GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-04-23 21:12:32 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD10EZEX-00UD2A0 rev.01.01A01 931,51GB Running: e6g73uwg.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\pxtdrpow.sys ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION 95EBC33AFCA74D21FE9E8297B599699B3762E1238B4F40EF0A60479A75D6BF6BCC75FED624E48428F3F01BB9418C1644FCD69825058F00A2A6B5E2890F3C39BC7A119EFA1FDFD085A2D344E18E3DFBDF16D88DAEA52462970C00B1AAB709457FCB59744F1AB6F78A3ED1FDAF5D0D1E84D7050D78E14DC350D58D6CEF3A7C423EC16A461D54CBF1E9CA79BDE8819D32B06FFBD85DC5103A33742CC1ED739B40E6316751D220456D39A2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC7933BA7FD869164D6794FEBC9E127BECC74CDC7AB94835708B936E5DDADF053B1ADF6AD9AAC17857856ABF734147AFFBF16F3D17C89E8AA77EC73927D7455D926A79CADA5C412BF348A48FE714AF7796C03B7E001C31A13EDE09D29C840BD4DB7D8A809D0333868E3019BAB2A49B85FECBDE0B1B9FD3987D742577B0A77929F9C2E53741DF7909C8F53CFD41CC9D39B33715CE4466724FE068BAE049AC72DD0A0DB29CD9D5087679B5DA19F3886038E7866C3AC7250BEB1ACA41D4C2A0E637561467E36F6D67D4AB6F924E20F921670524CA42673730D78C8D7F96EB37DFC0E1F3D442FED132F09C07D5668E64B07525DD67DED999863F5106926F0747F6C7E12B1B74F7D21C58C0476D2CFC31F4D297E3CD0E4AEE4A93356 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----