kontrola log..díky
Napsal: 11 srp 2010 16:29
zdravím,
prosím zkušené o kontrolu logu z Gmer.
Děkuji.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-11 17:26:07
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Mira\AppData\Local\Temp\kxldypow.sys
---- System - GMER 1.0.15 ----
SSDT 86640940 ZwAlertResumeThread
SSDT 86640C98 ZwAlertThread
SSDT 86715D20 ZwAllocateVirtualMemory
SSDT 85ED71E0 ZwAlpcConnectPort
SSDT 864E4870 ZwAssignProcessToJobObject
SSDT 866405D0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x898D9CDC]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x898D9ECE]
SSDT 86640440 ZwCreateSymbolicLinkObject
SSDT 86626510 ZwCreateThread
SSDT 864E4080 ZwCreateThreadEx
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x898DA0D6]
SSDT 86640E18 ZwDebugActiveProcess
SSDT 86715EF0 ZwDuplicateObject
SSDT 86715B40 ZwFreeVirtualMemory
SSDT 866406C0 ZwImpersonateAnonymousToken
SSDT 866407A0 ZwImpersonateThread
SSDT 85E5F540 ZwLoadDriver
SSDT 86715A40 ZwMapViewOfSection
SSDT 863FA508 ZwOpenEvent
SSDT 866263B8 ZwOpenProcess
SSDT 86715E10 ZwOpenProcessToken
SSDT 85DDFE80 ZwOpenSection
SSDT 86715FC0 ZwOpenThread
SSDT 864E4188 ZwProtectVirtualMemory
SSDT 86640D78 ZwResumeThread
SSDT 86715790 ZwSetContextThread
SSDT 86715870 ZwSetInformationProcess
SSDT 86715510 ZwSetSystemInformation
SSDT 8662C698 ZwSuspendProcess
SSDT 867153A8 ZwSuspendThread
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x898D9982]
SSDT 867155F0 ZwTerminateThread
SSDT 86715960 ZwUnmapViewOfSection
SSDT 86715C30 ZwWriteVirtualMemory
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C283F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C10FB4
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C281DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C286F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C291A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwSaveKeyEx + 13B1 82C7A8E9 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 82C9A3D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 139B 82CA1668 8 Bytes [40, 09, 64, 86, 98, 0C, 64, ...]
.text ntoskrnl.exe!KeRemoveQueueEx + 13B3 82CA1680 4 Bytes [20, 5D, 71, 86]
.text ntoskrnl.exe!KeRemoveQueueEx + 13BF 82CA168C 4 Bytes [E0, 71, ED, 85]
.text ntoskrnl.exe!KeRemoveQueueEx + 1413 82CA16E0 4 Bytes [70, 48, 4E, 86]
.text ntoskrnl.exe!KeRemoveQueueEx + 148F 82CA175C 1 Byte [D0]
.text ...
.text peauth.sys A14F3C9D 28 Bytes [C4, AA, 95, 23, 4D, 98, 95, ...]
.text peauth.sys A14F3CC1 28 Bytes [C4, AA, 95, 23, 4D, 98, 95, ...]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[4528] ntdll.dll!LdrLoadDll 7726F625 5 Bytes JMP 0066003A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4540] USER32.dll!TrackPopupMenu 76F94B3B 5 Bytes JMP 64FA721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!SetScrollRange 76F6AE3C 5 Bytes JMP 0341C759 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!GetScrollInfo 76F75151 7 Bytes JMP 0341C68B C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!SetScrollInfo 76F76632 7 Bytes JMP 0341C703 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!GetScrollRange 76F91B6C 5 Bytes JMP 0341C6D8 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!SetScrollPos 76F91BD0 5 Bytes JMP 0341C72E C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!GetScrollPos 76F9252B 5 Bytes JMP 0341C6B3 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!EnableScrollBar 76F9386D 7 Bytes JMP 0341C663 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!ShowScrollBar 76F95785 5 Bytes JMP 0341C787 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] [00454D58] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [00454F5C] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [00454D58] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [00454F5C] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] [0044BB58] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0044BB58] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] [0044B82C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0044B82C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 VMkbd.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 VMkbd.sys
Device \Driver\usbuhci \Device\USBPDO-0 hcmon.sys
Device \Driver\usbuhci \Device\USBPDO-1 hcmon.sys
Device \Driver\usbuhci \Device\USBPDO-2 hcmon.sys
Device \Driver\usbuhci \Device\USBPDO-3 hcmon.sys
Device \Driver\usbehci \Device\USBPDO-4 hcmon.sys
AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbhub \Device\USBPDO-6 hcmon.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbhub \Device\USBPDO-7 hcmon.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbhub \Device\00000075 hcmon.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbhub \Device\00000076 hcmon.sys
Device \Driver\usbhub \Device\00000077 hcmon.sys
Device \Driver\usbhub \Device\00000078 hcmon.sys
Device \Driver\usbhub \Device\00000079 hcmon.sys
AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\ACPI_HAL \Device\0000005e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-1 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-2 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-3 hcmon.sys
Device \Driver\usbehci \Device\USBFDO-4 hcmon.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\111111111111
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\111111111111@00233988bd3d 0x51 0xA2 0x0F 0x0C ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\111111111111 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\111111111111@00233988bd3d 0x51 0xA2 0x0F 0x0C ...
---- EOF - GMER 1.0.15 ----
prosím zkušené o kontrolu logu z Gmer.
