Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 2.1.19357 - http://www.gmer.net
- Rootkit scan 2015-08-31 19:13:58
- Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.GS00 298,09GB
- Running: 1w435to2.exe; Driver: C:\Users\Yazan\AppData\Local\Temp\pgloypob.sys
- ---- User IAT/EAT - GMER 2.1 ----
- IAT C:\Windows\system32\svchost.exe[556] @ c:\windows\system32\themeservice.dll[KERNEL32.dll!GetProcAddress] [7fefa442960] c:\windows\system32\uxtuneup.dll
- IAT C:\Windows\system32\svchost.exe[556] @ c:\windows\system32\themeservice.dll[KERNEL32.dll!ReadFile] [7fefa442840] c:\windows\system32\uxtuneup.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msiexec.exe[ADVAPI32.dll!RegCreateKeyExW] [7fef191b4f4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msiexec.exe[ADVAPI32.dll!RegDeleteValueW] [7fef191bbc8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msiexec.exe[ADVAPI32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msiexec.exe[ADVAPI32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msiexec.exe[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ADVAPI32.dll[KERNEL32.dll!CopyFileW] [7fef191a184] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ADVAPI32.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ADVAPI32.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ADVAPI32.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!RegCreateKeyExW] [7fef191b4f4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!CopyFileW] [7fef191a184] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!SetFileSecurityW] [7fef191bcb0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!RegCreateKeyExW] [7fef191b4f4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!RegSetValueExA] [7fef191ba0c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!RegDeleteValueW] [7fef191bbc8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!RegDeleteKeyW] [7fef191d12c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[ADVAPI32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[KERNEL32.dll!SetFileAttributesW] [7fef191abe0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[KERNEL32.dll!MoveFileW] [7fef191a6e0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\msi.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!CopyFileW] [7fef191a184] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!MoveFileW] [7fef191a6e0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!SetFileAttributesW] [7fef191abe0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!SetFileAttributesA] [7fef191ab7c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateFileA] [7fef191a2d8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WINSPOOL.DRV[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WINSPOOL.DRV[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WINSPOOL.DRV[KERNEL32.dll!SetFileAttributesW] [7fef191abe0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WINSPOOL.DRV[KERNEL32.dll!CopyFileW] [7fef191a184] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WINSPOOL.DRV[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WINSPOOL.DRV[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\MPR.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\sfc_os.DLL[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USERENV.dll[KERNEL32.dll!PrivCopyFileExW] [7fef191ab04] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\USERENV.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\IMM32.DLL[KERNEL32.dll!OpenFile] [7fef191a890] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\IMM32.DLL[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\IMM32.DLL[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\MSCTF.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\COMCTL32.DLL[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\COMCTL32.DLL[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[ADVAPI32.dll!RegDeleteValueW] [7fef191bbc8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[ADVAPI32.dll!RegCreateKeyExW] [7fef191b4f4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[ADVAPI32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[ADVAPI32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!SetFileAttributesW] [7fef191abe0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!MoveFileW] [7fef191a6e0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!_lwrite] [7fef191aa1c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!CreateFileA] [7fef191a2d8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!RegCreateKeyExA] [7fef191b3dc] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!RegSetValueExA] [7fef191ba0c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\wkscli.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!_lcreat] [7fef191a9a0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!_lopen] [7fef191a924] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!_lwrite] [7fef191aa1c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!DeleteFileA] [7fef191a580] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\VERSION.DLL[KERNEL32.dll!MoveFileW] [7fef191a6e0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ncrypt.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ncrypt.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ncrypt.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\bcrypt.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!CopyFileW] [7fef191a184] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!CreateFileA] [7fef191a2d8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!RegDeleteValueW] [7fef191bbc8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!RegCreateKeyExW] [7fef191b4f4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!MoveFileW] [7fef191a6e0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!SetFileAttributesW] [7fef191abe0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\DEVRTL.dll[KERNEL32.dll!MoveFileW] [7fef191a6e0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\DEVRTL.dll[KERNEL32.dll!MoveFileExW] [7fef191a804] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ntmarta.dll[ADVAPI32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ntmarta.dll[ADVAPI32.dll!RegCreateKeyExW] [7fef191b4f4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ntmarta.dll[ADVAPI32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ntmarta.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\ntmarta.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\WLDAP32.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\System32\perfproc.dll[ADVAPI32.dll!RegOpenKeyExW] [7fef191b6d0] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!RegDeleteValueA] [7fef191bb44] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!RegSetValueExA] [7fef191ba0c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!GetProcAddress] [7fefc974230] C:\Windows\system32\apphelp.dll
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!DeleteFileW] [7fef191a5e4] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!CreateFileW] [7fef191a42c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!RegOpenKeyExA] [7fef191b60c] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!RegDeleteValueW] [7fef191bbc8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- IAT C:\Windows\system32\msiexec.exe[5888] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!RegSetValueExW] [7fef191baa8] C:\Windows\AppPatch\AppPatch64\AcGenral.DLL
- ---- Threads - GMER 2.1 ----
- Thread C:\Windows\system32\svchost.exe [448:5404] 000007fef46ad3c8
- Thread C:\Windows\system32\svchost.exe [448:4996] 000007fef46ad3c8
- Thread C:\Windows\system32\svchost.exe [448:2632] 000007fef46ad3c8
- Thread C:\Windows\system32\svchost.exe [448:1804] 000007fef46ad3c8
- Thread C:\Windows\system32\svchost.exe [1776:720] 000007fef5d035c0
- Thread C:\Windows\system32\svchost.exe [1776:2132] 000007fef5d05600
- Thread C:\Windows\system32\svchost.exe [1776:4676] 000007fef3ff2888
- Thread C:\Windows\system32\svchost.exe [1776:4716] 000007fef4152940
- Thread C:\Windows\system32\svchost.exe [1776:2124] 000007fef3ff2a40
- Thread C:\Windows\System32\svchost.exe [2672:3164] 000007fef5d83410
- Thread C:\Windows\System32\svchost.exe [2672:3248] 000007fef5d62e30
- Thread C:\Windows\System32\svchost.exe [2672:3256] 000007fef5d35050
- Thread C:\Windows\System32\svchost.exe [2672:3260] 000007fef5d5ed70
- Thread C:\Windows\System32\svchost.exe [2672:3264] 000007fef5d35040
- Thread C:\Windows\System32\svchost.exe [2672:3268] 000007fef5dd4290
- ---- Registry - GMER 2.1 ----
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd607e35a
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd607e35a@c488e5a613b7 0xF5 0x7B 0x57 0xF1 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd607e35a@4cedde03a70e 0xA5 0x36 0xDD 0x31 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\1c4bd607e35a@14f42a04b1be 0xB3 0xF4 0x5E 0xF4 ...
- Reg HKLM\SYSTEM\CurrentControlSet\services\rdyboost\Parameters@LastBootPlanUserTime ?Mon?, ?Aug ?31 ?15, 06:50:12 PM???????????????????????????????
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd607e35a (not active ControlSet)
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd607e35a@c488e5a613b7 0xF5 0x7B 0x57 0xF1 ...
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd607e35a@4cedde03a70e 0xA5 0x36 0xDD 0x31 ...
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\1c4bd607e35a@14f42a04b1be 0xB3 0xF4 0x5E 0xF4 ...
- ---- EOF - GMER 2.1 ----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement