DanTheManCOF | 19.06.2010 18:19 | GMER Logfile: Code:
GMER 1.0.15.15281 - hxxp://www.gmer.net
Rootkit scan 2010-06-19 19:09:38
Windows 5.1.2600 Service Pack 3
Running: sbxil26d.exe; Driver: C:\DOKUME~1\Besitzer\LOKALE~1\Temp\pflyrpow.sys
---- System - GMER 1.0.15 ----
SSDT F7C1CEA3 ZwDeleteKey
SSDT F7C1CEAD ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey [0xF74D2FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF74D3340]
SSDT F7C1CEB2 ZwLoadKey
SSDT sptd.sys ZwOpenKey [0xF74CD0B0]
SSDT sptd.sys ZwQueryKey [0xF74D3418]
SSDT sptd.sys ZwQueryValueKey [0xF74D3298]
SSDT F7C1CEBC ZwReplaceKey
SSDT F7C1CEB7 ZwRestoreKey
---- Kernel code sections - GMER 1.0.15 ----
? C:\WINDOWS\system32\drivers\sptd.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
.text USBPORT.SYS!DllUnload F662C8AC 5 Bytes JMP 861C83E8
? System32\Drivers\aq50lhfq.SYS Das System kann den angegebenen Pfad nicht finden. !
---- User code sections - GMER 1.0.15 ----
.text C:\Dokumente und Einstellungen\Besitzer\Desktop\sbxil26d.exe[792] ntdll.dll!NtClose + 6 7C91CFF4 4 Bytes [CC, A9, 15, 00]
.text C:\Dokumente und Einstellungen\Besitzer\Desktop\sbxil26d.exe[792] ntdll.dll!NtDeviceIoControlFile + 6 7C91D284 4 Bytes [D0, A9, 15, 00]
.text C:\Dokumente und Einstellungen\Besitzer\Desktop\sbxil26d.exe[792] ntdll.dll!NtQueryDirectoryFile + 6 7C91D774 4 Bytes [EC, AB, 15, 00]
.text C:\Dokumente und Einstellungen\Besitzer\Desktop\sbxil26d.exe[792] ntdll.dll!NtResumeThread + 6 7C91DB44 4 Bytes [E4, AB, 15, 00]
.text C:\WINDOWS\Explorer.EXE[1508] ntdll.dll!NtClose + 6 7C91CFF4 4 Bytes [CC, A9, DF, 00]
.text C:\WINDOWS\Explorer.EXE[1508] ntdll.dll!NtDeviceIoControlFile + 6 7C91D284 4 Bytes [D0, A9, DF, 00]
.text C:\WINDOWS\Explorer.EXE[1508] ntdll.dll!NtQueryDirectoryFile + 6 7C91D774 4 Bytes [EC, AB, DF, 00] {IN AL, DX ; STOSD ; FILD WORD [EAX]}
.text C:\WINDOWS\Explorer.EXE[1508] ntdll.dll!NtResumeThread + 6 7C91DB44 4 Bytes [E4, AB, DF, 00] {IN AL, 0xab; FILD WORD [EAX]}
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F74E406C] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74E4018] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F75069AE] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F74E406C] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74CDAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74CDC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74CDB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74CE748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74CE61E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74E329A] sptd.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 863661E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{98705C23-14F7-48E9-B56C-03F1BB097EE4} 85AF91E8
Device \Driver\usbuhci \Device\USBPDO-0 861DC790
Device \Driver\usbuhci \Device\USBPDO-1 861DC790
Device \Driver\usbuhci \Device\USBPDO-2 861DC790
Device \Driver\usbuhci \Device\USBPDO-3 861DC790
Device \Driver\PCI_NTPNP8976 \Device\00000047 sptd.sys
Device \Driver\PCI_NTPNP8976 \Device\00000047 sptd.sys
Device \Driver\usbehci \Device\USBPDO-4 861CE790
Device \Driver\Ftdisk \Device\HarddiskVolume1 863D31E8
Device \Driver\Cdrom \Device\CdRom0 861811E8
Device \Driver\Cdrom \Device\CdRom1 861811E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7446B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7446B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7446B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [F7446B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7446B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\NetBT \Device\NetBt_Wins_Export 85AF91E8
Device \Driver\NetBT \Device\NetbiosSmb 85AF91E8
Device \Driver\usbuhci \Device\USBFDO-0 861DC790
Device \Driver\usbuhci \Device\USBFDO-1 861DC790
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8598A1E8
Device \Driver\usbuhci \Device\USBFDO-2 861DC790
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8598A1E8
Device \Driver\usbuhci \Device\USBFDO-3 861DC790
Device \Driver\usbehci \Device\USBFDO-4 861CE790
Device \Driver\Ftdisk \Device\FtControl 863D31E8
Device \Driver\aq50lhfq \Device\Scsi\aq50lhfq1Port3Path0Target0Lun0 8615D1E8
Device \Driver\aq50lhfq \Device\Scsi\aq50lhfq1 8615D1E8
Device \FileSystem\Cdfs \Cdfs 8604A298
