Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 2.2.19882 - http://www.gmer.net
- Rootkit scan 2016-06-19 15:16:23
- Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002d ST1000DM003-1SB102 rev.CC43 931,51GB
- Running: gmer.exe; Driver: C:\Users\komputer\AppData\Local\Temp\ffddipoc.sys
- ---- User code sections - GMER 2.2 ----
- ? C:\Windows\SYSTEM32\NTASN1.dll [2608] entry point in ".rdata" section 0000000071f1bb10
- ? C:\Windows\SYSTEM32\ActXPrxy.dll [3132] entry point in ".rdata" section 000000006f0dbd10
- ? C:\Windows\SYSTEM32\NTASN1.dll [4524] entry point in ".rdata" section 0000000071f1bb10
- ? C:\Windows\system32\apphelp.dll [4524] entry point in ".rdata" section 0000000072050380
- ? C:\Windows\SYSTEM32\iertutil.dll [4220] entry point in ".rdata" section 000000007066d380
- ? C:\Windows\SYSTEM32\NTASN1.dll [4220] entry point in ".rdata" section 0000000071f1bb10
- ? C:\Windows\system32\apphelp.dll [2420] entry point in ".rdata" section 0000000072050380
- ? C:\Windows\SYSTEM32\iertutil.dll [4292] entry point in ".rdata" section 000000007066d380
- ? C:\Windows\system32\wbem\wbemsvc.dll [4292] entry point in ".rdata" section 0000000074018fa0
- ? C:\Windows\SYSTEM32\NTASN1.dll [4292] entry point in ".rdata" section 0000000071f1bb10
- ? C:\Windows\SYSTEM32\srpapi.dll [4292] entry point in ".rdata" section 0000000069b22a90
- ? C:\Windows\SYSTEM32\ActXPrxy.dll [4292] entry point in ".rdata" section 000000006f0dbd10
- ? C:\Windows\SYSTEM32\PhotoMetadataHandler.dll [4292] entry point in ".rdata" section 0000000066135fc0
- ? C:\Windows\SYSTEM32\apphelp.dll [4292] entry point in ".rdata" section 0000000072050380
- ? C:\Windows\SYSTEM32\iertutil.dll [3164] entry point in ".rdata" section 000000007066d380
- ? C:\Windows\system32\apphelp.dll [6556] entry point in ".rdata" section 0000000072050380
- ? C:\Windows\system32\wbem\wbemsvc.dll [3456] entry point in ".rdata" section 0000000074018fa0
- ? C:\Windows\SYSTEM32\iertutil.dll [3456] entry point in ".rdata" section 000000007066d380
- ? C:\Windows\system32\apphelp.dll [12348] entry point in ".rdata" section 0000000072050380
- ? C:\Windows\SYSTEM32\iertutil.dll [12348] entry point in ".rdata" section 000000007066d380
- ? C:\Windows\system32\apphelp.dll [12964] entry point in ".rdata" section 0000000072050380
- ? C:\Windows\system32\apphelp.dll [12152] entry point in ".rdata" section 0000000072050380
- ---- User IAT/EAT - GMER 2.2 ----
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\USER32.dll[GDI32.dll!GdiDllInitialize] [7ffc769c002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\USER32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\SHELL32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\SHELL32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\shlwapi.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\COMDLG32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\COMDLG32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\ole32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\system32\ole32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\COMCTL32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\COMCTL32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[5288] @ C:\Windows\SYSTEM32\dwrite.dll[ntdll.dll!NtAlpcConnectPort] [7ffbf9489728] C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\53.0.2772.0\chrome_child.dll
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\USER32.dll[GDI32.dll!GdiDllInitialize] [7ffc769c002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\USER32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\SHELL32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\SHELL32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\shlwapi.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\COMDLG32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\COMDLG32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\ole32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\system32\ole32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\COMCTL32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\COMCTL32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11832] @ C:\Windows\SYSTEM32\dwrite.dll[ntdll.dll!NtAlpcConnectPort] [7ffbf9489728] C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\53.0.2772.0\chrome_child.dll
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\USER32.dll[GDI32.dll!GdiDllInitialize] [7ffc769c002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\USER32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\SHELL32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\SHELL32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\shlwapi.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\COMDLG32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\COMDLG32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\ole32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\system32\ole32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\COMCTL32.dll[GDI32.dll!GetStockObject] [7ffc769c006c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\COMCTL32.dll[USER32.dll!RegisterClassW] [7ffc74a9002c]
- IAT C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\chrome.exe[11296] @ C:\Windows\SYSTEM32\dwrite.dll[ntdll.dll!NtAlpcConnectPort] [7ffbf9489728] C:\Users\komputer\AppData\Local\Google\Chrome SxS\Application\53.0.2772.0\chrome_child.dll
- ---- Threads - GMER 2.2 ----
- Thread C:\Windows\system32\csrss.exe [600:7468] fffff9613cfd4030
- Thread C:\Windows\Explorer.EXE [1904:4536] 00007ffc29500250
- Thread C:\Windows\System32\RuntimeBroker.exe [3252:7228] 00007ffc18ee0250
- Thread C:\Windows\System32\RuntimeBroker.exe [3252:6576] 00007ffc18ee0250