Děkuji.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-11 17:26:07
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Mira\AppData\Local\Temp\kxldypow.sys
---- System - GMER 1.0.15 ----
SSDT 86640940 ZwAlertResumeThread
SSDT 86640C98 ZwAlertThread
SSDT 86715D20 ZwAllocateVirtualMemory
SSDT 85ED71E0 ZwAlpcConnectPort
SSDT 864E4870 ZwAssignProcessToJobObject
SSDT 866405D0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x898D9CDC]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x898D9ECE]
SSDT 86640440 ZwCreateSymbolicLinkObject
SSDT 86626510 ZwCreateThread
SSDT 864E4080 ZwCreateThreadEx
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x898DA0D6]
SSDT 86640E18 ZwDebugActiveProcess
SSDT 86715EF0 ZwDuplicateObject
SSDT 86715B40 ZwFreeVirtualMemory
SSDT 866406C0 ZwImpersonateAnonymousToken
SSDT 866407A0 ZwImpersonateThread
SSDT 85E5F540 ZwLoadDriver
SSDT 86715A40 ZwMapViewOfSection
SSDT 863FA508 ZwOpenEvent
SSDT 866263B8 ZwOpenProcess
SSDT 86715E10 ZwOpenProcessToken
SSDT 85DDFE80 ZwOpenSection
SSDT 86715FC0 ZwOpenThread
SSDT 864E4188 ZwProtectVirtualMemory
SSDT 86640D78 ZwResumeThread
SSDT 86715790 ZwSetContextThread
SSDT 86715870 ZwSetInformationProcess
SSDT 86715510 ZwSetSystemInformation
SSDT 8662C698 ZwSuspendProcess
SSDT 867153A8 ZwSuspendThread
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x898D9982]
SSDT 867155F0 ZwTerminateThread
SSDT 86715960 ZwUnmapViewOfSection
SSDT 86715C30 ZwWriteVirtualMemory
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C283F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C10FB4
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C281DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C286F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C28F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C291A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwSaveKeyEx + 13B1 82C7A8E9 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 82C9A3D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 139B 82CA1668 8 Bytes [40, 09, 64, 86, 98, 0C, 64, ...]
.text ntoskrnl.exe!KeRemoveQueueEx + 13B3 82CA1680 4 Bytes [20, 5D, 71, 86]
.text ntoskrnl.exe!KeRemoveQueueEx + 13BF 82CA168C 4 Bytes [E0, 71, ED, 85]
.text ntoskrnl.exe!KeRemoveQueueEx + 1413 82CA16E0 4 Bytes [70, 48, 4E, 86]
.text ntoskrnl.exe!KeRemoveQueueEx + 148F 82CA175C 1 Byte [D0]
.text ...
.text peauth.sys A14F3C9D 28 Bytes [C4, AA, 95, 23, 4D, 98, 95, ...]
.text peauth.sys A14F3CC1 28 Bytes [C4, AA, 95, 23, 4D, 98, 95, ...]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[4528] ntdll.dll!LdrLoadDll 7726F625 5 Bytes JMP 0066003A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4540] USER32.dll!TrackPopupMenu 76F94B3B 5 Bytes JMP 64FA721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!SetScrollRange 76F6AE3C 5 Bytes JMP 0341C759 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!GetScrollInfo 76F75151 7 Bytes JMP 0341C68B C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!SetScrollInfo 76F76632 7 Bytes JMP 0341C703 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!GetScrollRange 76F91B6C 5 Bytes JMP 0341C6D8 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!SetScrollPos 76F91BD0 5 Bytes JMP 0341C72E C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!GetScrollPos 76F9252B 5 Bytes JMP 0341C6B3 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!EnableScrollBar 76F9386D 7 Bytes JMP 0341C663 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[5876] USER32.dll!ShowScrollBar 76F95785 5 Bytes JMP 0341C787 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] [00454D58] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [00454F5C] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [00454D58] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\a-squared Free\a2service.exe[1588] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [00454F5C] C:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe[1684] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75285E25] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] [0044BB58] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0044BB58] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1956] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BD5C] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] [0044B82C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0044B82C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2084] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 VMkbd.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 VMkbd.sys
Device \Driver\usbuhci \Device\USBPDO-0 hcmon.sys
Device \Driver\usbuhci \Device\USBPDO-1 hcmon.sys
Device \Driver\usbuhci \Device\USBPDO-2 hcmon.sys
Device \Driver\usbuhci \Device\USBPDO-3 hcmon.sys
Device \Driver\usbehci \Device\USBPDO-4 hcmon.sys
AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbhub \Device\USBPDO-6 hcmon.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbhub \Device\USBPDO-7 hcmon.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbhub \Device\00000075 hcmon.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\usbhub \Device\00000076 hcmon.sys
Device \Driver\usbhub \Device\00000077 hcmon.sys
Device \Driver\usbhub \Device\00000078 hcmon.sys
Device \Driver\usbhub \Device\00000079 hcmon.sys
AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\ACPI_HAL \Device\0000005e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-1 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-2 hcmon.sys
Device \Driver\usbuhci \Device\USBFDO-3 hcmon.sys
Device \Driver\usbehci \Device\USBFDO-4 hcmon.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\111111111111
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\111111111111@00233988bd3d 0x51 0xA2 0x0F 0x0C ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\111111111111 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\111111111111@00233988bd3d 0x51 0xA2 0x0F 0x0C ...
---- EOF - GMER 1.0.15 ----