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xAE 0xC8 0x85 0x38 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x1B 0x25 0x9F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD2 0xF9 0x6B 0xE0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xAE 0xC8 0x85 0x38 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x1B 0x25 0x9F 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD1 0xD7 0x87 0xBF ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programme\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xAE 0xC8 0x85 0x38 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x1B 0x25 0x9F 0x43 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD2 0xF9 0x6B 0xE0 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION 4696D627D6287D29D01C6AC60D59C995477D1D4587E2311ACA030972F1F579CE5387E3E0013DCE2896B73CA6A2C40D2083A2477BC2B09137CD1DBD909AC7273A08EC4ED018CAF468CE51185FCB9D10D67EC7BCEB6EBD85AF8639FBD86F100943BC6364309C722CDBC8180E6452A99DF422D16E6ABB1607AE9693B41A293F6E1DE9183665702BB0667851EE5ADF8486AD793B8FF63F19185145FA1CD3679A28F42F501B105C3D48DEF555D21C071D9D25368F97CA74793DAAF9CEAC39FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14075D575E7D6A3B9808C038D530D6EB345290987C4053C4CD26D24510F804668791959545F4134878B034C80FCC427122CA8F0CE133DF5EF7D0D7B4056D49DAC449DCCE78A18E3A1779EF6BEF7198D2BE72D452D4EAE0D05D6449F2E03EC35504BE13B33E52D0E661AAA30746993FB4FDC9C9D2C0C2E12311CFF729403634AFD66191D604DDF31D095052B06F48CB7B5217BAC7150D0FEEE3B698D9C411825813D0981BBA8FB6C00626E35350F4F59E73D55741C30E3860F070C5D41203B6515060483AD7267CC8911F232B4D0D97AB5CB2B42147FE53B813097BC551B1FEB06C9A29C057D44BBFA9DE404B52EF33414C90CA1E190CF8CE69409C2730B52EA1893BA30F34C
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OOSAFEERASE04.00.00.01MSWINDOWS E72B9253426200178C2CFBB1BEE4D256D4A461415101D55C5EF097C750A94245651DB5D48B0096F917F558F99C501B0D6B7474D04F61FEEF97E93857180D84ED0C8DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14075D575E7D6A3B9808C038D530D6EB34528B3B22D46C286E6A98C9E59FA80578EE0460A7792FEBBC1C8FAAB4921FEBBA4EF6E2F5DBA7FA98095BB0E5242E721E7931CC14808D624447437B4010DFADCF40C656FD82D5FE88457CDF6BF423876F16E2F2FA23F98F115E7A7641DF9557E1A195E566DED1C4B0683E2D1859D9E820CBA5CD8A745FCD39C4A8D898FD659506D26037637C1C6E46EFC7C10B074CCDA6556AABF777CE89131129B72ADE982D95E80CC2A75AD533C48D259C6E2C1584BDA10530F9A5FC433C90377A60E61E722D2CDB556EEB47606825C58E69E673EBE5D2AD514D6BC3929341765CA57108502F197C0F75185AD2B5D27C3DADCB4DF7E14081D931AB1F1E3FD66BEEEB4B0B453F5FFB66FEB91FFE706381236C63A83238F281E8E73A30A4A43AFD9328378262C6654CA2CE20476C24D7EE0E5BA9B235352A8FF03BE03D76F105FD04D26AEA50734343E02F8D29369E65451E388D3A3367D776B9F4DAAC7A17879BCAE610E6C6B6C39C126E39410A72F5E74BBD7334E
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OOSAFEERASE03.00.00.01MSWINDOWS FE966B0BAED615377F963E79011325FA66F4D6C8A9A9293EDC50886C8AD8B631EDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14075D575E7D6A3B9808C038D530D6EB345277A2C2AAE52BC9659DBD1111ABB8336E46C504D3C882689E282923700ADEBF6DE2EC3AEAB6FD0A3CF53BB62AF6C3182F157E5D6E852316B0408843C339933172AF4F251BD314950211B705E2ACBCAEF1176E1AB81F62C81152D29425D147712FDCF228ECCB5D36745A15F26BD91D284544D0AA06BE62B73E82BC9B293C635D355BA5FD5363AE8D53AED911B73FC209BA0686906C432CEB39671EF026913A21170FD5F28791C20F6461AE0103D070A866BB1064453DA9C30A107241B6218041ECD29B680580B581EF376279C8B7CCB564B796D0AFF12BF0BA795BCBB96E4E13D0F2ACD30C110A02C16AE7434BCFE130CF43E2950DDBE2F85A9999E4D42E1E43642F68BD2157A47FABA8D2BE8F2A1FEC4C16650583A76A357B5797756B4B534F4BBE4D450C99CF3E8115DE5CDD0AD4157E633008FD37BB53B40FE0F9AC64B00A2C4903995954B6D41CC4682343E9BAA4904AF9182A9F3656A091240283CCDE9A336B5181D7B56C31584273AD13F46CED30649EC5F8AB9D935D22B6B2278A6A7C0FB6A4559DA2E691968B2329DE0CE59
Reg HKLM\SOFTWARE\Classes\.svg@ Adobe.SVGCtl
Reg HKLM\SOFTWARE\Classes\.svg@Content Type image/svg+xml
Reg HKLM\SOFTWARE\Classes\.svgz@ Adobe.SVGCtl
Reg HKLM\SOFTWARE\Classes\.svgz@Content Type image/svg+xml
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xE9 0x02 0x6C 0xFA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0x50 0x93 0xE5 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- Files - GMER 1.0.15 ----
File C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\ICQ\393799368\ReceivedFiles\456056942 ..\ich2 034.jpg 345374 bytes
File C:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\ICQ\393799368\ReceivedFiles\456056942 ..\Thumbs.db 5632 bytes
File C:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\ntuser_mssec.exe 59392 bytes executable
File C:\ntuser_mssec.exe 56832 bytes executable
---- EOF - GMER 1.0.15 ---- --- --- --- |