GMER 1.0.15.15125 -
http://www.gmer.netRootkit scan 2009-10-09 16:51:36
Windows 5.1.2600 Service Pack 2
Running: 23be4qiz.exe; Driver: C:\DOCUME~1\Fong\LOCALS~1\Temp\uwtdypob.sys
---- System - GMER 1.0.15 ----
Code 8A93533E ZwEnumerateKey
Code 8A934FD6 ZwFlushInstructionCache
Code 8A938426 ZwSaveKey
Code 8A9382AE ZwSaveKeyEx
Code 8A9357D5 IofCallDriver
Code 8A935A75 IofCompleteRequest
Code 8A93282D ZwSaveKey
Code 8A9250B5 ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EE0E6 5 Bytes JMP 8A9357DA
.text ntkrnlpa.exe!IofCompleteRequest 804EE176 5 Bytes JMP 8A935A7A
.text ntkrnlpa.exe!ZwSaveKey 804FE584 5 Bytes JMP 8A932832
.text ntkrnlpa.exe!ZwSaveKeyEx 804FE598 5 Bytes JMP 8A9250BA
.text ntkrnlpa.exe!KeReleaseInStackQueuedSpinLockFromDpcLevel + 816 8053C83A 4 Bytes CALL 897D21D2 00000B8A
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805AACBA 5 Bytes JMP 8A934FDA
PAGE ntkrnlpa.exe!ZwSaveKey 8061748A 5 Bytes JMP 8A93842A
PAGE ntkrnlpa.exe!ZwSaveKeyEx 8061751A 5 Bytes JMP 8A9382B2
PAGE ntkrnlpa.exe!ZwEnumerateKey 80619820 5 Bytes JMP 8A935342
? C:\windows\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload B959A7AE 5 Bytes JMP 8A8485A0
? System32\Drivers\alxn12du.SYS The system cannot find the path specified. !
? 00000B8A The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!DialogBoxIndirectParamW 77D6204B 5 Bytes JMP 7E38C510 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!MessageBoxIndirectA 77D6A062 5 Bytes JMP 7E38C491 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!DialogBoxParamA 77D6B124 5 Bytes JMP 7E38C4D5 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!MessageBoxExW 77D80540 5 Bytes JMP 7E38C3D9 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!MessageBoxExA 77D80564 5 Bytes JMP 7E38C413 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!DialogBoxIndirectParamA 77D86CB5 5 Bytes JMP 7E38C54B C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] USER32.dll!MessageBoxIndirectW 77D9609B 5 Bytes JMP 7E38C44D C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] WININET.dll!HttpAddRequestHeadersA 771C0FA7 5 Bytes JMP 0108000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] WININET.dll!HttpAddRequestHeadersW 77228A3D 5 Bytes JMP 0128000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00D627E0
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] WS2_32.dll!send 71AB428A 5 Bytes JMP 00D627C0
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00D627A0
.text C:\Program Files\Internet Explorer\Iexplore.exe[560] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00D629A0
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6C0AD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6C0C1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6C0B9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6C1748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6C161E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6D5ACA] sptd.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\Explorer.EXE[420] @ C:\windows\Explorer.EXE [USER32.dll!TranslateMessage] 015E5736
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 015E51CB
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 015E5117
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 015E50B2
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 015E5080
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 015E5484
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 015E5736
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 015E5736
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 015E5736
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 015E5484
IAT C:\windows\Explorer.EXE[420] @ C:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 015E51CB
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\services.exe [ntdll.dll!NtQueryDirectoryFile] 013A51CB
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 013A51CB
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 013A5117
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 013A50B2
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 013A5080
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 013A5484
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 013A5736
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 013A5736
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 013A5484
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 013A5736
IAT C:\windows\system32\services.exe[852] @ C:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 013A51CB
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00F551CB
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00F55117
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00F550B2
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00F55080
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 00F55117
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00F551CB
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 00F55117
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00F550B2
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00F55484
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00F55736
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00F55736
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00F55484
IAT C:\windows\system32\lsass.exe[864] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00F55736
IAT C:\windows\system32\svchost.exe[1036] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 02AE5080
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00405117
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004050B2
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00405080
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\windows\System32\alg.exe[1140] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00FB51CB
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00FB5117
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00FB50B2
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00FB5080
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FB5736
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00FB5484
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00FB5736
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00FB5736
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00FB5484
IAT C:\windows\system32\svchost.exe[1152] @ C:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00FB51CB
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01A051CB
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01A05117
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01A050B2
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 01A05080
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01A05736
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 01A05484
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 01A05736
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01A05736
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01A05484
IAT C:\windows\System32\svchost.exe[1248] @ C:\windows\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 01A051CB
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00405117
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004050B2
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00405080
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\WINDOWS\system32\msiexec.exe[1616] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00405117
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004050B2
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00405080
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\windows\system32\svchost.exe[1816] @ C:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001451CB
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00145117
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 001450B2
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00145080
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145736
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145736
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145484
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00145484
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00145736
IAT C:\Documents and Settings\Fong\Desktop\23be4qiz.exe[2168] @ C:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001451CB
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00405117
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004050B2
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00405080
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\ole32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\ole32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405736
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405484
IAT C:\windows\System32\svchost.exe[2364] @ C:\windows\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004051CB
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8AF421E8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbohci \Device\USBPDO-0 8A8537A0
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8AF441E8
Device \Driver\dmio \Device\DmControl\DmConfig 8AF441E8
