GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-01-10 06:03:46
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\QTech\AppData\Local\Temp\fglcipog.sys
---- System - GMER 1.0.15 ----
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2AAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2A104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2A3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C132D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C12898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2A1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2A958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2A6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2AF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C2B1A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C8A579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CAEF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\Drivers\spcy.sys The system cannot find the path specified. !
PAGE dxgkrnl.sys!g_TdrForceTimeout + 9788 91A25800 11 Bytes [42, 39, 5D, 0C, 75, 28, C7, ...]
PAGE dxgkrnl.sys!g_TdrForceTimeout + 9794 91A2580C 10 Bytes [00, 33, FF, 47, 57, FF, 15, ...]
PAGE dxgkrnl.sys!g_TdrForceTimeout + 979F 91A25817 13 Bytes [50, 57, 89, 58, 0C, 89, 58, ...]
PAGE dxgkrnl.sys!g_TdrForceTimeout + 97AD 91A25825 185 Bytes [C7, 45, 10, 33, FB, FF, FF, ...]
PAGE dxgkrnl.sys!g_TdrForceTimeout + 9867 91A258DF 21 Bytes [C7, 45, 0C, 0A, FB, FF, FF, ...]
PAGE ...
PAGE dxgkrnl.sys!DpiGetDriverVersion + 96 91A30888 8 Bytes [00, 6A, 02, FF, D6, 83, 60, ...]
PAGE dxgkrnl.sys!DpiGetDriverVersion + 9F 91A30891 21 Bytes [50, 6A, 02, 89, 58, 0C, FF, ...]
PAGE dxgkrnl.sys!DpiGetDriverVersion + B5 91A308A7 1 Byte [90]
PAGE dxgkrnl.sys!DpiGetDriverVersion + B5 91A308A7 21 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
PAGE dxgkrnl.sys!DpiGetDriverVersion + CD 91A308BF 11 Bytes [6A, 02, FF, 15, FC, 73, A1, ...]
PAGE ...
PAGE dxgkrnl.sys!TdrIsTimeoutForcedFlip + 7 91A8D677 50 Bytes [87, 01, F7, D8, 1B, C0, F7, ...]
PAGE dxgkrnl.sys!TdrIsTimeoutForcedFlip + 43 91A8D6B3 37 Bytes CALL 91A8D30B \SystemRoot\System32\drivers\dxgkrnl.sys (DirectX Graphics Kernel/Microsoft Corporation)
PAGE dxgkrnl.sys!TdrIsTimeoutForcedFlip + 69 91A8D6D9 33 Bytes [6A, 03, 58, B9, 00, B0, A1, ...]
PAGE dxgkrnl.sys!TdrIsTimeoutForcedFlip + 8B 91A8D6FB 69 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
PAGE dxgkrnl.sys!TdrIsTimeoutForcedFlip + D1 91A8D741 33 Bytes [3B, C7, 89, 46, 08, 7D, 02, ...]
PAGE ...
PAGE dxgkrnl.sys!TdrCreateRecoveryContext + 37 91A8D920 34 Bytes [89, 86, B8, 0A, 00, 00, A1, ...]
PAGE dxgkrnl.sys!TdrCreateRecoveryContext + 5A 91A8D943 8 Bytes [F3, 90, 8B, 50, 04, 89, 56, ...] {PAUSE ; MOV EDX, [EAX+0x4]; MOV [ESI+0x54], EDX}
PAGE dxgkrnl.sys!TdrCreateRecoveryContext + 63 91A8D94C 37 Bytes [10, 89, 56, 50, 8B, 50, 08, ...]
PAGE dxgkrnl.sys!TdrCreateRecoveryContext + 89 91A8D972 5 Bytes [C7, 40, 0C, F0, 0A]
PAGE dxgkrnl.sys!TdrCreateRecoveryContext + 8F 91A8D978 63 Bytes [00, C7, 40, 10, 60, C0, A1, ...]
PAGE ...
PAGE dxgkrnl.sys!TdrCompleteRecoveryContext + D 91A8E7DA 22 Bytes [8B, 46, 1C, 85, C0, 74, 11, ...]
PAGE dxgkrnl.sys!TdrCompleteRecoveryContext + 24 91A8E7F1 112 Bytes [FF, 56, B9, 48, B6, A1, 91, ...]
PAGE dxgkrnl.sys!TdrIsRecoveryRequired + 20 91A8E862 151 Bytes [CE, BA, 7C, C0, A1, 91, F0, ...]
PAGE dxgkrnl.sys!TdrIsRecoveryRequired + B8 91A8E8FA 16 Bytes CALL 91A8DD64 \SystemRoot\System32\drivers\dxgkrnl.sys (DirectX Graphics Kernel/Microsoft Corporation)
PAGE dxgkrnl.sys!TdrIsRecoveryRequired + C9 91A8E90B 26 Bytes CALL 91A0E821 \SystemRoot\System32\drivers\dxgkrnl.sys (DirectX Graphics Kernel/Microsoft Corporation)
PAGE dxgkrnl.sys!TdrIsRecoveryRequired + E4 91A8E926 28 Bytes [8B, 40, 04, 8B, 80, BC, 00, ...]
