GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-07-03 09:44:19 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 HITACHI_ rev.PC4Z 465,76GB Running: 94lbmzp2.exe; Driver: C:\Users\PiotrR\AppData\Local\Temp\uxldqpod.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ec2d88 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c44619c61ad8 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c44619c61ad8@f81edf6c8dac 0x17 0xD6 0x15 0xF8 ... Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????oem25.inf??????p??????????????????????????????????????N????????????D?????????~???????????????????1??85??? ??????????????????????????????hdaudio\func_01&ven_1002&dev_aa01&rev_1002??????? ????????????????????????????????????"???????????????X??????0???????????????????????~??????????????Microsoft Word???????????~???????????7??????}????????????8???????????????????0?????s????? 0????????????D ???????g???? ?????????????~?????p?,?????? ????????????????????ly ??? ???????~???????????p?,?????? ????? ??????anc??WUDFCoinstaller.dll?????WINUSB.INF???????$????????????????????????????????N????????????D??????????????N???????????D?????6.1.7600.16385??????????????????pc??{5d624f94-8850-40c3-a3fa-a4fd2080baf3}\vwifimp\5&31b5f917&0&01?22-???????~???????????$|?????????????????????????????????????????????Intel????????@??????????? ???????;???????????;?,?????? ????? ????????????????????d???????????????????????????????~????`??????3???1??? ????????????????????????????N???????????D??????????????????~???d??_2??????l?????Z??????-? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ?????????????????????????????????????????????????????????????????D??ic???????????{??55????&??????????e??????????????????????????????????????????????????????4m??42??????????????id??????????????{4d36e968-e325-11ce-bfc1-08002be10318}??????{00000000-0000-0000-ffff-ffffffffffff}?-??????N?????? ????D??????????=??sdbus.inf:Generic.NTamd64:SDHost:6.1.7600.16438:pci\cc_080501???PCI\VEN_197B&DEV_2388&SUBSYS_392317AA&REV_20?PCI\VEN_197B&DEV_2388&SUBSYS_392317AA?PCI\VEN_197B&DEV_2388&CC_088000?PCI\VEN_197B&DEV_2388&CC_0880???????????????????????????????????????4?????????~??????????@system32\DRIVERS\pci.sys,#2176;Base System Device?ie systemowe?????PCI\VEN_197B&DEV_2388&REV_20?PCI\VEN_197B&DEV_2388?PCI\VEN_197B&CC_088000?PCI\VEN_197B&CC_0880?PCI\VEN_197B?PCI\CC_088000?PCI\CC_0880??????????????????????s????9.1.1.1020?.76???????????v??er???????????c??c0??????????????????????????LegacyDriver????????????????????????????????????????????{4d36e97d-e325-11ce-bfc1-08002be10318}???????????????????????????????????????????????i?? (? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????????????????????????????v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Steam\steamapps\common\xcom ufo defense\dosbox.exe|Name=X-COM: UFO Defense|?ox??v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Steam\steamapps\common\xcom ufo defense\dosbox.exe|Name=X-COM: UFO Defense|?p???&???????c???????????????????o???&???????X??????????????????????v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Steam\steamapps\common\x-com terror from the deep\runme.exe|Name=X-COM: Terror from the Deep|????&???????e???????????????????????(???????B???????????????????????????????????????????????????????????????\????????X???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ????????{4d36e967-e325-11ce-bfc1-08002be10318}\0003??????????n???O???e??Wolumin uniwersalny?\\??LegacyDriver?0???/?0?????????????????????1??????????????????????????????????????????????????????????PCI\VEN_8086&DEV_3B32&REV_06?PCI\VEN_8086&DEV_3B32?PCI\VEN_8086&CC_118000?PCI\VEN_8086&CC_1180?PCI\VEN_8086?PCI\CC_118000?PCI\CC_1180????????j?k?k?k????????{4d36e97d-e325-11ce-bfc1-08002be10318}??????@nettun.inf,%msft%;Microsoft?????????g???????e??????????DI??????????????????????????LegacyDriver????????????????????@oem4.inf,%pci\ven_8086&dev_3b34.devicedesc%;Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller - 3B34???????????????&?????????????X??????????????,??????.NTAMD64????PCI\VEN_8086&DEV_3B34&REV_06?PCI\VEN_8086&DEV_3B34?PCI\VEN_8086&CC_0C0320?PCI\VEN_8086&CC_0C03?PCI\VEN_8086?PCI\CC_0C0320?PCI\CC_0C03??D1}????~??????????????????l??????????? l??????????????????????l?????~?????g?????????????o???o????X??????8???0???????????h???g??????????????? ???????g???????????????????????????????f???x?z?????h??? ???????g?????g???????0??L????????? ??????????????g???g???g?????g??? ???????g?????g???????0????????????&???????????????????????? ???????g?????g???????0????????????????????? ???????g???????????d?0?????????????????????????????????????T???????????P??5???????????????????????????????????{4d36e96e-e Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???~?s??PnP Filter??????????????????????????????????????????t???File system???????P??r?????????e???????r?????r???r??????????????? ???????n?????r?????r????????$????????x????@%systemroot%\system32\fxsresm.dll,-118???????????????????????????B??r????????h?????%systemroot%\system32\fxssvc.exe????????????????t?????????????????????P??r?????????n????@%systemroot%\system32\fxsresm.dll,-122??????????r???+????????@??r???????????e??TapiSrv?RpcSs?PlugPlay?Spooler??????? 8??r??????????????NT AUTHORITY\NetworkService???????,??r???+???????+???????????????????????????r??????????????????SeAssignPrimaryTokenPrivilege?SeAuditPrivilege?SeChangeNotifyPrivilege?SeCreateGlobalPrivilege?SeImpersonatePrivilege?SeIncreaseQuotaPrivilege???????r?r?r?r?r?r?r?r?r?r?r??????????????????????????? ???????r???????????r?????????????????????????????????p?????????????(??????P??????????????????? ???????????????????????????? ???????n???????????r??????????N??????c????@%SystemRoot%\system32\drivers\fvevol.sys,-100???????????t????:??r????????h???????? ---- EOF - GMER 2.1 ----