GMER 2.0.18444 - http://www.gmer.net Rootkit scan 2013-02-13 20:35:04 Windows 5.1.2600 Dodatek Service Pack 2 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-1b WDC_WD600BB-75CAA0 rev.16.06V16 55,90GB Running: lyy240wf.exe; Driver: D:\DOCUME~1\GuziX\USTAWI~1\Temp\awkcqaog.sys ---- Kernel code sections - GMER 2.0 ---- .text D:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB4A8D3C0, 0x95B7EA, 0xE8000020] ---- Registry - GMER 2.0 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x2D 0xFD 0xA0 0xD8 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x2D 0xFD 0xA0 0xD8 ... ---- EOF - GMER 2.0 ----