PAGE dxgkrnl.sys!TdrIsRecoveryRequired + 102 91A8E944 44 Bytes [02, 75, 17, 8B, 46, 30, 0B, ...]
PAGE ...
PAGE dxgkrnl.sys!TdrResetFromTimeout + 46 91A8E9FF 179 Bytes [00, C0, EB, D3, 8B, C8, E8, ...]
PAGE dxgkrnl.sys!TdrResetFromTimeout + FA 91A8EAB3 62 Bytes [06, 8B, CB, 2B, C8, 51, FF, ...]
PAGE dxgkrnl.sys!TdrResetFromTimeout + 139 91A8EAF2 85 Bytes [83, 60, 0C, 00, 83, 60, 10, ...]
PAGE dxgkrnl.sys!TdrResetFromTimeout + 18F 91A8EB48 42 Bytes CALL 91A12D8F \SystemRoot\System32\drivers\dxgkrnl.sys (DirectX Graphics Kernel/Microsoft Corporation)
PAGE dxgkrnl.sys!TdrResetFromTimeout + 1BA 91A8EB73 179 Bytes [15, FC, 73, A1, 91, 83, 60, ...]
PAGE ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x92434000, 0x2CB104, 0xE8000020]
.text USBPORT.SYS!DllUnload 91B15CA0 5 Bytes JMP 86EA84E0
.text a5srzgoj.SYS 91B3D000 12 Bytes [44, 58, C1, 82, EE, 56, C1, ...]
.text a5srzgoj.SYS 91B3D00D 9 Bytes [37, C1, 82, 48, 5B, C1, 82, ...]
.text a5srzgoj.SYS 91B3D017 20 Bytes [00, DE, 57, D1, 8B, E6, 55, ...]
.text a5srzgoj.SYS 91B3D02C 149 Bytes [00, 00, 00, 00, D0, 51, C8, ...]
.text a5srzgoj.SYS 91B3D0C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text peauth.sys A2A0DC9D 2 Bytes [0F, 2E]
.text peauth.sys A2A0DCC1 2 Bytes [0F, 2E]
PAGE peauth.sys A2A13E20 101 Bytes [E4, FC, 8B, E0, CD, A8, 79, ...]
PAGE peauth.sys A2A1402C 102 Bytes [47, F9, B1, 3C, EE, 86, F0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 A2B94000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 A2B94123 629 Bytes [F5, B8, A2, FE, 05, 34, F5, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 A2B94399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F A2B943FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B A2B944AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1680] kernel32.dll!SetUnhandledExceptionFilter 76253142 4 Bytes [C2, 04, 00, 00]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8BC19042] \SystemRoot\System32\Drivers\spcy.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8BC196D6] \SystemRoot\System32\Drivers\spcy.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8BC19800] \SystemRoot\System32\Drivers\spcy.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8BC1913E] \SystemRoot\System32\Drivers\spcy.sys
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortNotification] 00147880
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortQuerySystemTime] 78800C75
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortReadPortUchar] 06750015
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortStallExecution] C25DC033
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortWritePortUchar] 458B0008
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortWritePortUlong] 6A006A08
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 50056A24
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 005AB7E8
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortGetScatterGatherList] 0001B800
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortGetParentBusType] C25D0000
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortRequestCallback] CCCC0008
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortWritePortBufferUshort] CCCCCCCC
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortGetUnCachedExtension] CCCCCCCC
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortCompleteRequest] CCCCCCCC
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortCopyMemory] 53EC8B55
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortEtwTraceLog] 800C5D8B
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 7500117B
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 127B806A
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 80647500
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7500137B
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortInitialize] 157B805E
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortGetDeviceBase] 56587500
IAT \SystemRoot\System32\Drivers\a5srzgoj.SYS[ataport.SYS!AtaPortDeviceStateChange] 8008758B
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [01F219FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CloseHandle] [01F46209] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!ReadFile] [01F45F4C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetFileSize] [01F4624A] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileMappingW] [01F4647C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA] [01F21922] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [01F21ADA] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [01F45EE6] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetFilePointerEx] [01F46158] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [01F219FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetFilePointer] [01F460FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileMappingW] [01F4647C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetFileSizeEx] [01F46291] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [01F21ADA] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CloseHandle] [01F46209] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!WriteFile] [01F45FFE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [01F45EE6] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [01F219FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetFileSize] [01F4624A] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetFileSizeEx] [01F46291] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [01F21ADA] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CloseHandle] [01F46209] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileW] [01F45EE6] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [01F21922] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!WriteFile] [01F45FFE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetFilePointer] [01F460FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileMappingW] [01F4647C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!ReadFile] [01F45F4C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetOverlappedResult] [01F462D8] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetFileAttributesExA] [01F463D8] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetFileSizeEx] [01F46291] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetFilePointerEx] [01F46158] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateFileMappingA] [01F46421] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [01F219FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateFileMappingW] [01F4