Hundert30 | 14.02.2013 20:25 | GMER: Code:
GMER 2.0.18454 - hxxp://www.gmer.net
Rootkit scan 2013-02-14 20:21:57
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-5 Maxtor_6B200M0 rev.BANC1B70 189,92GB
Running: gmer_2.0.18454.exe; Driver: C:\Users\Georg\AppData\Local\Temp\fgloqpob.sys
---- System - GMER 2.0 ----
SSDT 8E516846 ZwCreateSection
SSDT 8E516850 ZwRequestWaitReplyPort
SSDT 8E51684B ZwSetContextThread
SSDT 8E516855 ZwSetSecurityObject
SSDT 8E51685A ZwSystemDebugControl
SSDT 8E5167E7 ZwTerminateProcess
---- Kernel code sections - GMER 2.0 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82A3F9E9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A791C2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 82A8030C 4 Bytes [46, 68, 51, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 82A80668 4 Bytes [50, 68, 51, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1597 82A806AC 4 Bytes [4B, 68, 51, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1613 82A80728 4 Bytes [55, 68, 51, 8E]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1667 82A8077C 4 Bytes [5A, 68, 51, 8E]
.text ...
? System32\Drivers\spwj.sys Das System kann den angegebenen Pfad nicht finden. !
PAGE ataport.SYS!DllUnload + 1 88CEDAD7 4 Bytes JMP 84A731D9
.text USBPORT.SYS!DllUnload 8D843DB9 5 Bytes JMP 85C341D8
.text ae980za4.SYS 8FD7A000 12 Bytes [44, 98, E1, 82, EE, 96, E1, ...]
.text ae980za4.SYS 8FD7A00D 9 Bytes [77, E1, 82, 48, 9B, E1, 82, ...] {JA 0xffffffe3; OR BYTE [EAX-0x65], 0xe1; ADD BYTE [EAX], 0x0}
.text ae980za4.SYS 8FD7A017 170 Bytes [00, DE, C7, B1, 88, E6, C5, ...]
.text ae980za4.SYS 8FD7A0C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ae980za4.SYS 8FD7A0CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text ad1ydun9.SYS 8FDB1000 12 Bytes [44, 98, E1, 82, EE, 96, E1, ...]
.text ad1ydun9.SYS 8FDB100D 9 Bytes [77, E1, 82, 48, 9B, E1, 82, ...] {JA 0xffffffe3; OR BYTE [EAX-0x65], 0xe1; ADD BYTE [EAX], 0x0}
.text ad1ydun9.SYS 8FDB1017 170 Bytes [00, DE, C7, B1, 88, E6, C5, ...]
.text ad1ydun9.SYS 8FDB10C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ad1ydun9.SYS 8FDB10CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 2.0 ----
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtCreateFile + 6 774A55CE 4 Bytes [28, 90, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtCreateFile + B 774A55D3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtMapViewOfSection + 6 774A5C2E 4 Bytes [28, 93, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtMapViewOfSection + B 774A5C33 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenFile + 6 774A5CDE 4 Bytes [68, 90, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenFile + B 774A5CE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenProcess + 6 774A5D8E 4 Bytes [A8, 91, D9, 00] {TEST AL, 0x91; FLD DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenProcess + B 774A5D93 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenProcessToken + B 774A5DA3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenProcessTokenEx + 6 774A5DAE 4 Bytes [A8, 92, D9, 00] {TEST AL, 0x92; FLD DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenProcessTokenEx + B 774A5DB3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenThread + 6 774A5E0E 4 Bytes [68, 91, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenThread + B 774A5E13 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenThreadToken + 6 774A5E1E 4 Bytes [68, 92, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenThreadToken + B 774A5E23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtOpenThreadTokenEx + B 774A5E33 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtQueryAttributesFile + 6 774A5F3E 4 Bytes [A8, 90, D9, 00] {TEST AL, 0x90; FLD DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtQueryAttributesFile + B 774A5F43 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtQueryFullAttributesFile + B 774A5FF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtSetInformationFile + 6 774A663E 4 Bytes [28, 91, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtSetInformationFile + B 774A6643 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtSetInformationThread + 6 774A669E 4 Bytes [28, 92, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtSetInformationThread + B 774A66A3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtUnmapViewOfSection + 6 774A69BE 4 Bytes [68, 93, D9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2756] ntdll.dll!NtUnmapViewOfSection + B 774A69C3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtCreateFile + 6 774A55CE 4 Bytes [28, 58, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtCreateFile + B 774A55D3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtMapViewOfSection + 6 774A5C2E 4 Bytes [28, 5B, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtMapViewOfSection + B 774A5C33 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenFile + 6 774A5CDE 4 Bytes [68, 58, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenFile + B 774A5CE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenProcess + 6 774A5D8E 4 Bytes [A8, 59, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenProcess + B 774A5D93 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenProcessToken + 6 774A5D9E 4 Bytes CALL 764A6CFC C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenProcessToken + B 774A5DA3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenProcessTokenEx + 6 774A5DAE 4 Bytes [A8, 5A, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenProcessTokenEx + B 774A5DB3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenThread + 6 774A5E0E 4 Bytes [68, 59, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenThread + B 774A5E13 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenThreadToken + 6 774A5E1E 4 Bytes [68, 5A, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenThreadToken + B 774A5E23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenThreadTokenEx + 6 774A5E2E 4 Bytes CALL 764A6D8D C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtOpenThreadTokenEx + B 774A5E33 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtQueryAttributesFile + 6 774A5F3E 4 Bytes [A8, 58, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtQueryAttributesFile + B 774A5F43 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtQueryFullAttributesFile + 6 774A5FEE 4 Bytes CALL 764A6F4B C:\Windows\system32\SHELL32.dll (Allgemeine Windows-Shell-DLL/Microsoft Corporation)
