První log, který jsem našel byl tento druhý scan ješte jede...
Obnovilo se mi připojení k netu

- to je tou předešlkou opravou?
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit quick scan 2012-02-12 22:31:11
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EARS-00Y5B1 rev.80.00A80
Running: gmer.exe; Driver: C:\Users\Krotil\AppData\Local\Temp\pwdiipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----
Process PING.EXE (*** hidden *** ) 3932
---- EOF - GMER 1.0.15 ----
DRUHÝ LOG:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-02-12 22:26:45
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EARS-00Y5B1 rev.80.00A80
Running: gmer.exe; Driver: C:\Users\Krotil\AppData\Local\Temp\pwdiipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwAdjustPrivilegesToken [0xAA37CE36]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwAlpcConnectPort [0xAA37F074]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwAlpcCreatePort [0xAA37F2EE]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwAlpcSendWaitReceivePort [0xAA37F564]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwClose [0xAA37D74A]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwConnectPort [0xAA37E57E]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateEvent [0xAA37EAC8]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateFile [0xAA37DA26]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateMutant [0xAA37E9AE]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateNamedPipeFile [0xAA37CA24]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreatePort [0xAA37E882]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateSection [0xAA37CBCC]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateSemaphore [0xAA37EBE8]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateThread [0xAA37D3D0]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateThreadEx [0xAA37D4CE]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateUserProcess [0xAA37F7AE]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwCreateWaitablePort [0xAA37E918]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwDebugActiveProcess [0xAA3802D6]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwDeviceIoControlFile [0xAA37DEA8]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwDuplicateObject [0xAA3814E4]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwFsControlFile [0xAA37DCB6]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwLoadDriver [0xAA3803C8]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwMapViewOfSection [0xAA380B30]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenEvent [0xAA37EB5E]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenFile [0xAA37D7CC]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenMutant [0xAA37EA3E]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenProcess [0xAA37D074]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenSection [0xAA3808CA]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenSemaphore [0xAA37EC7E]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwOpenThread [0xAA37CF64]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwQueryDirectoryObject [0xAA37F868]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwQuerySection [0xAA380E6A]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwQueueApcThread [0xAA38075C]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwReplaceKey [0xAA37B6DE]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwReplyPort [0xAA37EFE2]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwReplyWaitReceivePort [0xAA37EEA8]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwRequestWaitReplyPort [0xAA380070]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwRestoreKey [0xAA37BA56]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwResumeThread [0xAA381386]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSaveKey [0xAA37B676]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSecureConnectPort [0xAA37E2C4]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSetContextThread [0xAA37D5EC]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSetInformationToken [0xAA37F90A]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSetSecurityObject [0xAA380566]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSetSystemInformation [0xAA380FBA]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSuspendProcess [0xAA3810AC]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSuspendThread [0xAA3811E6]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwSystemDebugControl [0xAA3801FA]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwTerminateProcess [0xAA37D21A]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwTerminateThread [0xAA37D170]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwUnmapViewOfSection [0xAA380D0E]
SSDT \SystemRoot\system32\DRIVERS\6324704drv.sys ZwWriteVirtualMemory [0xAA37D306]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82E54369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E8DD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 82E94D8C 4 Bytes [36, CE, 37, AA]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 82E94DB4 8 Bytes [74, F0, 37, AA, EE, F2, 37, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1143 82E94DF8 4 Bytes [64, F5, 37, AA]
.text ntkrnlpa.exe!KeRemoveQueueEx + 116F 82E94E24 4 Bytes [4A, D7, 37, AA] {DEC EDX; XLATB ; AAA ; STOSB }
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82E94E48 4 Bytes [7E, E5, 37, AA] {JLE 0xffffffffffffffe7; AAA ; STOSB }
.text ...
? system32\DRIVERS\55685608.sys Systém nemůže nalézt uvedenou cestu. !
? system32\DRIVERS\cdrom.sys Systém nemůže nalézt uvedenou cestu. !
? system32\DRIVERS\6324704drv.sys Systém nemůže nalézt uvedenou cestu. !