647C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetOverlappedResult] [01F462D8] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetQueuedCompletionStatus] [01F4637F] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateIoCompletionPort] [01F4632B] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [01F21ADA] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CloseHandle] [01F46209] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!ReadFile] [01F45F4C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetFileSize] [01F4624A] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateFileA] [01F45E80] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateFileW] [01F45EE6] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetFilePointer] [01F460FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!WriteFile] [01F45FFE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WriteFile] [01F45FFE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReadFile] [01F45F4C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFilePointerEx] [01F46158] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFilePointer] [01F460FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileMappingA] [01F46421] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileMappingW] [01F4647C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [01F219FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [01F45EE6] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [01F45E80] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [01F21ADA] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [01F21922] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CloseHandle] [01F46209] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!CreateFileA] [01F45E80] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!CreateFileMappingA] [01F46421] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [01F219FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetFileSize] [01F4624A] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!SetFilePointer] [01F460FE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!ReadFile] [01F45F4C] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!WriteFile] [01F45FFE] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!CloseHandle] [01F46209] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!CreateFileW] [01F45EE6] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [01F21922] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [01F21ADA] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateIoCompletionPort] [01F4632B] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetQueuedCompletionStatus] [01F4637F] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [01F21788] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
IAT C:\Program Files\PPStream\PPSAP.exe[3524] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [01F21855] C:\Program Files\PPStream\1.1.0.2730\vodres.dll (PPS ¶¯Ì¬Á´½Ó¿â/PPStream Inc.)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 866101F8
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
Device \Driver\volmgr \Device\VolMgrControl 8660C1F8
Device \Driver\usbohci \Device\USBPDO-0 86EBB500
Device \Driver\usbohci \Device\USBPDO-1 86EBB500
Device \Driver\usbehci \Device\USBPDO-2 86EBD500
Device \Driver\NetBT \Device\NetBT_Tcpip_{CA108F1E-0803-4775-A3B9-596F5A3E967F} 86DD11F8
Device \Driver\usbohci \Device\USBPDO-3 86EBB500
Device \Driver\PCI_PNP1123 \Device\00000060 spcy.sys
Device \Driver\usbohci \Device\USBPDO-4 86EBB500
Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbehci \Device\USBPDO-5 86EBD500
Device \Driver\usbohci \Device\USBPDO-6 86EBB500
Device \Driver\volmgr \Device\HarddiskVolume1 8660C1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\volmgr \Device\HarddiskVolume2 8660C1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 86CB51F8
Device \Driver\volmgr \Device\HarddiskVolume3 8660C1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 86CB51F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 8660E1F8
Device \Driver\atapi \Device\Ide\IdePort0 8660E1F8
Device \Driver\atapi \Device\Ide\IdePort1 8660E1F8
Device \Driver\atapi \Device\Ide\IdePort2 8660E1F8
Device \Driver\atapi \Device\Ide\IdePort3 8660E1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-3 8660E1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-6 8660E1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-7 8660E1F8
Device \Driver\volmgr \Device\HarddiskVolume4 8660C1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\volmgr \Device\HarddiskVolume5 8660C1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\volmgr \Device\HarddiskVolume6 8660C1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBt_Wins_Export 86DD11F8
Device \Driver\usbohci \Device\USBFDO-0 86EBB500
Device \Driver\usbohci \Device\USBFDO-1 86EBB500
Device \Driver\usbehci \Device\USBFDO-2 86EBD500
Device \Driver\usbohci \Device\USBFDO-3 86EBB500
Device \Driver\usbohci \Device\USBFDO-4 86EBB500
Device \Driver\usbehci \Device\USBFDO-5 86EBD500
Device \Driver\sptd \Device\2873703129 spcy.sys
Device \Driver\usbohci \Device\USBFDO-6 86EBB500
Device \Driver\a5srzgoj \Device\Scsi\a5srzgoj1Port4Path0Target0Lun0 86D2B1F8
Device \Driver\a5srzgoj \Device\Scsi\a5srzgoj1 86D2B1F8
---- Threads - GMER 1.0.15 ----
Thread System [4:276] 86E4A930
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0011f603bf6a
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0011f603bf6a@0025e774e267 0x8F 0xF6 0x1D 0x93 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x22 0x25 0x5B 0x8B ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x37 0x87 0x36 0xE1 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x66 0x0B 0xB5 0xE3 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0011f603bf6a (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0011f603bf6a@0025e774e267 0x8F 0xF6 0x1D 0x93 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x22 0x25 0x5B 0x8B ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x37 0x87 0x36 0xE1 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x66 0x0B 0xB5 0xE3 ...
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\146@DoneAddingCrawlSeeds 0
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: MBR rootkit code detected
---- EOF - GMER 1.0.15 ----
Added on January 10, 2010, 4:43 pmpls help
Added on January 10, 2010, 5:58 pmsomeone ?
Added on January 11, 2010, 9:50 amplease help me out !!! thanks.
Added on January 11, 2010, 7:48 pmHELP me please !
This post has been edited by quanonly90: Jan 11 2010, 07:48 PM