- GMER 1.0.15.15641 - http://www.gmer.net
- Rootkit scan 2012-07-11 20:59:29
- Windows 6.1.7601 Service Pack 1
- Running: xg97yeki.exe
- ---- Registry - GMER 1.0.15 ----
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60fb428457c8
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60fb428457c8@001edc4f36a0 0x20 0x28 0x24 0xB3 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCF 0x42 0xDD 0x7B ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x59 0xC0 0xEF 0x6F ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xEA 0x30 0xA9 0xF6 ...
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60fb428457c8 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60fb428457c8@001edc4f36a0 0x20 0x28 0x24 0xB3 ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCF 0x42 0xDD 0x7B ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x59 0xC0 0xEF 0x6F ...
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xEA 0x30 0xA9 0xF6 ...
- Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{49BE948F-B6F7-8CDF-30CB-D758FB0ECFDD}
- Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{49BE948F-B6F7-8CDF-30CB-D758FB0ECFDD}@oaaoeahdifbajohfegpmdfapakdabg 0x6B 0x61 0x67 0x67 ...
- Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{49BE948F-B6F7-8CDF-30CB-D758FB0ECFDD}@pacbkeaemiidemppmpcfahllpencfjep 0x6B 0x61 0x67 0x67 ...
- ---- Files - GMER 1.0.15 ----
- File C:\Windows\Temp\NODC90D.tmp 0 bytes
- ---- EOF - GMER 1.0.15 ----