Device \Driver\dmio \Device\DmControl\DmPnP 8AF441E8
Device \Driver\dmio \Device\DmControl\DmInfo 8AF441E8
Device \Driver\usbehci \Device\USBPDO-1 8A8F25C8
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\Ftdisk \Device\HarddiskVolume1 8AED91E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8AED91E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8AED91E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8AED81E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 8AED81E8
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 8AED81E8
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\NetBT \Device\NetBt_Wins_Export 8AC3B620
Device \Driver\NetBT \Device\NetBT_Tcpip_{DA5111B4-4FD1-4B9D-A8AE-FA4483C4DF47} 8AC3B620
Device \Driver\NetBT \Device\NetbiosSmb 8AC3B620
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbohci \Device\USBFDO-0 8A8537A0
Device \Driver\usbehci \Device\USBFDO-1 8A8F25C8
Device \Driver\nvata \Device\NvAta0 8AF431E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A91B7A0
Device \Driver\PCI_NTPNP4864 \Device 00006e sptd.sys
Device \Driver\nvata \Device\NvAta1 8AF431E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A91B7A0
Device \Driver\rjbdive \Device\{9DD6AFA1-8646-4720-836B-EDCB1085864A} 00000B8A
Device \Driver\nvata \Device\NvAta2 8AF431E8
Device \Driver\Ftdisk \Device\FtControl 8AED91E8
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target3Lun0 8A83D5C0
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target3Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target2Lun0 8A83D5C0
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target2Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target0Lun0 8A83D5C0
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\alxn12du \Device\Scsi\alxn12du1 8A83D5C0
Device \Driver\alxn12du \Device\Scsi\alxn12du1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target1Lun0 8A83D5C0
Device \Driver\alxn12du \Device\Scsi\alxn12du1Port5Path0Target1Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Cdfs \Cdfs 8A85E7A0
---- Threads - GMER 1.0.15 ----
Thread System [4:1980] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.1980] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.1980] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.1980] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.1980] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.1980] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.1980] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.1980] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.1980] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.1980] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.1980] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.1980] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.1980] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.1980] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.1980] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:1984] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.1984] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.1984] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.1984] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.1984] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.1984] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.1984] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.1984] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.1984] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.1984] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.1984] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.1984] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.1984] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.1984] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.1984] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:1988] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.1988] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.1988] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.1988] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.1988] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.1988] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.1988] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.1988] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.1988] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.1988] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.1988] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.1988] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.1988] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.1988] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.1988] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:1992] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.1992] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.1992] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.1992] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.1992] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.1992] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.1992] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.1992] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.1992] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.1992] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.1992] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.1992] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.1992] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.1992] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.1992] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:828] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.828] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.828] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.828] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.828] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.828] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.828] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.828] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.828] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.828] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.828] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.828] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.828] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.828] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.828] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:1312] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.1312] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.1312] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.1312] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.1312] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.1312] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.1312] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.1312] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.1312] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.1312] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.1312] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.1312] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.1312] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.1312] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.1312] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:988] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.988] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.988] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.988] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.988] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.988] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.988] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.988] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.988] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.988] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.988] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.988] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.988] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.988] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.988] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:984] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.984] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.984] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.984] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.984] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.984] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.984] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.984] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.984] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.984] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.984] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.984] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.984] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.984] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.984] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:1284] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.1284] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.1284] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.1284] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.1284] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.1284] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.1284] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.1284] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.1284] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.1284] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.1284] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.1284] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.1284] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.1284] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.1284] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread System [4:2180] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A System [4.2180] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A System [4.2180] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A System [4.2180] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A System [4.2180] ZwOpenKey [0x897D11B5]
