GMER Log Code:
GMER 1.0.15.15077 [tw6dupgv.exe] - http://www.gmer.net
Rootkit scan 2009-08-30 14:47:22
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xB7F7236E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xB7F72A86]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xB7F7360C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xB7F73B40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xB7F72D78]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xB7F71460]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xB7F73A18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xB7F70D0A]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xBA780B00]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xB7F738D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xB7F72102]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xB7F73C72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xB7F7540E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xB7F72886]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xB7F73976]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xB7F71A20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xB7F71CF8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xB7F7321C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xB7F75980]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xB7F71E3A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xB7F71EE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xB7F73016]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xB7F74EA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xB7F7143C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xB7F7144E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xB7F72030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xB7F73BE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xB7F72B08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xB7F71604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xB7F73AB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xB7F7256E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xB7F75438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xB7F73D14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xB7F72492]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xB7F71F8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xB7F71BB6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xB7F718BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xB7F75128]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xB7F71B34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xB7F710C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xB7F7409E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xB7F73F64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xB7F74C30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xB7F71224]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xB7F75860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xB7F70EC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xB7F73312]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xB7F72984]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xB7F745F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xB7F74FA0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xB7F754C2]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xBA78C550]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xB7F71744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xB7F755A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xB7F756D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xB7F74DD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xB7F726EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xB7F7263C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xB7F727C8]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF74 5 Bytes JMP B7F67424 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF902 5 Bytes JMP B7F677DE \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntkrnlpa.exe!ZwCallbackReturn + 2C70 805044FC 16 Bytes [18, 3A, F7, B7, 0A, 0D, F7, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2C8C 80504518 16 Bytes [02, 21, F7, B7, 72, 3C, F7, ...] {ADD AH, [ECX]; DIV DWORD [EDI-0x4808c38e]; PUSH CS; PUSH ESP; DIV DWORD [EDI-0x4808d77a]}
.text ntkrnlpa.exe!ZwCallbackReturn + 2D48 805045D4 12 Bytes [A6, 4E, F7, B7, 3C, 14, F7, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2EC4 80504750 16 Bytes [34, 1B, F7, B7, C2, 10, F7, ...] {XOR AL, 0x1b; DIV DWORD [EDI-0x4808ef3e]; SAHF ; INC EAX; DIV DWORD [EDI-0x4808c09c]}
.text ntkrnlpa.exe!ZwCallbackReturn + 2FB8 80504844 12 Bytes [A6, 55, F7, B7, D2, 56, F7, ...]
.text ...
---- User code sections - GMER 1.0.15 ----
.rsrc C:\WINDOWS\system32\svchost.exe[776] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x2000, 0x60000060]
.rsrc C:\WINDOWS\System32\svchost.exe[788] C:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x2000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[1028] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x2000, 0x60000060]
.rsrc C:\WINDOWS\system32\winlogon.exe[1624] C:\WINDOWS\system32\winlogon.exe section is executable [0x01077000, 0xC000, 0x60000060]
.rsrc C:\WINDOWS\system32\winlogon.exe[1624] C:\WINDOWS\system32\winlogon.exe entry point in ".rsrc" section [0x01082000]
.rsrc C:\WINDOWS\system32\services.exe[1696] C:\WINDOWS\system32\services.exe section is executable [0x0101B000, 0x2000, 0x60000060]
.rsrc C:\WINDOWS\system32\services.exe[1696] C:\WINDOWS\system32\services.exe entry point in ".rsrc" section [0x0101C000]
.rsrc C:\WINDOWS\system32\svchost.exe[1928] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x2000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[1976] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x2000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[2044] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x2000, 0x60000060]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] [BA0C9670] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [BA0C9670] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExA] [004167F7] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExW] [00416871] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!ShowWindow] [004168EB] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowPos] [0041699D] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!CreateWindowExW] [00416871] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [004167F7] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [00416871] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [0041699D] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [004168EB] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!CreateWindowExW] [00416871] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!ShowWindow] [004168EB] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
IAT C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe[1412] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowPos] [0041699D] C:\DOKUME~1\Adrian\LOKALE~1\Temp\b.exe
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A5747A0
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\Cdrom \Device\CdRom0 8A1E29A0
Device \FileSystem\Rdbss \Device\FsWrap 8A1F7AD8
Device \Driver\Cdrom \Device\CdRom1 8A1E29A0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8A19D3F8
Device \Driver\atapi \Device\Ide\IdePort0 8A19D3F8
Device \Driver\atapi \Device\Ide\IdePort1 8A19D3F8
Device \Driver\atapi \Device\Ide\IdePort2 8A19D3F8
Device \Driver\atapi \Device\Ide\IdePort3 8A19D3F8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-19 8A19D3F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e 8A19D3F8
Device \FileSystem\Srv \Device\LanmanServer 89D4BB78
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A1A9AE0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A1A9AE0
Device \FileSystem\Npfs \Device\NamedPipe 8A1E5A08
Device \FileSystem\Msfs \Device\Mailslot 8A1D4C18
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port4Path0Target0Lun0 8A17DE28
Device \Driver\a347scsi \Device\Scsi\a347scsi1 8A17DE28
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8A1B75B8
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8A1B75B8
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8A1B75B8
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8A1B75B8
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8A1B75B8
Device \FileSystem\Cdfs \Cdfs 8A220CA0
---- Modules - GMER 1.0.15 ----
Module _________ BA6E2000-BA6FA000 (98304 bytes)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION FBC33696BB742647BB3090CC74D4B4AED6431825958EC86E01F0CA12FB82D7BB5052CDEDD8667F2958584064F1F44854111A6EEF38483A2F0FA14EE41F33C0CB0E5CC888D6AEE146C609D6BBC4DABF2E1BC370FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14075D575E7D6A3B9808A6171C11EC38DE3D561DC3EBB407FCC3E58D6D88FE979A332B2D98BD30AE83EE1230DF206568804C1D89EEA2EBE813F414EB7B9F2E8085DEC01F5D2ABC28F9FCB517A2B2DCC99153A8EE46FDA95527CEE1A06CE64A2C10F5311BAB74B2DA78E279A0F3BDF59D468DCD76F61FA8BA0F6D9BE7293DD5AD2163E0935059FC9C98767C10A07B279E07DC83D96DDC0B5B26E0301063B4BBEB2583D98EDC496E1977027FC2BC564CDFC099E3E8DB3FD14CCBAC347F0C9347A08A28C82224663D50B4436AA519EF22C4E60EAD07B884E576E0C8DFAE5C54A8DBC5157E7FBD080116746DC4BA531DCC06EDF944AABE9D911ACEA28DA74E27F4FE4E83EF66863BB89260A63E1844E5D030CF0FAEE0EAB105C67D98BE8CA0ECA341A0A0B52B9E3E44C1A507286A11061AA50A751747809853635C7F9611D73D132EBB0E8CB76A84EAF1731E78EB1CEF76991EC6CC91056174295E9E5DFDB9E1012423E0D58992B6D448006DC8F10FC61
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120% (Trial Version)
Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120% (Trial Version)
---- EOF - GMER 1.0.15 ---- |