GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-03-30 21:58:57 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 IC25N040ATMR04-0 rev.MO2OAD4A 37,26GB Running: 9jrsmv0f.exe; Driver: C:\DOCUME~1\riky\USTAWI~1\Temp\uflyrpoc.sys ---- Kernel code sections - GMER 2.1 ---- init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xF727D900] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 1150 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@DhcpServer 255.255.255.255 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@Lease 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@LeaseObtainedTime 1427735579 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@T1 1427735579 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@T2 1427735579 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@LeaseTerminatesTime 2147483647 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@IPAutoconfigurationAddress 169.254.171.11 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@AddressType 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@DhcpIPAddress 169.254.171.11 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}@DhcpRetryTime 325 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@DhcpIPAddress 169.254.171.11 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@DhcpSubnetMask 255.255.0.0 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@DhcpServer 255.255.255.255 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@Lease 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@LeaseObtainedTime 1427735579 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@T1 1427735579 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@T2 1427735579 Reg HKLM\SYSTEM\CurrentControlSet\Services\{73A0D28A-609B-485D-8A7C-F8A23D6DAC01}\Parameters\Tcpip@LeaseTerminatesTime 2147483647 ---- EOF - GMER 2.1 ----