GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-09-28 21:45:39 Windows 5.1.2600 Dodatek Service Pack 3 Running: is95kd9h.exe; Driver: C:\DOCUME~1\user\USTAWI~1\Temp\kwxdikog.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwClose [0xB528ACF0] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateKey [0xB528ABAC] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDeleteKey [0xB528B160] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDeleteValueKey [0xB528B08A] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDuplicateObject [0xB528A782] SSDT sppe.sys ZwEnumerateKey [0xB9EC6CA2] SSDT sppe.sys ZwEnumerateValueKey [0xB9EC7030] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenKey [0xB528AC86] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenProcess [0xB528A6C2] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenThread [0xB528A726] SSDT sppe.sys ZwQueryKey [0xB9EC7108] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwQueryValueKey [0xB528ADA6] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xB528B22E] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRestoreKey [0xB528AD66] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwSetValueKey [0xB528AEE6] INT 0x63 ? 8A922BF8 INT 0x63 ? 8A922BF8 INT 0x63 ? 8A77CF00 INT 0x63 ? 8A922BF8 INT 0x83 ? 8A77CF00 INT 0xA4 ? 8A77CF00 INT 0xB4 ? 8A77CF00 Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xB5297BAE] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0xB52979D2] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0xB5297B0C] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) NtCreateSection Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject ---- Kernel code sections - GMER 1.0.15 ---- PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP B5297B10 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP B52979D6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP B52935D4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP B5294FFA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B5297BB2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ? sppe.sys Nie mo¿na odnaleŸæ okreœlonego pliku. ! .sfrelocÿÿÿÿsfsync03unknown last section [0xBA0D5000, 0xA20, 0x40000040] C:\WINDOWS\system32\drivers\sfsync03.sys unknown last section [0xBA0D5000, 0xA20, 0x40000040] .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8C6A380, 0x2FF527, 0xE8000020] .text USBPORT.SYS!DllUnload B8C088AC 5 Bytes JMP 8A77C4E0 .text aoss6dbl.SYS B8B54384 1 Byte [20] .text aoss6dbl.SYS B8B54384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...] .text aoss6dbl.SYS B8B543AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...] .text aoss6dbl.SYS B8B543C4 3 Bytes [00, 00, 00] .text aoss6dbl.SYS B8B543C9 1 Byte [00] .text ... ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[748] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP } ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA9040] sppe.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA913C] sppe.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA90BE] sppe.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA97FC] sppe.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA96D2] sppe.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB9048] sppe.sys IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!KfAcquireSpinLock] 000000AD IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!KeGetCurrentIrql] 000000A2 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!KfRaiseIrql] 000000AF IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!KfLowerIrql] 0000009C IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!HalGetInterruptVector] 000000A4 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!HalTranslateBusAddress] 00000072 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!KfReleaseSpinLock] 000000B7 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!READ_PORT_USHORT] 00000093 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[WMILIB.SYS!WmiSystemControl] 000000F7 IAT \SystemRoot\System32\Drivers\aoss6dbl.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINDOWS\system32\services.exe[1124] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[1124] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software) Device \FileSystem\Ntfs \Ntfs 8A9211F8 AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) Device \Driver\sptd \Device\4026489230 sppe.sys Device \Driver\usbuhci \Device\USBPDO-0 8A77A1F8 Device \Driver\usbuhci \Device\USBPDO-1 8A77A1F8 Device \Driver\usbuhci \Device\USBPDO-2 8A77A1F8 Device \Driver\usbuhci \Device\USBPDO-3 8A77A1F8 Device \Driver\usbehci \Device\USBPDO-4 8A777448 AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) Device \Driver\Ftdisk \Device\HarddiskVolume1 8A9931F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{B3A6381D-E539-46DF-A10D-B1F1D4E44ADE} 