GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-09-12 13:11:27 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST316081 rev.3.CH 0,00MB Running: 5t8vtjli.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\agdirpog.sys ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\Tcpip \Device\Ip {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys AttachedDevice \Driver\Tcpip \Device\Tcp {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys AttachedDevice \Driver\Tcpip \Device\Udp {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys AttachedDevice \Driver\Tcpip \Device\RawIp {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@RequireSignedAppInit_DLLs 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----