GMER scan taking much longer than expected. Willl post when it is done
EDIT: its up now. Sorry about the weird line breaks.. it just happened when i pasted it. The GMER scan terminated with a "Rootkit modifications detected" (or something along these lines)
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-28 11:33:49
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF0F716B8] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF0F71574] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF0F71A52] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF0F7114C] <-- ROOTKIT !!!
SSDT spuc.sys ZwEnumerateKey [0xF5BBECA2] <-- ROOTKIT !!!
SSDT spuc.sys ZwEnumerateValueKey [0xF5BBF030] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF0F7164E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF0F7108C] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF0F710F0] <-- ROOTKIT !!!
SSDT spuc.sys ZwQueryKey [0xF5BBF108] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF0F7176E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF0F7172E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF0F718AE] <-- ROOTKIT !!!
INT 0x62 ? FCC5BD64
INT 0x63 ? FC8472AC
INT 0x73 ? FC9AEE54
INT 0x74 ? FCAE3974
INT 0x82 ? FCC59E54
INT 0x83 ? FCC62D54
INT 0x84 ? FC99752C
INT 0x93 ? FC8EF5FC
INT 0x94 ? FC976E54
INT 0xA3 ? FCA95E54
INT 0xA4 ? FC9F18DC
INT 0xB1 ? FCD06E54
INT 0xB4 ? FCAF276C
---- Kernel code sections - GMER 1.0.15 ----
? spuc.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F4BFE62C 5 Bytes JMP FCC861D8
.text vaxscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 F4AEE4D0 48 Bytes [FC, 38, AF, B9, 7E, F5, EB, ...]
? C:\WINDOWS\System32\Drivers\vaxscsi.sys The process cannot access the file because it is being used by another process.
.text al07kawl.SYS F4AB6386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text al07kawl.SYS F4AB63AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text al07kawl.SYS F4AB63C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text al07kawl.SYS F4AB63C9 1 Byte [2E]
.text al07kawl.SYS F4AB63C9 11 Bytes [2E, 00, 00, 00, 5A, 02, 00, ...]
.text ...
? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] KERNEL32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] KERNEL32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] KERNEL32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[276] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F200F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F1A0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F1D0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F230F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [18, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[436] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[512] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\stsystra.exe[516] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\stsystra.exe[516] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\stsystra.exe[516] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\stsystra.exe[516] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[544] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Saitek\Software\Profiler.exe[560] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Saitek\Software\Profiler.exe[560] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Saitek\Software\SaiMfd.exe[628] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\Ati2evxx.exe[808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[808] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[1136] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[1136] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe[1392] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\Explorer.EXE[1464] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[1464] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[1464] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1464] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\rundll32.exe[2080] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2080] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Razer\Diamondback 3G\razerhid.exe[2392] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\NOTEPAD.EXE[2416] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\joonhi\Desktop\vfnhodbh.exe[2696] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe[2804] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2868] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wscntfy.exe[2976] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wscntfy.exe[2976] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[2976] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[3088] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe[3160] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] KERNEL32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] KERNEL32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] KERNEL32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3184] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text E:\Program Files\Java\jre6\bin\jusched.exe[3252] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Razer\Diamondback 3G\razerofa.exe[3280] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3292] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text E:\Program Files\Free Download Manager\fdm.exe[3320] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text E:\Program Files\Free Download Manager\fdm.exe[3320] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text E:\Program Files\Free Download Manager\fdm.exe[3320] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Contacts\wlcomm.exe[3332] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text E:\Program Files\DAEMON Tools Lite\daemon.exe[3348] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3464] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\System32\alg.exe[3580] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] kernel32.dll!ExitProcess 7C81CDDA 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!EndPage 77F2DDB1 6 Bytes JMP 5F190F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!EndDoc 77F2E041 6 Bytes JMP 5F130F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!StartPage 77F2F116 6 Bytes JMP 5F160F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!AbortDoc 77F43EFF 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!StartDocW 77F44B8F 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!StartDocW + 4 77F44B93 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!StartDocA 77F450A9 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe[3808] GDI32.dll!StartDocA + 4 77F450AD 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F5BA1040] spuc.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F5BA113C] spuc.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F5BA10BE] spuc.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F5BA17FC] spuc.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F5BA16D2] spuc.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F5BB1048] spuc.sys
