- GMER 1.0.15.15281 - http://www.gmer.net
- Rootkit scan 2010-03-22 10:39:24
- Windows 6.1.7600
- Running: gmer.exe; Driver: C:\Users\pezo\AppData\Local\Temp\kxldapog.sys
- ---- System - GMER 1.0.15 ----
- INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83032AF8
- INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83032104
- INT 0x61 ? 9042F558
- INT 0x71 ? 9042F7D8
- INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830323F4
- INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8301A634
- INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8301A898
- INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830321DC
- INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83032958
- INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830326F8
- INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83032F2C
- INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830331A8
- ---- Devices - GMER 1.0.15 ----
- Device \FileSystem\Ntfs \Ntfs 8475D1F8
- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
- AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
- Device \Driver\volmgr \Device\VolMgrControl 847581F8
- Device \Driver\NetBT \Device\NetBT_Tcpip_{94CBBF97-4295-444A-845A-89A7D5AC6009} 8584B1F8
- Device \Driver\usbuhci \Device\USBPDO-0 85A341F8
- Device \Driver\usbuhci \Device\USBPDO-1 85A341F8
- Device \Driver\ACPI_HAL \Device\00000053 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
- Device \Driver\usbehci \Device\USBPDO-2 85A1E500
- Device \Driver\usbuhci \Device\USBPDO-3 85A341F8
- Device \Driver\usbuhci \Device\USBPDO-4 85A341F8
- Device \Driver\usbuhci \Device\USBPDO-5 85A341F8
- Device \Driver\usbehci \Device\USBPDO-6 85A1E500
- Device \Driver\NetBT \Device\NetBT_Tcpip_{DDA78DE3-9A4D-4A5B-9482-45182EB29149} 8584B1F8
- Device \Driver\volmgr \Device\HarddiskVolume1 847581F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
- Device \Driver\volmgr \Device\HarddiskVolume2 847581F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
- Device \Driver\cdrom \Device\CdRom0 8567A1F8
- Device \Driver\volmgr \Device\HarddiskVolume3 847581F8
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
- AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
- Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8475A1F8
- Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-4 8475A1F8
- Device \Driver\atapi \Device\Ide\IdePort0 8475A1F8
- Device \Driver\atapi \Device\Ide\IdePort1 8475A1F8
- Device \Driver\atapi \Device\Ide\IdePort2 8475A1F8
- Device \Driver\atapi \Device\Ide\IdePort3 8475A1F8
- Device \Driver\atapi \Device\Ide\IdePort4 8475A1F8
- Device \Driver\msahci \Device\Ide\PciIde1Channel0 8475B1F8
- Device \Driver\msahci \Device\Ide\PciIde1Channel1 8475B1F8
- Device \Driver\msahci \Device\Ide\PciIde1Channel2 8475B1F8
- Device \Driver\NetBT \Device\NetBt_Wins_Export 8584B1F8
- Device \Driver\usbuhci \Device\USBFDO-0 85A341F8
- Device \Driver\usbuhci \Device\USBFDO-1 85A341F8
- Device \Driver\usbehci \Device\USBFDO-2 85A1E500
- Device \Driver\usbuhci \Device\USBFDO-3 85A341F8
- Device \Driver\usbuhci \Device\USBFDO-4 85A341F8
- Device \Driver\usbuhci \Device\USBFDO-5 85A341F8
- Device \Driver\usbehci \Device\USBFDO-6 85A1E500
- ---- Registry - GMER 1.0.15 ----
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
- Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
- ---- EOF - GMER 1.0.15 ----
