GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2005-01-01 03:30:03 Windows 5.1.2600 Dodatek Service Pack 3 Running: euybtz50.exe ---- Services - GMER 2.1 ---- Service C:\WINDOWS\System32\Drivers\a9f31c9f453ee82.sys (*** hidden *** ) [BOOT] a9f31c9f453ee82 <-- ROOTKIT !!! ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@ImagePath \SystemRoot\System32\Drivers\a9f31c9f453ee82.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@Group Boot Bus Extender Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@ErrorControl 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@Tag 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82@DisplayName syshost.exe Reg HKLM\SYSTEM\CurrentControlSet\Services\a9f31c9f453ee82 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE6 0x14 0xC6 0x16 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0x66 0x4F 0x09 ... Reg HKLM\SOFTWARE\Classes\CLSID\{24e73457-2467-4717-a120-aed7b07a1920}@Model 18 Reg HKLM\SOFTWARE\Classes\CLSID\{24e73457-2467-4717-a120-aed7b07a1920}@Therad 30 Reg HKLM\SOFTWARE\Classes\CLSID\{24e73457-2467-4717-a120-aed7b07a1920}@MData 0x2B 0x8F 0x78 0x29 ... Reg HKLM\SOFTWARE\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}@scansk 0x1C 0x76 0xF2 0xE6 ... ---- EOF - GMER 2.1 ----