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\al07kawl.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[912] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[912] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs FCC851F8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \FatCdrom FA42E1F8
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
Device \Driver\usbuhci \Device\USBPDO-0 FCA3E1F8
Device \Driver\usbuhci \Device\USBPDO-1 FCA3E1F8
Device \Driver\usbuhci \Device\USBPDO-2 FCA3E1F8
Device \Driver\usbuhci \Device\USBPDO-3 FCA3E1F8
Device \Driver\usbehci \Device\USBPDO-4 FCA111F8
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{028D2654-F787-43B1-B6BB-85DEEF136108} FC926500
Device \Driver\Ftdisk \Device\HarddiskVolume1 FCC871F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 FCC871F8
Device \Driver\Cdrom \Device\CdRom0 FC9B81F8
Device \Driver\sptd \Device\3002608012 spuc.sys
Device \Driver\Ftdisk \Device\HarddiskVolume3 FCC871F8
Device \Driver\Cdrom \Device\CdRom1 FC9B81F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 FCCF61F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 FCCF61F8
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 FCCF61F8
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e FCCF61F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\PCI_PNP9262 \Device 000066 spuc.sys
Device \Driver\PCI_PNP9262 \Device 000067 spuc.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{849E3F7A-920B-4801-B7C3-DD485E8252FF} FC926500
Device \Driver\NetBT \Device\NetBt_Wins_Export FC926500
Device \Driver\NetBT \Device\NetbiosSmb FC926500
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBFDO-0 FCA3E1F8
Device \Driver\usbuhci \Device\USBFDO-1 FCA3E1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver FC983500
Device \Driver\usbuhci \Device\USBFDO-2 FCA3E1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector FC983500
Device \Driver\usbuhci \Device\USBFDO-3 FCA3E1F8
Device \Driver\usbehci \Device\USBFDO-4 FCA111F8
Device \Driver\Ftdisk \Device\FtControl FCC871F8
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 FC9F2500
Device \Driver\al07kawl \Device\Scsi\al07kawl1Port2Path0Target0Lun0 FC8C5500
Device \Driver\al07kawl \Device\Scsi\al07kawl1Port2Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\al07kawl \Device\Scsi\al07kawl1 FC8C5500
Device \Driver\al07kawl \Device\Scsi\al07kawl1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Fastfat \Fat FA42E1F8
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Cdfs \Cdfs FC803500
---- Services - GMER 1.0.15 ----
Service system32\drivers\UACbtkxnyqk.sys (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys 1060a53fe6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys 1060a53fe6@001e3a3ef264 0x59 0x71 0xF0 0x62 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys 1060a53fe6@00247c0e1a06 0x8B 0xC1 0xCC 0x4E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04@ujdew 0xDA 0x3D 0xC7 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001@ujdew 0x9A 0xA7 0xBA 0xE9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001\jdgg40@ujdew 0xCB 0xCF 0xB7 0xD1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE5 0xD5 0x15 0x9B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 E:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001@khjeh 0x26 0xC2 0x57 0x31 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf40@khjeh 0x24 0x60 0x39 0x10 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf41@khjeh 0xFC 0x1C 0x6F 0x9C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf42@khjeh 0xB7 0x05 0x93 0x9B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACbtkxnyqk.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys 1060a53fe6
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys 1060a53fe6@001e3a3ef264 0x59 0x71 0xF0 0x62 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys 1060a53fe6@00247c0e1a06 0x8B 0xC1 0xCC 0x4E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04@ujdew 0xDA 0x3D 0xC7 0x75 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001@ujdew 0x9A 0xA7 0xBA 0xE9 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001\jdgg40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\CfgD79C293C1ED61418462E24595C90D04 000001\jdgg40@ujdew 0xCB 0xCF 0xB7 0xD1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE5 0xD5 0x15 0x9B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 E:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001@khjeh 0x26 0xC2 0x57 0x31 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf40@khjeh 0x24 0x60 0x39 0x10 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf41@khjeh 0xFC 0x1C 0x6F 0x9C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf42
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 000001Jf42@khjeh 0xB7 0x05 0x93 0x9B ...
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACbtkxnyqk.sys
Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@group file system
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version@Version 0x77 0x6E 0x0C 0xDF ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6895C28E-790B-C040-24C9-5FC31BD1CB61}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F13CC3FE-D74B-C823-F0DC-FCB1AB595A15}
---- Files - GMER 1.0.15 ----
File C:\Program Files\microsoft frontpage\version3.0 0 bytes
File C:\Program Files\Microsoft Games for Windows - LIVE\Client 0 bytes
File C:\Program Files\Microsoft Games for Windows - LIVE\Client\ja 0 bytes
File C:\Program Files\Microsoft Games for Windows - LIVE\Client\ja\msadctls.dll.mui 13408 bytes executable
---- EOF - GMER 1.0.15 ----