SSDT 00000B8A System [4.2180] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A System [4.2180] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A System [4.2180] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A System [4.2180] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A System [4.2180] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A System [4.2180] ZwSetContextThread [0x897D1152]
SSDT 00000B8A System [4.2180] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A System [4.2180] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A System [4.2180] ZwTerminateThread [0x897D108C]
SSDT 00000B8A System [4.2180] ZwWriteVirtualMemory [0x897D171B]
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\UACiswsbomawk.dll (*** hidden *** ) @ C:\windows\Explorer.EXE [420] 0x00D50000
---- Threads - GMER 1.0.15 ----
Thread explorer.exe [420:580] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A explorer.exe [420.580] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A explorer.exe [420.580] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A explorer.exe [420.580] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A explorer.exe [420.580] ZwOpenKey [0x897D11B5]
SSDT 00000B8A explorer.exe [420.580] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A explorer.exe [420.580] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A explorer.exe [420.580] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A explorer.exe [420.580] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A explorer.exe [420.580] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A explorer.exe [420.580] ZwSetContextThread [0x897D1152]
SSDT 00000B8A explorer.exe [420.580] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A explorer.exe [420.580] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A explorer.exe [420.580] ZwTerminateThread [0x897D108C]
SSDT 00000B8A explorer.exe [420.580] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread explorer.exe [420:1884] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A explorer.exe [420.1884] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A explorer.exe [420.1884] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A explorer.exe [420.1884] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A explorer.exe [420.1884] ZwOpenKey [0x897D11B5]
SSDT 00000B8A explorer.exe [420.1884] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A explorer.exe [420.1884] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A explorer.exe [420.1884] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A explorer.exe [420.1884] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A explorer.exe [420.1884] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A explorer.exe [420.1884] ZwSetContextThread [0x897D1152]
SSDT 00000B8A explorer.exe [420.1884] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A explorer.exe [420.1884] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A explorer.exe [420.1884] ZwTerminateThread [0x897D108C]
SSDT 00000B8A explorer.exe [420.1884] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread explorer.exe [420:260] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A explorer.exe [420.260] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A explorer.exe [420.260] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A explorer.exe [420.260] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A explorer.exe [420.260] ZwOpenKey [0x897D11B5]
SSDT 00000B8A explorer.exe [420.260] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A explorer.exe [420.260] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A explorer.exe [420.260] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A explorer.exe [420.260] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A explorer.exe [420.260] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A explorer.exe [420.260] ZwSetContextThread [0x897D1152]
SSDT 00000B8A explorer.exe [420.260] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A explorer.exe [420.260] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A explorer.exe [420.260] ZwTerminateThread [0x897D108C]
SSDT 00000B8A explorer.exe [420.260] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread explorer.exe [420:308] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A explorer.exe [420.308] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A explorer.exe [420.308] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A explorer.exe [420.308] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A explorer.exe [420.308] ZwOpenKey [0x897D11B5]
SSDT 00000B8A explorer.exe [420.308] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A explorer.exe [420.308] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A explorer.exe [420.308] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A explorer.exe [420.308] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A explorer.exe [420.308] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A explorer.exe [420.308] ZwSetContextThread [0x897D1152]
SSDT 00000B8A explorer.exe [420.308] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A explorer.exe [420.308] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A explorer.exe [420.308] ZwTerminateThread [0x897D108C]
SSDT 00000B8A explorer.exe [420.308] ZwWriteVirtualMemory [0x897D171B]
Library \\?\globalroot\systemroot\system32\UACiswsbomawk.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [560] 0x00F50000
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:1872] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.1872] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.1872] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.1872] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.1872] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.1872] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.1872] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.1872] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.1872] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.1872] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.1872] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.1872] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.1872] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.1872] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.1872] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:1876] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.1876] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.1876] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.1876] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.1876] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.1876] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.1876] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.1876] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.1876] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.1876] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.1876] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.1876] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.1876] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.1876] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.1876] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:1880] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.1880] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.1880] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.1880] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.1880] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.1880] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.1880] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.1880] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.1880] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.1880] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.1880] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.1880] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