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 B8633000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 B8633123 629 Bytes [E5, 62, B8, FE, 05, 34, E5, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 B8633399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F B86333FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B B86334AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[956] ntdll.dll!NtProtectVirtualMemory 77245F18 5 Bytes JMP 0090000A
.text C:\Windows\system32\svchost.exe[956] ntdll.dll!NtWriteVirtualMemory 77246A98 5 Bytes JMP 009B000A
.text C:\Windows\system32\svchost.exe[956] ntdll.dll!KiUserExceptionDispatcher 77246FE8 5 Bytes JMP 003E000A
? C:\Windows\system32\svchost.exe[956] C:\Windows\system32\smss.exe image checksum mismatch; time/date stamp mismatch;
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeHeap] 83EC8B55
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeUnicodeString] 458D74EC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!DbgPrintEx] 15FF50F8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUpcaseUnicodeChar] [00AEF014] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtClose] 01FC7531
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationFile] 458DF875
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenFile] 15FF508C
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationFile] [00AEF004] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCompareUnicodeString] 458D086A
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAppendUnicodeStringToString] 458D50F8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAllocateHeap] 15FF508C
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnicodeStringToInteger] [00AEF000] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreatePagingFile] 508C458D
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_alldiv] F00815FF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQuerySystemInformation] 458B00AE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_allmul] E84533E4
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtFlushKey] 33EC4533
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDeleteValueKey] C3C9F045
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetValueKey] 8BEC8B55
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateKey] EC833040
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCompareMemory] 57565314
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDeviceIoControlFile] D98B388B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitUnicodeStringEx] EB04708D
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlExtendedIntegerMultiply] 46B70F20
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryVolumeInformationFile] 30448D1A
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationProcess] F0F0681C
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAppendUnicodeToString] 4F5000AE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitUnicodeString] 00DCAFE8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetSystemInformation] 85595900
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDosPathNameToNtPathName_U] 811374C0
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlExpandEnvironmentStrings_U] 00011CC6
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryValueKey] [75FF8500] C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateFile] 5FC033DC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenKey] C2C95B5E
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_vsnwprintf] 468B0008
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventWrite] F4458908
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventEnabled] 8B0C468B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetSecurityObject] 45890473
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetOwnerSecurityDescriptor] 74F685F0
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetDaclSecurityDescriptor] D8BB8D77
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAddAccessAllowedAce] 57000000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateAcl] AF015068
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateSecurityDescriptor] 8D426A00
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAllocateAndInitializeSid] 4E50FC45
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateUnicodeString] F0E015FF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtReadFile] C08500AE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_chkstk] 458D537C
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtMakeTemporaryObject] 046A50EC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateSymbolicLinkObject] 50F8458D
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenDirectoryObject] [75FF096A] C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAnsiStringToUnicodeString] DC15FFFC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitAnsiString] 8500AEF0
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_stricmp] 8B317CC0
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!qsort] 452BF845
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlRandomEx] F0453BF4
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!LdrVerifyImageMatchesChecksumEx] 006A2673
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateDirectoryObject] FFFC75FF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlEqualUnicodeString] AEF0D415
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!memcpy] 7CC08500
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsicmp] 0C4D8B17
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetEnvironmentVariable] 1F8B018B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!iswspace] 8908558B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlQueryEnvironmentVariable_U] 5F8BC21C
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFindSetBits] C25C8904
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInterlockedSetBitRun] 01894004
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlTestBit] FFFC75FF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnlockBootStatusData] AEF0D815
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlGetSetBootStatusData] 40C78300
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlLockBootStatusData] 8F75F685
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetSaclSecurityDescriptor] E940C033
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAddMandatoryAce] FFFFFF67
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlLengthSid] 51EC8B55
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlGetAce] 0173A051
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlPrefixUnicodeString] 565300AF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQuerySymbolicLinkObject] C0BE0F57
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenSymbolicLinkObject] 7D89FF33
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryDirectoryObject] DC2AE8F8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlTimeToTimeFields] DC8B0000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSerializeBoot] 45C7F633
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!memset] 001000FC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtMapViewOfSection] FC458B00
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateSection] 0F73F83B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlQueryRegistryValues] 11E8C72B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDosSearchPath_U] 8B0000DC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtResumeThread] 2BC38BF4
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWaitForSingleObject] 8DF88BC6
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtTerminateProcess] 5750FC45
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDestroyProcessParameters] FF056A56
