kontrola logu
Napsal: 20 led 2010 14:01
U tohoto příspěvku je ve foru černá tečka, nevím co to je, asi jsem něco udělal blbě - když mi to vysvětlíte, polepším se.
Dobrý den, prosím o kontrolu logu z gmeru, popř. o radu jak postupovat s následujícím problémem.
Zhruba po 20ti minutách zmizí u ikon na ploše písmo, nebo je rozmazané. Následně se místo ikon a ostatních hlášek při ukončení otevřených programu zobrazují jen bílé obdélníky. Při vypínání pomocí nabídky start je to stejné - vypínám nebo restartuji jen po paměti. Na příkaz vypnutí nebo restart to stejně nereaguje a musím to vypnout vypínačem na tvrdo.
Hijackthis je čistý, stejně tak mwav. Avast nenalézá nic, stejně tak spyware doctor i spyware terminator.
Dík za pomoc
log1:
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2010-01-20 09:47:13
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xB9E6D4FE]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xB9E78CB0]
---- Devices - GMER 1.0.15 ----
Device 89DCB1F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Modules - GMER 1.0.15 ----
Module _________ B9DCF000-B9DE7000 (98304 bytes)
---- EOF - GMER 1.0.15 ----
log.2:
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2010-01-20 13:39:10
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAB4C56B8]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwCreateKey [0xB9D6782E]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xB9E6CC70]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xB9D81282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xB9D81474]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwDeleteKey [0xB9D6853A]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwDeleteValueKey [0xB9D67F4E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAB4C514C]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xB9E6D4FE]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xB9E78CB0]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwOpenKey [0xB9D67ACC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAB4C508C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAB4C50F0]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwQueryKey [0xB9E6D51E]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwQueryValueKey [0xB9D67D52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xB9D93422]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAB4C572E]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xB9E78450]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwSetValueKey [0xB9D682CA]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xB9D80F32]
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89AF0BF8
INT 0x63 ? 89D5DBF8
INT 0x83 ? 89D5DBF8
INT 0x83 ? 89D5DBF8
INT 0x83 ? 89AF0BF8
INT 0x83 ? 89D5DBF8
INT 0x84 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xB4 ? 89AF0BF8
---- Kernel code sections - GMER 1.0.15 ----
? speo.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B907B8AC 5 Bytes JMP 89AF01D8
.text awz6t687.SYS B8F71384 1 Byte [20]
.text awz6t687.SYS B8F71384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text awz6t687.SYS B8F713AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text awz6t687.SYS B8F713C4 3 Bytes [00, 00, 00]
.text awz6t687.SYS B8F713C9 1 Byte [00]
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EBBD92] speo.sys
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[908] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[908] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device 89DCB1F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-0 89AEE1F8
Device \Driver\sptd \Device\1074650142 speo.sys
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89DCD1F8
Device \Driver\dmio \Device\DmControl\DmConfig 89DCD1F8
Device \Driver\dmio \Device\DmControl\DmPnP 89DCD1F8
Device \Driver\dmio \Device\DmControl\DmInfo 89DCD1F8
Device \Driver\usbuhci \Device\USBPDO-1 89AEE1F8
Device \Driver\usbuhci \Device\USBPDO-2 89AEE1F8
Device \Driver\usbehci \Device\USBPDO-3 89AC6500
Device \Driver\usbuhci \Device\USBPDO-4 89AEE1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{339E23C4-64DB-4036-9C25-4DBE3B205913} 897C9500
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-5 89AEE1F8
Device \Driver\usbuhci \Device\USBPDO-6 89AEE1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89D5E1F8
Device \Driver\usbehci \Device\USBPDO-7 89AC6500
Device \Driver\Cdrom \Device\CdRom0 89754220
Device \FileSystem\Rdbss \Device\FsWrap 89B88678
Device \Driver\Cdrom \Device\CdRom1 89754220
Device \Driver\atapi \Device\Ide\IdePort0 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort1 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort2 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort3 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort4 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort5 8976D3C8
Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-14 8976D3C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 8976D3C8
Device \Driver\Cdrom \Device\CdRom2 89754220
Device \Driver\Cdrom \Device\CdRom3 89754220
Device \Driver\Cdrom \Device\CdRom4 89754220
Device \Driver\Cdrom \Device\CdRom5 89754220
Device \Driver\NetBT \Device\NetBt_Wins_Export 897C9500
Device \Driver\Cdrom \Device\CdRom6 89754220
Device \Driver\NetBT \Device\NetbiosSmb 897C9500
Device \FileSystem\Srv \Device\LanmanServer 88B828C0
Device \Driver\PCI_PNP3892 \Device\0000004f speo.sys
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBFDO-0 89AEE1F8
Device \Driver\usbuhci \Device\USBFDO-1 89AEE1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88BF9500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89BBAFB0
Device \Driver\usbuhci \Device\USBFDO-2 89AEE1F8
Device 88BF9500
Device 89BBAFB0
Device \Driver\usbehci \Device\USBFDO-3 89AC6500
Device \FileSystem\Npfs \Device\NamedPipe 89C46120
Device \Driver\usbuhci \Device\USBFDO-4 89AEE1F8
Device \Driver\Ftdisk \Device\FtControl 89D5E1F8
Device \FileSystem\Msfs \Device\Mailslot 899CDF70
Device \Driver\usbuhci \Device\USBFDO-5 89AEE1F8
Device \Driver\usbuhci \Device\USBFDO-6 89AEE1F8
Device \Driver\usbehci \Device\USBFDO-7 89AC6500