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtQueryFullAttributesFile + B 774A5FF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtSetInformationFile + 6 774A663E 4 Bytes [28, 59, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtSetInformationFile + B 774A6643 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtSetInformationThread + 6 774A669E 4 Bytes [28, 5A, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtSetInformationThread + B 774A66A3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtUnmapViewOfSection + 6 774A69BE 4 Bytes [68, 5B, 0F, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2764] ntdll.dll!NtUnmapViewOfSection + B 774A69C3 1 Byte [E2]
---- Kernel IAT/EAT - GMER 2.0 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88A20042] \SystemRoot\System32\Drivers\spwj.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88A206D6] \SystemRoot\System32\Drivers\spwj.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88A20800] \SystemRoot\System32\Drivers\spwj.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88A2013E] \SystemRoot\System32\Drivers\spwj.sys
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortNotification] 000003E3
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortQuerySystemTime] 8B24568B
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortReadPortUchar] 50522046
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortStallExecution] FFED23E8
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortWritePortUchar] 08C483FF
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortWritePortUlong] 0874FF85
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortGetPhysicalAddress] FF53006A
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 08C483D7
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortGetScatterGatherList] 81107D8B
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortGetParentBusType] 0003E5FF
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortRequestCallback] 0F840F00
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 81000001
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0003E3FF
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortCompleteRequest] EC840F00
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortCopyMemory] 8B000000
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortEtwTraceLog] 0001F88E
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] FC8E0B00
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 0F000001
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 0000DA84
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortReadPortBufferUshort] ECF2E800
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortInitialize] [8E8BFFFF] \SystemRoot\system32\drivers\RTKVAC.SYS (Realtek AC'97 Audio Driver (WDM)/Realtek Semiconductor Corp.)
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortGetDeviceBase] 000001F8
IAT \SystemRoot\System32\Drivers\ae980za4.SYS[ataport.SYS!AtaPortDeviceStateChange] 01E08E01
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortNotification] 00147880
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortQuerySystemTime] 78800C75
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortReadPortUchar] 06750015
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortStallExecution] C25DC033
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortWritePortUchar] 458B0008
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortWritePortUlong] 6A006A08
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 50056A24
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 005AB7E8
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortGetScatterGatherList] 0001B800
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortGetParentBusType] C25D0000
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortRequestCallback] CCCC0008
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortWritePortBufferUshort] CCCCCCCC
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortGetUnCachedExtension] CCCCCCCC
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortCompleteRequest] CCCCCCCC
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortCopyMemory] 53EC8B55
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortEtwTraceLog] 800C5D8B
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 7500117B
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 127B806A
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 80647500
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7500137B
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortInitialize] 157B805E
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortGetDeviceBase] 56587500
IAT \SystemRoot\System32\Drivers\ad1ydun9.SYS[ataport.SYS!AtaPortDeviceStateChange] 8008758B
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
IAT C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2316] @ C:\Windows\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [754FFFF6] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation)
---- Registry - GMER 2.0 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA0 0xC4 0x1E 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x31 0x10 0x99 0x4C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xF5 0xEA 0x7D 0x19 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0x1F 0xDA 0x94 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xA0 0xC4 0x1E 0xCA ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x31 0x10 0x99 0x4C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xF5 0xEA 0x7D 0x19 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0xF9 0xFB 0xC8 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
---- EOF - GMER 2.0 ---- |