.1880] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.1880] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.1880] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:1928] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.1928] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.1928] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.1928] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.1928] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.1928] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.1928] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.1928] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.1928] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.1928] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.1928] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.1928] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.1928] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.1928] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.1928] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:608] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.608] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.608] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.608] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.608] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.608] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.608] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.608] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.608] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.608] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.608] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.608] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.608] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.608] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.608] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:660] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.660] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.660] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.660] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.660] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.660] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.660] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.660] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.660] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.660] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.660] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.660] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.660] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.660] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.660] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:1788] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.1788] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.1788] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.1788] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.1788] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.1788] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.1788] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.1788] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.1788] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.1788] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.1788] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.1788] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.1788] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.1788] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.1788] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:2108] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.2108] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.2108] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.2108] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.2108] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.2108] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.2108] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.2108] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.2108] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.2108] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.2108] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.2108] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.2108] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.2108] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.2108] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread iexplore.exe [560:2112] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A iexplore.exe [560.2112] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A iexplore.exe [560.2112] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A iexplore.exe [560.2112] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A iexplore.exe [560.2112] ZwOpenKey [0x897D11B5]
SSDT 00000B8A iexplore.exe [560.2112] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A iexplore.exe [560.2112] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A iexplore.exe [560.2112] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A iexplore.exe [560.2112] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A iexplore.exe [560.2112] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A iexplore.exe [560.2112] ZwSetContextThread [0x897D1152]
SSDT 00000B8A iexplore.exe [560.2112] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A iexplore.exe [560.2112] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A iexplore.exe [560.2112] ZwTerminateThread [0x897D108C]
SSDT 00000B8A iexplore.exe [560.2112] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread winlogon.exe [796:1940] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A winlogon.exe [796.1940] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A winlogon.exe [796.1940] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A winlogon.exe [796.1940] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A winlogon.exe [796.1940] ZwOpenKey [0x897D11B5]
SSDT 00000B8A winlogon.exe [796.1940] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A winlogon.exe [796.1940] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A winlogon.exe [796.1940] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A winlogon.exe [796.1940] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A winlogon.exe [796.1940] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A winlogon.exe [796.1940] ZwSetContextThread [0x897D1152]
SSDT 00000B8A winlogon.exe [796.1940] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A winlogon.exe [796.1940] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A winlogon.exe [796.1940] ZwTerminateThread [0x897D108C]
SSDT 00000B8A winlogon.exe [796.1940] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread winlogon.exe [796:1944] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A winlogon.exe [796.1944] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A winlogon.exe [796.1944] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A winlogon.exe [796.1944] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A winlogon.exe [796.1944] ZwOpenKey [0x897D11B5]
SSDT 00000B8A winlogon.exe [796.1944] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A winlogon.exe [796.1944] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A winlogon.exe [796.1944] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A winlogon.exe [796.1944] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A winlogon.exe [796.1944] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A winlogon.exe [796.1944] ZwSetContextThread [0x897D1152]
SSDT 00000B8A winlogon.exe [796.1944] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A winlogon.exe [796.1944] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A winlogon.exe [796.1944] ZwTerminateThread [0x897D108C]
SSDT 00000B8A winlogon.exe [796.1944] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread services.exe [852:1400] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A services.exe [852.1400] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A services.exe [852.1400] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A services.exe [852.1400] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A services.exe [852.1400] ZwOpenKey [0x897D11B5]
SSDT 00000B8A services.exe [852.1400] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A services.exe [852.1400] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A services.exe [852.1400] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A services.exe [852.1400] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A services.exe [852.1400] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A services.exe [852.1400] ZwSetContextThread [0x897D1152]
SSDT 00000B8A services.exe [852.1400] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A services.exe [852.1400] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A services.exe [852.1400] ZwTerminateThread [0x897D108C]