- Thread C:\Windows\System32\RuntimeBroker.exe [3252:11156] 00007ffc18ee0250
- Thread C:\Windows\system32\mmc.exe [11124:7452] 00007ffc2e849230
- Thread C:\Windows\system32\mmc.exe [11124:3520] 00007ffc0a525ae0
- Thread C:\Windows\system32\mmc.exe [11124:6668] 00007ffc0a525ae0
- Thread C:\Windows\system32\mmc.exe [11124:11632] 00007ffc0a547830
- ---- Processes - GMER 2.2 ----
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (Dism Host Servicing Process/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ff626980000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\DismCorePS.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] 00007ffbf5dd0000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismprov.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Provider Store/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5d90000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\OSProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM OS Services Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5d60000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\LogProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Logging Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5d30000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\CbsProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Package Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5c50000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\MsiProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Msi Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5ba0000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\IntlProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM International Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5b40000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\IBSProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM IBS Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5b20000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\DmiProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Driver Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5ac0000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\UnattendProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Unattend Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5a70000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\SmiProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Settings Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf57d0000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\AppxProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM App Package (.appx) Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5750000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\ProvProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Provisioning Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf56a0000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\AssocProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Assoc Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5a50000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\GenericProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Generic Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf58e0000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\OfflineSetupProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM OfflineSetup Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5a30000
- Library C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\TransmogProvider.dll (*** suspicious ***) @ C:\Users\komputer\AppData\Local\Temp\3126E3D0-820A-4042-8204-E66BA96FBF3D\dismhost.exe [11616] (DISM Transmogrify Provider/Microsoft Corporation SIGNED)(2016-06-19 12:40:52) 00007ffbf5610000
- ---- Registry - GMER 2.2 ----
- Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\Windows\TEMP\INS_b84f8ec1.TMP??\??\C:\Windows\TEMP\NvidiaLogging??\??\C:\Users\komputer\AppData\Local\Temp\MSNET-6fd97e0b.NVX??\??\C:\Windows\system32\DRIVERS\SET1163.tmp??\??\C:\Windows\system32\SET1286.tmp??\??\C:\Windows\system32\SET1DD0.tmp??\??\C:\Windows\SysWow64\SET2408.tmp??\??\C:\Users\komputer\AppData\Local\Temp\INS_733a9329.TMP??\??\C:\Users\komputer\AppData\Local\Temp\F8EA.tmp??\??\C:\Users\komputer\AppData\Local\Temp\GoogleUpdate.exe8dffed??\??\C:\Users\komputer\AppData\Local\Temp\goopdate.dll8e001c??
- Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed -900742669
- Reg HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT@Start 3
- Reg HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
- Reg HKLM\SYSTEM\CurrentControlSet\Services\rdyboost\Parameters@LastBootPlanUserTime ?niedz.?, ?cze ?19 ?16, 10:49:54 AM????????????????????????????
- Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 1104
- Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ab494b66-a3c7-4379-bede-43d5f04c9208}@LeaseObtainedTime 1466336855
- Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ab494b66-a3c7-4379-bede-43d5f04c9208}@T1 1466340455
- Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ab494b66-a3c7-4379-bede-43d5f04c9208}@T2 1466343155
- Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ab494b66-a3c7-4379-bede-43d5f04c9208}@LeaseTerminatesTime 1466344055
- Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeConfidence 6
- Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated 0x1F 0x45 0x28 0x4F ...
- Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh 0x1F 0xAD 0xEC 0xB0 ...
- Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow 0x1F 0xDD 0x63 0xED ...
- Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeTickCount 0x4F 0xD6 0xCB 0x00 ...
- ---- Disk sectors - GMER 2.2 ----
- Disk \Device\Harddisk0\DR0 unknown MBR code
- ---- EOF - GMER 2.2 ----
Add Comment
Please, Sign In to add comment