210
.text C:\WINDOWS\system32\taskhostw.exe[1824] C:\WINDOWS\SYSTEM32\ntdll.dll!NtVdmControl 00007ffdde538750 5 bytes JMP 00007ffd5e670270
? C:\WINDOWS\SYSTEM32\iertutil.dll [7884] entry point in ".rdata" section 0000000072dfcaf0
? C:\WINDOWS\SYSTEM32\iertutil.dll [8732] entry point in ".rdata" section 0000000072dfcaf0
---- Threads - GMER 2.2 ----
Thread C:\WINDOWS\system32\csrss.exe [6556:8668] fffff961a09e4060
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [6088:1124] 00007ffdb4ac838c
Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [6088:7152] 00007ffdb545c680
---- Services - GMER 2.2 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] MessagingService_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] OneSyncSvc_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] PimIndexMaintenanceSvc_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [MANUAL] UnistoreSvc_8dbfcd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] UserDataSvc_8dbfcd <-- ROOTKIT !!!
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\MS_002515_00_07D2_60^823CB2ED9AB6B9C849287EE9C9AEA149@Timestamp 0xEC 0x4B 0x2F 0xCC ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\a1841308-3541-4fab-bc81-f71556f20b4a\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\bf566a8d-4d48-4a62-aefa-26597c0d5105\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@ACSettingIndex 18
Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\bf566a8d-4d48-4a62-aefa-26597c0d5105\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 66
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 1477862540
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 4022
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 3954
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@TotalResumeTime 14625
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeBootMgrTime 469
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeAppTime 1682
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeAppStartTimestamp 4507
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeHiberFileTime 1082
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeRestoreImageStartTimestamp 4964
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeIoTime 862
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeDecompressTime 267
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeKernelSwitchTimestamp 6189
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelReturnFromHandlerTimestamp 6245
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@SleeperThreadEndTimestamp 13173
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@TimeStampCounterAtSwitchTime 6218
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelReturnSystemPowerState 14616
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberHiberFileTime 5740
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberInitTime 90
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@TotalHibernateTime 12997
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeHiberFileTime 5196
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeInitTime 71
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeSharedBufferTime 9
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@DeviceResumeTime 1410
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelAnimationTime 108
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelPagesProcessed 426473
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelPagesWritten 0x0A 0x1D 0x02 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@BootPagesProcessed 34806
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@BootPagesWritten 0x24 0x3F 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeDecompressRate 73
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberChecksumTime 134
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberChecksumIoTime 20
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelChecksumTime 99
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelChecksumIoTime 35
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@KernelResumeIoCpuTime 4224
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HiberIoCpuTime 814
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@HybridBootAnimationTime 6958
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@ResumeCompleteTimestamp 0x45 0xFB 0x10 0x04 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@GlassSessionId 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\c8f7337894a6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@Bluetooth_UniqueID {00000000-0000-0000-0000-000000000000}#907F61048447_00000000
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@ConnectionCount 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0003
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0003@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0003@ConnectionCount 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0005
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0005@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0005@ConnectionCount 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@DisplayName Slu?ba zas?l?n? zpr?v_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Type 7
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Action 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Guid 0x16 0x28 0x7A 0x2D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@Data0 0x75 0x18 0xBC 0xA3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd\TriggerInfo\0@DataType0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@DisplayName Hostitel synchronizace_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@DisplayName Data kontakt?_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 6779
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 1664
Reg HKLM\SYSTEM\CurrentControlSet\Services\SynTP\Parameters@DetectTimeMS 447
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@LeaseObtainedTime 1463985219
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@T1 1464028419
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@T2 1464060819
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75d28585-8da2-449d-9034-21b3ec8132ea}@LeaseTerminatesTime 1464071619
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@ImagePath C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@DisplayName ?lo?i?t? u?ivatelsk?ch dat_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@Type 224
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@ImagePath C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@DisplayName P??stup k u?ivatelsk?m dat?m_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd\Security@Security 0x01 0x00 0x04 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_8dbfcd
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated 0xFE 0x9E 0xA0 0x20 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh 0xFE 0x06 0x65 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow 0xFE 0x36 0xDC 0xBE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeTickCount 0xD1 0xF0 0x29 0x06 ...
Reg HKLM\SYSTEM\Setup\Upgrade\NsiMigrationRoot\62\0@Rw 0x64 0x62 0x03 0x00 ...
Reg HKLM\SYSTEM\Setup\Upgrade\NsiMigrationRoot\62\0@RwMask 0x64 0x62 0x03 0x00 ...
Reg HKLM\SYSTEM\Setup\Upgrade\Pnp\CurrentControlSet\Control\DeviceMigration\Devices\SWD\DAFUPNPPROVIDER\UUID:59AA9DE9-7EF0-F0CB-9D7A-D735B3185F7A\Interfaces\{d0875fb4-2196-4c7a-a63d-e416addd60a1}\Properties\{88ad39db-0d0c-4a38-8435-4043826b5c91}\000E@ 0x64 0x62 0x02 0x00 ...
Reg HKLM\SYSTEM\Setup\Upgrade\Pnp\CurrentControlSet\Control\DeviceMigration\Devices\SWD\DAFUPNPPROVIDER\UUID:59AA9DE9-7EF0-F0CB-9D7A-D735B3185F7A\Properties\{88ad39db-0d0c-4a38-8435-4043826b5c91}\000E@ 0x64 0x62 0x02 0x00 ...
---- Disk sectors - GMER 2.2 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.2 ----