SSDT 00000B8A services.exe [852.1400] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread lsass.exe [864:964] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A lsass.exe [864.964] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A lsass.exe [864.964] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A lsass.exe [864.964] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A lsass.exe [864.964] ZwOpenKey [0x897D11B5]
SSDT 00000B8A lsass.exe [864.964] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A lsass.exe [864.964] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A lsass.exe [864.964] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A lsass.exe [864.964] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A lsass.exe [864.964] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A lsass.exe [864.964] ZwSetContextThread [0x897D1152]
SSDT 00000B8A lsass.exe [864.964] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A lsass.exe [864.964] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A lsass.exe [864.964] ZwTerminateThread [0x897D108C]
SSDT 00000B8A lsass.exe [864.964] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread lsass.exe [864:1860] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A lsass.exe [864.1860] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A lsass.exe [864.1860] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A lsass.exe [864.1860] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A lsass.exe [864.1860] ZwOpenKey [0x897D11B5]
SSDT 00000B8A lsass.exe [864.1860] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A lsass.exe [864.1860] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A lsass.exe [864.1860] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A lsass.exe [864.1860] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A lsass.exe [864.1860] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A lsass.exe [864.1860] ZwSetContextThread [0x897D1152]
SSDT 00000B8A lsass.exe [864.1860] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A lsass.exe [864.1860] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A lsass.exe [864.1860] ZwTerminateThread [0x897D108C]
SSDT 00000B8A lsass.exe [864.1860] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread lsass.exe [864:1864] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A lsass.exe [864.1864] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A lsass.exe [864.1864] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A lsass.exe [864.1864] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A lsass.exe [864.1864] ZwOpenKey [0x897D11B5]
SSDT 00000B8A lsass.exe [864.1864] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A lsass.exe [864.1864] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A lsass.exe [864.1864] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A lsass.exe [864.1864] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A lsass.exe [864.1864] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A lsass.exe [864.1864] ZwSetContextThread [0x897D1152]
SSDT 00000B8A lsass.exe [864.1864] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A lsass.exe [864.1864] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A lsass.exe [864.1864] ZwTerminateThread [0x897D108C]
SSDT 00000B8A lsass.exe [864.1864] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread lsass.exe [864:1868] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A lsass.exe [864.1868] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A lsass.exe [864.1868] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A lsass.exe [864.1868] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A lsass.exe [864.1868] ZwOpenKey [0x897D11B5]
SSDT 00000B8A lsass.exe [864.1868] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A lsass.exe [864.1868] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A lsass.exe [864.1868] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A lsass.exe [864.1868] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A lsass.exe [864.1868] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A lsass.exe [864.1868] ZwSetContextThread [0x897D1152]
SSDT 00000B8A lsass.exe [864.1868] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A lsass.exe [864.1868] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A lsass.exe [864.1868] ZwTerminateThread [0x897D108C]
SSDT 00000B8A lsass.exe [864.1868] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1036:1780] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1036.1780] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1036.1780] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1036.1780] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1036.1780] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1036.1780] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1036.1780] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1036.1780] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1036.1780] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1036.1780] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1036.1780] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1036.1780] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1036.1780] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1036.1780] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1036.1780] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1036:1924] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1036.1924] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1036.1924] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1036.1924] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1036.1924] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1036.1924] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1036.1924] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1036.1924] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1036.1924] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1036.1924] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1036.1924] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1036.1924] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1036.1924] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1036.1924] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1036.1924] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1036:244] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1036.244] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1036.244] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1036.244] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1036.244] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1036.244] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1036.244] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1036.244] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1036.244] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1036.244] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1036.244] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1036.244] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1036.244] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1036.244] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1036.244] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:1116] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A alg.exe [1140.1116] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.1116] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.1116] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.1116] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.1116] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.1116] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.1116] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.1116] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.1116] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.1116] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.1116] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.1116] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.1116] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.1116] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:1896] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A alg.exe [1140.1896] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.1896] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.1896] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.1896] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.1896] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.1896] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.1896] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.1896] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.1896] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.1896] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.1896] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.1896] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.1896] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.1896] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:288] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A alg.exe [1140.288] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.288] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.288] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.288] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.288] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.288] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.288] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.288] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.288] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.288] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.288] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.288] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.288] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.288] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:292] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A alg.exe [1140.292] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.292] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.292] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.292] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.292] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.292] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.292] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.292] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.292] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.292] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.292] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.292] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.292] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.292] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:188] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A alg.exe [1140.188] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.188] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.188] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.188] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.188] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.188] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.188] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.188] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.188] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.188] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.188] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.188] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.188] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.188] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:300] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A alg.exe [1140.300] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.300] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.300] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.300] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.300] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.300] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.300] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.300] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.300] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.300] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.300] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.300] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.300] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.300] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:324] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A alg.exe [1140.324] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.324] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.324] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.324] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.324] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.324] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.324] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.324] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.324] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.324] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.324] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.324] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.324] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.324] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread alg.exe [1140:340] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A alg.exe [1140.340] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A alg.exe [1140.340] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A alg.exe [1140.340] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A alg.exe [1140.340] ZwOpenKey [0x897D11B5]
SSDT 00000B8A alg.exe [1140.340] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A alg.exe [1140.340] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A alg.exe [1140.340] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A alg.exe [1140.340] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A alg.exe [1140.340] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A alg.exe [1140.340] ZwSetContextThread [0x897D1152]
SSDT 00000B8A alg.exe [1140.340] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A alg.exe [1140.340] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A alg.exe [1140.340] ZwTerminateThread [0x897D108C]
SSDT 00000B8A alg.exe [1140.340] ZwWriteVirtualMemory [0x897D171B]
Library \\?\globalroot\systemroot\system32\UACedyrsvskgo.dll (*** hidden *** ) @ C:\windows\system32\svchost.exe [1152] 0x10000000
Library \\?\globalroot\systemroot\system32\UACkbfnyprpfg.dll (*** hidden *** ) @ C:\windows\system32\svchost.exe [1152] 0x009E0000
Library \\?\globalroot\systemroot\system32\UACedyrsvskgo.dll (*** hidden *** ) @ C:\windows\System32\svchost.exe [1248] 0x10000000
Library \\?\globalroot\systemroot\system32\UACkbfnyprpfg.dll (*** hidden *** ) @ C:\windows\System32\svchost.exe [1248] 0x009D0000
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1608] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1608] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1608] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1608] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1608] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1608] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1608] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1608] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1608] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1608] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1608] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1608] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1608] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1608] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1608] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1704] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1704] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1704] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1704] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1704] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1704] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1704] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1704] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1704] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1704] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1704] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1704] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1704] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1704] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1704] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:272] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.272] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.272] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.272] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.272] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.272] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.272] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.272] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.272] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.272] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.272] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.272] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.272] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.272] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.272] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1604] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1604] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1604] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1604] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1604] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1604] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1604] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1604] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1604] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1604] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1604] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1604] