GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2011-10-11 14:53:25 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340810A rev.3.39 Running: pr6dq02e.exe; Driver: C:\DOCUME~1\Karolina\USTAWI~1\Temp\kfldqfoc.sys ---- Kernel code sections - GMER 1.0.15 ---- PAGE ntoskrnl.exe!ZwResumeThread 80578E76 1 Byte [CC] {INT 3 } .text atapi.sys F847D852 1 Byte [CC] {INT 3 } ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) ---- Threads - GMER 1.0.15 ---- Thread System [4:136] 8230216D Thread System [4:796] 81DBEB90 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeLo -900250816 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeHi 30181374 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeLo -900050528 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeHi 30181374 ---- EOF - GMER 1.0.15 ----