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target5Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target3Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target0Lun0 89085460
Device \Driver\vax347s \Device\Scsi\vax347s1 89DCC1F8
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target4Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target2Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target1Lun0 89085460
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 89B9B2A8
Device 89AB0FB0
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module _________ B9DCF000-B9DE7000 (98304 bytes)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9C 0x18 0x4E 0x0D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xB7 0x2D 0xAE 0xDB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x12 0x46 0xF6 0xA2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xCC 0x74 0x25 0xD6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0x26 0x6D 0x13 0x6B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43@ujdew 0x79 0xD2 0xF6 0x4E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44@ujdew 0x95 0xA5 0x76 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45@ujdew 0xC2 0xAF 0x41 0xA8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg40@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg41@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg42
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg42@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg43
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg43@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg43@ljej40 0xBB 0x2B 0x02 0x4B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg44
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg44@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg44@ljej40 0xBB 0x2B 0x02 0x4B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg45
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg45@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg45@ljej40 0xB8 0x2B 0x02 0x4B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9C 0x18 0x4E 0x0D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xB7 0x2D 0xAE 0xDB ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x12 0x46 0xF6 0xA2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xCC 0x74 0x25 0xD6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0x26 0x6D 0x13 0x6B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43@ujdew 0x79 0xD2 0xF6 0x4E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44@ujdew 0x95 0xA5 0x76 0x75 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45@ujdew 0xC2 0xAF 0x41 0xA8 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{06CC7CA1-AC59-2353-4175-E60D24B6D141}\InProcServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{06CC7CA1-AC59-2353-4175-E60D24B6D141}\InProcServer32@oacadfciennjnmfnilkmecpjpajllj 0x6B 0x61 0x61 0x70 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{06CC7CA1-AC59-2353-4175-E60D24B6D141}\InProcServer32@nacajeidhhfnmllalgahnakicebm 0x6A 0x61 0x61 0x70 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- EOF - GMER 1.0.15 ----
Dobrý den, prosím o kontrolu logu z gmeru, popř. o radu jak postupovat s následujícím problémem.
Zhruba po 20ti minutách zmizí u ikon na ploše písmo, nebo je rozmazané. Následně se místo ikon a ostatních hlášek při ukončení otevřených programu zobrazují jen bílé obdélníky. Při vypínání pomocí nabídky start je to stejné - vypínám nebo restartuji jen po paměti. Na příkaz vypnutí nebo restart to stejně nereaguje a musím to vypnout vypínačem na tvrdo.
Hijackthis je čistý, stejně tak mwav. Avast nenalézá nic, stejně tak spyware doctor i spyware terminator.
Dík za pomoc
log1:
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2010-01-20 09:47:13
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xB9E6D4FE]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xB9E78CB0]
---- Devices - GMER 1.0.15 ----
Device 89DCB1F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Modules - GMER 1.0.15 ----
Module _________ B9DCF000-B9DE7000 (98304 bytes)
---- EOF - GMER 1.0.15 ----
log.2:
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2010-01-20 13:39:10
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAB4C56B8]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwCreateKey [0xB9D6782E]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xB9E6CC70]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xB9D81282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xB9D81474]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwDeleteKey [0xB9D6853A]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwDeleteValueKey [0xB9D67F4E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAB4C514C]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xB9E6D4FE]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xB9E78CB0]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwOpenKey [0xB9D67ACC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAB4C508C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAB4C50F0]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwQueryKey [0xB9E6D51E]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwQueryValueKey [0xB9D67D52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xB9D93422]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAB4C572E]
SSDT vax347b.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xB9E78450]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwSetValueKey [0xB9D682CA]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xB9D80F32]
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89D5DBF8
INT 0x63 ? 89AF0BF8
INT 0x63 ? 89D5DBF8
INT 0x83 ? 89D5DBF8
INT 0x83 ? 89D5DBF8
INT 0x83 ? 89AF0BF8
INT 0x83 ? 89D5DBF8
INT 0x84 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xA4 ? 89AF0BF8
INT 0xB4 ? 89AF0BF8
---- Kernel code sections - GMER 1.0.15 ----
? speo.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B907B8AC 5 Bytes JMP 89AF01D8
.text awz6t687.SYS B8F71384 1 Byte [20]
.text awz6t687.SYS B8F71384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text awz6t687.SYS B8F713AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text awz6t687.SYS B8F713C4 3 Bytes [00, 00, 00]
.text awz6t687.SYS B8F713C9 1 Byte [00]