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1604] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1604] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1604] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1932] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1932] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1932] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1932] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1932] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1932] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1932] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1932] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1932] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1932] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1932] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1932] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1932] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1932] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1932] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1936] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1936] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1936] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1936] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1936] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1936] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1936] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1936] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1936] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1936] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1936] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1936] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1936] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1936] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1936] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1948] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1948] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1948] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1948] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1948] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1948] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1948] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1948] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1948] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1948] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1948] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1948] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1948] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1948] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1948] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:1972] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.1972] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.1972] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.1972] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.1972] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.1972] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.1972] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.1972] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.1972] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.1972] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.1972] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.1972] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.1972] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.1972] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.1972] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:2008] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.2008] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.2008] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.2008] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.2008] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.2008] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.2008] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.2008] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.2008] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.2008] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.2008] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.2008] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.2008] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.2008] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.2008] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:2012] SSDT 0x8A7578B8 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.2012] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.2012] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.2012] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.2012] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.2012] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.2012] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.2012] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.2012] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.2012] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.2012] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.2012] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.2012] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.2012] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.2012] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:2020] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.2020] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.2020] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.2020] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.2020] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.2020] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.2020] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.2020] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.2020] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.2020] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.2020] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.2020] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.2020] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.2020] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.2020] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:2028] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.2028] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.2028] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.2028] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.2028] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.2028] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.2028] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.2028] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.2028] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.2028] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.2028] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.2028] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.2028] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.2028] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.2028] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:916] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.916] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.916] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.916] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.916] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.916] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.916] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.916] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.916] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.916] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.916] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.916] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.916] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.916] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.916] ZwWriteVirtualMemory [0x897D171B]
---- Threads - GMER 1.0.15 ----
Thread svchost.exe [1248:248] SSDT 0x8A758448 != 0x8050131C
SSDT 00000B8A svchost.exe [1248.248] ZwDeleteValueKey [0x897D15BD]
SSDT 00000B8A svchost.exe [1248.248] ZwEnumerateKey [0x897D126D]
SSDT 00000B8A svchost.exe [1248.248] ZwEnumerateValueKey [0x897D1379]
SSDT 00000B8A svchost.exe [1248.248] ZwOpenKey [0x897D11B5]
SSDT 00000B8A svchost.exe [1248.248] ZwOpenProcess [0x897D0F1F]
SSDT 00000B8A svchost.exe [1248.248] ZwOpenThread [0x897D0FA7]
SSDT 00000B8A svchost.exe [1248.248] ZwProtectVirtualMemory [0x897D1781]
SSDT 00000B8A svchost.exe [1248.248] ZwQuerySystemInformation [0x897D0E19]
SSDT 00000B8A svchost.exe [1248.248] ZwReadVirtualMemory [0x897D16B5]
SSDT 00000B8A svchost.exe [1248.248] ZwSetContextThread [0x897D1152]
SSDT 00000B8A svchost.exe [1248.248] ZwSetValueKey [0x897D14B9]
SSDT 00000B8A svchost.exe [1248.248] ZwSuspendThread [0x897D10EF]
SSDT 00000B8A svchost.exe [1248.248] ZwTerminateThread [0x897D108C]
SSDT 00000B8A svchost.exe [1248.248] ZwWriteVirtualMemory [0x897D171B]