offline
- veljko-94
- Zaslužni građanin
- Pridružio: 29 Jul 2008
- Poruke: 615
- Gde živiš: Zemun
|
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-28 10:38:15
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwClose [0xBA760818]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreateKey [0xBA7607D0]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xBA754A20]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xBA7552A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xBA760910]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwOpenKey [0xBA760794]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xBA7552C8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryValueKey [0xBA760866]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xBA7600B0]
---- Kernel code sections - GMER 1.0.14 ----
? C:\WINDOWS\system32\drivers\jeleqn.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.14 ----
.text D:\live\Windows Live\Messenger\MSNMSGR.EXE[1896] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 0056DBBD D:\live\Windows Live\Messenger\MSNMSGR.EXE (Windows Live Messenger/Microsoft Corporation)
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtCreateFile + 6 7C90D096 4 Bytes [ 25, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtCreateFile + B 7C90D09B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenFile + 6 7C90D586 4 Bytes [ 65, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenFile + B 7C90D58B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcess + 6 7C90D5E6 4 Bytes [ A5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcess + B 7C90D5EB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessToken + 6 7C90D5F6 4 Bytes [ E5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessToken + B 7C90D5FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D606 4 Bytes [ A5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenProcessTokenEx + B 7C90D60B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThread + 6 7C90D646 4 Bytes [ 65, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThread + B 7C90D64B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadToken + 6 7C90D656 4 Bytes [ 65, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadToken + B 7C90D65B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D666 4 Bytes [ E5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtOpenThreadTokenEx + B 7C90D66B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryAttributesFile + 6 7C90D6F6 4 Bytes [ A5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryAttributesFile + B 7C90D6FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D796 4 Bytes [ E5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtQueryFullAttributesFile + B 7C90D79B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationFile + 6 7C90DC46 4 Bytes [ 25, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationFile + B 7C90DC4B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationThread + 6 7C90DC96 4 Bytes [ 25, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2104] ntdll.dll!NtSetInformationThread + B 7C90DC9B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtCreateFile + 6 7C90D096 4 Bytes [ 25, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtCreateFile + B 7C90D09B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenFile + 6 7C90D586 4 Bytes [ 65, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenFile + B 7C90D58B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenProcess + 6 7C90D5E6 4 Bytes [ A5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenProcess + B 7C90D5EB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenProcessToken + 6 7C90D5F6 4 Bytes [ E5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenProcessToken + B 7C90D5FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D606 4 Bytes [ A5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenProcessTokenEx + B 7C90D60B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenThread + 6 7C90D646 4 Bytes [ 65, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenThread + B 7C90D64B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenThreadToken + 6 7C90D656 4 Bytes [ 65, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenThreadToken + B 7C90D65B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D666 4 Bytes [ E5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtOpenThreadTokenEx + B 7C90D66B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtQueryAttributesFile + 6 7C90D6F6 4 Bytes [ A5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtQueryAttributesFile + B 7C90D6FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D796 4 Bytes [ E5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtQueryFullAttributesFile + B 7C90D79B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtSetInformationFile + 6 7C90DC46 4 Bytes [ 25, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtSetInformationFile + B 7C90DC4B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtSetInformationThread + 6 7C90DC96 4 Bytes [ 25, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2560] ntdll.dll!NtSetInformationThread + B 7C90DC9B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtCreateFile + 6 7C90D096 4 Bytes [ 25, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtCreateFile + B 7C90D09B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenFile + 6 7C90D586 4 Bytes [ 65, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenFile + B 7C90D58B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenProcess + 6 7C90D5E6 4 Bytes [ A5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenProcess + B 7C90D5EB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenProcessToken + 6 7C90D5F6 4 Bytes [ E5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenProcessToken + B 7C90D5FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D606 4 Bytes [ A5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenProcessTokenEx + B 7C90D60B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenThread + 6 7C90D646 4 Bytes [ 65, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenThread + B 7C90D64B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenThreadToken + 6 7C90D656 4 Bytes [ 65, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenThreadToken + B 7C90D65B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D666 4 Bytes [ E5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtOpenThreadTokenEx + B 7C90D66B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtQueryAttributesFile + 6 7C90D6F6 4 Bytes [ A5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtQueryAttributesFile + B 7C90D6FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D796 4 Bytes [ E5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtQueryFullAttributesFile + B 7C90D79B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtSetInformationFile + 6 7C90DC46 4 Bytes [ 25, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtSetInformationFile + B 7C90DC4B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtSetInformationThread + 6 7C90DC96 4 Bytes [ 25, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3284] ntdll.dll!NtSetInformationThread + B 7C90DC9B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtCreateFile + 6 7C90D096 4 Bytes [ 25, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtCreateFile + B 7C90D09B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenFile + 6 7C90D586 4 Bytes [ 65, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenFile + B 7C90D58B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenProcess + 6 7C90D5E6 4 Bytes [ A5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenProcess + B 7C90D5EB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenProcessToken + 6 7C90D5F6 4 Bytes [ E5, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenProcessToken + B 7C90D5FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D606 4 Bytes [ A5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenProcessTokenEx + B 7C90D60B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenThread + 6 7C90D646 4 Bytes [ 65, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenThread + B 7C90D64B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenThreadToken + 6 7C90D656 4 Bytes [ 65, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenThreadToken + B 7C90D65B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D666 4 Bytes [ E5, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtOpenThreadTokenEx + B 7C90D66B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtQueryAttributesFile + 6 7C90D6F6 4 Bytes [ A5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtQueryAttributesFile + B 7C90D6FB 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D796 4 Bytes [ E5, 00, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtQueryFullAttributesFile + B 7C90D79B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtSetInformationFile + 6 7C90DC46 4 Bytes [ 25, 01, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtSetInformationFile + B 7C90DC4B 1 Byte [ E2 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtSetInformationThread + 6 7C90DC96 4 Bytes [ 25, 02, 16, 00 ]
.text C:\Documents and Settings\veljko™\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3544] ntdll.dll!NtSetInformationThread + B 7C90DC9B 1 Byte [ E2 ]
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 8A922180
Device \FileSystem\Fastfat \FatCdrom 8A2B8DF0
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
Device \Driver\Cdrom \Device\CdRom0 8A356608
Device \FileSystem\Rdbss \Device\FsWrap 8A2BB238
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
Device \Driver\Cdrom \Device\CdRom1 8A356608
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8A356B08
Device \Driver\atapi \Device\Ide\IdePort0 8A356B08
Device \Driver\atapi \Device\Ide\IdePort1 8A356B08
Device \Driver\atapi \Device\Ide\IdePort2 8A356B08
Device \Driver\atapi \Device\Ide\IdePort3 8A356B08
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 8A356B08
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume5 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
Device \Driver\usbhub \Device\00000092 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000093 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000094 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\Srv \Device\LanmanServer 8A204478
Device \Driver\usbhub \Device\00000095 hcmon.sys (VMware USB monitor/VMware, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
Device \Driver\usbuhci \Device\USBFDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbuhci \Device\USBFDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A639390
Device \Driver\usbehci \Device\USBFDO-3 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A639390
Device \Driver\usbuhci \Device\USBFDO-4 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\Npfs \Device\NamedPipe 8A3687F8
Device \Driver\usbuhci \Device\USBFDO-5 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\Msfs \Device\Mailslot 8A368A08
Device \Driver\usbuhci \Device\USBFDO-6 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbehci \Device\USBFDO-7 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\0000008c hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 8A27A7A8
Device \Driver\d347prt \Device\Scsi\d347prt1 8A27A7A8
Device \Driver\usbhub \Device\0000008d hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \FileSystem\Fastfat \Fat 8A2B8DF0
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8A626AE8
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8A626AE8
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8A626AE8
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8A626AE8
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8A626AE8
Device \FileSystem\Cdfs \Cdfs 8A464CB0
---- Modules - GMER 1.0.14 ----
Module _________ BA5D0000-BA5E8000 (98304 bytes)
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF9 0x9E 0xD1 0x91 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xAD 0xBA 0xD2 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5C 0x0B 0xA5 0xF0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x19 0xD8 0x1A 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z0 0x9C 0x27 0xD1 0x42 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z1 0x11 0x27 0x23 0x4C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z2 0x19 0x27 0xBB 0x0C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z3 0x01 0x27 0x56 0x51 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z4 0x08 0x27 0x4C 0x29 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z5 0x33 0x27 0x78 0x2D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z6 0x3A 0x27 0xCA 0x68 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z7 0x24 0x27 0x9E 0xE1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z8 0x2E 0x27 0xF5 0xA0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z9 0x28 0x27 0x8E 0xAE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z10 0x52 0x27 0x31 0x84 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z11 0x5C 0x27 0x01 0x37 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z12 0x59 0x27 0x1C 0xBE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z13 0x43 0x27 0x3F 0x1C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z14 0x4C 0x27 0x24 0xDC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z15 0x49 0x27 0x98 0xFD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z16 0x72 0x27 0xDE 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z17 0x7F 0x27 0xE3 0xEB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z18 0x78 0x27 0xB7 0x34 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z19 0x65 0x27 0xE6 0x69 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z20 0x61 0x27 0xDD 0x8B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z21 0x6A 0x27 0xF9 0x13 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z22 0x96 0x27 0x62 0x86 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z23 0x93 0x27 0x6D 0x66 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z24 0x9F 0x27 0xE9 0x30 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z25 0x9B 0x27 0xDC 0xEC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z26 0x87 0x27 0x9F 0x9D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z27 0x80 0x27 0xE7 0x5D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z28 0x8C 0x27 0xD0 0x33 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z29 0x88 0x27 0x47
|