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateUserProcess] AEF0D015
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateProcessParametersEx] 00043D00
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDisplayString] D574C000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWriteFile] 047DC085
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsupr] 60EBC033
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAdjustPrivilege] F003C033
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtInitializeRegistry] 468D016A
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!TpReleaseWork] 18685038
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!TpPostWork] FF00AEF1
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocWork] AEF0CC15
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetEvent] [75C08400] C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetCurrentEnvironment] 85068B08
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateEnvironment] EBE375C0
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenEvent] 68006A3C
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetBits] 00040000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlClearAllBits] F07415FF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeBitMap] F88B00AE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcCreatePort] 2974FF85
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationProcess] FF016A57
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateTagHeap] 15FF4476
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleaseSRWLockExclusive] [00AEF020] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquireSRWLockExclusive] 127CC085
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationThread] 8B0C75FF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationToken] 0875FFCE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenThreadToken] 81E8C78B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcImpersonateClientOfPort] 89FFFFFE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleaseSRWLockShared] FF57F845
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquireSRWLockShared] AEF02415
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!TpSetPoolMinThreads] F8458B00
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcDisconnectPort] 5FEC658D
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeSRWLock] C2C95B5E
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtConnectPort] 8B550008
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!AlpcGetMessageAttribute] 3CEC81EC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcAcceptConnectPort] 56000002
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcOpenSenderProcess] E856F08B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcCancelMessage] 0000DB36
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcSendWaitReceivePort] 00803D59
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!AlpcInitializeMessageAttribute] 870F0000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetThreadIsCritical] 000000AC
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtRequestWaitReplyPort] 0F2E3E80
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDuplicateObject] 0000A384
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateEvent] 858D5600
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlWakeConditionVariable] FFFFFDC8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlClearBits] AEF12068
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDeleteNoSplay] 15FF5000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtClearEvent] [00AEF02C] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSleepConditionVariableSRW] FDC8858D
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlWakeAllConditionVariable] 2E6AFFFF
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFindClearBits] DB06E850
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeSid] C4830000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtRaiseHardError] [74C08514] C:\Windows\system32\schannel.DLL (TLS / SSL Security Provider/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWaitForMultipleObjects] 66C9337B
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocAlpcCompletion] C0830889
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocPool] F1906802
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetProcessIsCritical] E85000AE
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventRegister] 0000DAF2
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetHeapInformation] C0855959
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeConditionVariable] 858D6275
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDelayExecution] FFFFFDC8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnicodeStringToAnsiString] CC758D50
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryEvent] 000DFFE8
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleasePrivilege] 19685000
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquirePrivilege] 8D000200
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!LdrQueryImageFileExecutionOptions] FF50FC45
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!wcstoul] AEF03815
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsnicmp] 7CC08500
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnhandledExceptionFilter] EC458D3F
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnwind] 50106A50
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlNormalizeProcessParams] 2868026A
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlConnectToSm] FF00AEF2
IAT C:\Windows\system32\svchost.exe[956] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSendMsgToSm] F633FC75
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] [6CE99832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] [6CE9A27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlLockHeap] [6CE994D8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlUnlockHeap] [6CE994E8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlDestroyHeap] [6CE994B8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlCreateHeap] [6CE994A8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlExitUserProcess] [6CE9AA9E] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] [6CE9A27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] [6CE99832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] [6CE99832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] [6CE99832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [752CFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\Iphlpapi.dll [ntdll.dll!RtlFreeHeap] [6CE99E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[2596] @ C:\Windows\system32\Iphlpapi.dll [ntdll.dll!RtlAllocateHeap] [6CE992CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) 8CD66000-8CD76000 (65536 bytes)
---- Threads - GMER 1.0.15 ----
Thread System [4:1888] B8640F2E
---- Processes - GMER 1.0.15 ----
Process C:\Windows\System32\ping.exe (*** hidden *** ) 3932
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB1865$\2195031452 0 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\@ 2048 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\cfg.ini 251 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\L 0 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\L\xadqgnnk 108544 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\twl.dll 223744 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U 0 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U\80000000.@ 66560 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\U\80000032.@ 73216 bytes
File C:\Windows\$NtUninstallKB1865$\2195031452\version 856 bytes
File C:\Windows\$NtUninstallKB1865$\3886658860 0 bytes
---- EOF - GMER 1.0.15 ----