89EA71F8 Device \Driver\Ftdisk \Device\HarddiskVolume2 8A9931F8 Device \Driver\Cdrom \Device\CdRom0 8A7211F8 Device \Driver\Ftdisk \Device\HarddiskVolume3 8A9931F8 Device \Driver\Cdrom \Device\CdRom1 8A7211F8 Device \Driver\atapi \Device\Ide\IdePort0 [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-5 [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-5 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\atapi \Device\Ide\IdePort1 [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\atapi \Device\Ide\IdePort2 [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\atapi \Device\Ide\IdePort3 [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 [B9E21B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\usbstor \Device\00000080 89E471F8 Device \Driver\usbstor \Device\00000080 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\NetBT \Device\NetBt_Wins_Export 89EA71F8 Device \Driver\NetBT \Device\NetbiosSmb 89EA71F8 Device \Driver\PCI_PNP5480 \Device\0000004d sppe.sys Device \Driver\usbstor \Device\00000087 89E471F8 Device \Driver\usbstor \Device\00000087 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) Device \Driver\usbstor \Device\00000089 89E471F8 Device \Driver\usbstor \Device\00000089 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) Device \Driver\usbuhci \Device\USBFDO-0 8A77A1F8 Device \Driver\usbuhci \Device\USBFDO-1 8A77A1F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89E6E500 Device \Driver\usbuhci \Device\USBFDO-2 8A77A1F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 89E6E500 Device \Driver\usbstor \Device\0000007c 89E471F8 Device \Driver\usbstor \Device\0000007c sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\usbuhci \Device\USBFDO-3 8A77A1F8 Device \Driver\usbstor \Device\0000007d 89E471F8 Device \Driver\usbstor \Device\0000007d sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\usbehci \Device\USBFDO-4 8A777448 Device \Driver\Ftdisk \Device\FtControl 8A9931F8 Device \Driver\usbstor \Device\0000007e 89E471F8 Device \Driver\usbstor \Device\0000007e sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\usbstor \Device\0000007f 89E471F8 Device \Driver\usbstor \Device\0000007f sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\NetBT \Device\NetBT_Tcpip_{D88685C3-CAAE-459E-ABF1-387F7750B763} 89EA71F8 Device \Driver\aoss6dbl \Device\Scsi\aoss6dbl1Port4Path0Target0Lun0 8A6B61F8 Device \Driver\aoss6dbl \Device\Scsi\aoss6dbl1Port4Path0Target0Lun0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \Driver\aoss6dbl \Device\Scsi\aoss6dbl1 8A6B61F8 Device \Driver\aoss6dbl \Device\Scsi\aoss6dbl1 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology) Device \FileSystem\Cdfs \Cdfs 89E461F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 E:\Sim\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA4 0xC4 0x52 0x2E ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDC 0x6B 0x1A 0xB6 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x55 0xD0 0xC9 0x3C ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 E:\Sim\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA4 0xC4 0x52 0x2E ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDC 0x6B 0x1A 0xB6 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x55 0xD0 0xC9 0x3C ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 E:\Sim\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA4 0xC4 0x52 0x2E ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDC 0x6B 0x1A 0xB6 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x55 0xD0 0xC9 0x3C ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 E:\Sim\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA4 0xC4 0x52 0x2E ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDC 0x6B 0x1A 0xB6 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x24 0x49 0x46 0x0B ... Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL D834B928C91EA4A754966A7CC340B528EC5675BC2195A5F4EDCAB24900828690B791712EFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA2D97226D213B555FEBC9E127BECC74CA0A96AE0AE730FD29A63CB89E18E6BD271FE2E8FEF913FB361647C44AE9BB64C5AF584DD1306A688D77FA6EC547741474B78162217D2E0871A119F6138E8DAE3241790291B0766DFE025223F0D4A9404871FF54038CED648CC8929EAA41F91552B25ECCA4C83C80D3C5E3AA6BC9A51E826150FCC4B3D9C2393A4B89FD33A083AC148B97F10DEC9B515CBB2FCF54DE5C84A8DE1DDAC29B139AAC933720D0B6E205DBF5DB7B64BECF53A21114FB09C44EBBAD0383F9C711A9E7277C00C78347A09975D8098F1D236DA9E23205EC816E210663B9AEDBF475EDCF1BE4C47232E63EB2F0910FA57D12F6A5AAFEDA0FB1B3DE35CBD5B1E1F340971CFC387B30044E631073B3D6962F9E69826B54BC06EE2520CCEDB8A34A5102A4D594165156316C4B823037CA671CEEED26137501929F4239F962E804CA58B565480059EE10798C2D3AD8288A546295BF611CB553E94B0382B2FE0D8B5512923E1D8EE3048081229C8F4705D9087B7C757599FF8F403C69AAE3933F2EFC23FACC01D74D825671F44506A163C41C078CF3D87F11F3 ---- EOF - GMER 1.0.15 ----