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EBBD92] speo.sys
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\awz6t687.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[908] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[908] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device 89DCB1F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-0 89AEE1F8
Device \Driver\sptd \Device\1074650142 speo.sys
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89DCD1F8
Device \Driver\dmio \Device\DmControl\DmConfig 89DCD1F8
Device \Driver\dmio \Device\DmControl\DmPnP 89DCD1F8
Device \Driver\dmio \Device\DmControl\DmInfo 89DCD1F8
Device \Driver\usbuhci \Device\USBPDO-1 89AEE1F8
Device \Driver\usbuhci \Device\USBPDO-2 89AEE1F8
Device \Driver\usbehci \Device\USBPDO-3 89AC6500
Device \Driver\usbuhci \Device\USBPDO-4 89AEE1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{339E23C4-64DB-4036-9C25-4DBE3B205913} 897C9500
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-5 89AEE1F8
Device \Driver\usbuhci \Device\USBPDO-6 89AEE1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 89D5E1F8
Device \Driver\usbehci \Device\USBPDO-7 89AC6500
Device \Driver\Cdrom \Device\CdRom0 89754220
Device \FileSystem\Rdbss \Device\FsWrap 89B88678
Device \Driver\Cdrom \Device\CdRom1 89754220
Device \Driver\atapi \Device\Ide\IdePort0 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort1 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort2 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort3 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort4 8976D3C8
Device \Driver\atapi \Device\Ide\IdePort5 8976D3C8
Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-14 8976D3C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 8976D3C8
Device \Driver\Cdrom \Device\CdRom2 89754220
Device \Driver\Cdrom \Device\CdRom3 89754220
Device \Driver\Cdrom \Device\CdRom4 89754220
Device \Driver\Cdrom \Device\CdRom5 89754220
Device \Driver\NetBT \Device\NetBt_Wins_Export 897C9500
Device \Driver\Cdrom \Device\CdRom6 89754220
Device \Driver\NetBT \Device\NetbiosSmb 897C9500
Device \FileSystem\Srv \Device\LanmanServer 88B828C0
Device \Driver\PCI_PNP3892 \Device\0000004f speo.sys
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBFDO-0 89AEE1F8
Device \Driver\usbuhci \Device\USBFDO-1 89AEE1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88BF9500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89BBAFB0
Device \Driver\usbuhci \Device\USBFDO-2 89AEE1F8
Device 88BF9500
Device 89BBAFB0
Device \Driver\usbehci \Device\USBFDO-3 89AC6500
Device \FileSystem\Npfs \Device\NamedPipe 89C46120
Device \Driver\usbuhci \Device\USBFDO-4 89AEE1F8
Device \Driver\Ftdisk \Device\FtControl 89D5E1F8
Device \FileSystem\Msfs \Device\Mailslot 899CDF70
Device \Driver\usbuhci \Device\USBFDO-5 89AEE1F8
Device \Driver\usbuhci \Device\USBFDO-6 89AEE1F8
Device \Driver\usbehci \Device\USBFDO-7 89AC6500
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target5Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target3Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target0Lun0 89085460
Device \Driver\vax347s \Device\Scsi\vax347s1 89DCC1F8
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target4Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target2Lun0 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871 89085460
Device \Driver\awz6t687 \Device\Scsi\awz6t6871Port7Path0Target1Lun0 89085460
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 89B9B2A8
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 89B9B2A8
Device 89AB0FB0
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module _________ B9DCF000-B9DE7000 (98304 bytes)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9C 0x18 0x4E 0x0D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xB7 0x2D 0xAE 0xDB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x12 0x46 0xF6 0xA2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xCC 0x74 0x25 0xD6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0x26 0x6D 0x13 0x6B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43@ujdew 0x79 0xD2 0xF6 0x4E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44@ujdew 0x95 0xA5 0x76 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45@ujdew 0xC2 0xAF 0x41 0xA8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg40@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg41@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg42
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg42@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg43
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg43@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg43@ljej40 0xBB 0x2B 0x02 0x4B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg44
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg44@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg44@ljej40 0xBB 0x2B 0x02 0x4B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg45
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg45@ujdew 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\vax347s\Config\jdgg45@ljej40 0xB8 0x2B 0x02 0x4B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9C 0x18 0x4E 0x0D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xB7 0x2D 0xAE 0xDB ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x12 0x46 0xF6 0xA2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xCC 0x74 0x25 0xD6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg42@ujdew 0x26 0x6D 0x13 0x6B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg43@ujdew 0x79 0xD2 0xF6 0x4E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg44@ujdew 0x95 0xA5 0x76 0x75 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg45@ujdew 0xC2 0xAF 0x41 0xA8 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{06CC7CA1-AC59-2353-4175-E60D24B6D141}\InProcServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{06CC7CA1-AC59-2353-4175-E60D24B6D141}\InProcServer32@oacadfciennjnmfnilkmecpjpajllj 0x6B 0x61 0x61 0x70 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{06CC7CA1-AC59-2353-4175-E60D24B6D141}\InProcServer32@nacajeidhhfnmllalgahnakicebm 0x6A 0x61 0x61 0x70 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- EOF - GMER 1.0.15 ----