GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-07-13 21:54:41 Windows 5.1.2600 Dodatek Service Pack 3 Running: sxt4vsix.exe; Driver: c:\Temp\uwliipow.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB73863A0, 0x592C35, 0xE8000020] init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xB63F7A00] init C:\WINDOWS\System32\Drivers\sunkfilt.sys entry point in "init" section [0xB84782E0] .text c:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl section is writeable [0xB37DB000, 0x2892, 0xE8000020] .vmp2 c:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl entry point in ".vmp2" section [0xB37FE050] ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x38 0xDA 0x8F 0x83 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x38 0xDA 0x8F 0x83 ... Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL CC85D412455BFE5768662051F61D660AD09247CF4017736E093334225FAEA30BF51D572A38236ED05DD7A0877B9AAECAB3255D2025B36171C2A0572CBDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D6794BA7FD869164D6794A9C6AECB7A5D14072293B018B015D6A236D00865C0A46E789B3C0312E532E1F6587EF6AEBB6A2FC2BCEEFC0987173ACD7B4EC4454C48E8A3D153685182CC3D7FBA89D9A7D16E8FB4B4F95CDC610CC8E91D2A0F01B37E3C1E126807D019C885026CE77D35AA20FE22C2AC04145B41BD5F82CA5470948EADB315ED265D668D29D098B9A0B844A5B58222F54C4555B33DE8998A257DCF75E887194AAF546D347D916D12A627E252509E93353397F21A4B18D1B6B9A60BE37B0CDFD8342A730A37BE9EFA18088CB2CE1559BF584A1C58D0CEA091EA7E2FBC578BAE696466049173A5E16DA0F70E04175B3B5E022DFE0D1BC57E51B6A9E81B54A1503E18236C7F3167F15D10A574396FB5864F97A70986DC886820BEE42AC92C3F908E4A10BEBDD47B0E2BDA5715F985418942A6B0F0C82BF65E9BC9FB274AFC2AC2061B70D068A3A9F73118E4061FE96A97DCE0D72C8A7E44655741525ACFC9F93B424B9C3D534B8FF63A043A22B710F309B899BB793735790756B2DD7F45F71DD357C ---- EOF - GMER 1.0.15 ----