GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2011-11-19 02:36:20 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000AAKS-22V1A0 rev.05.01D05 Running: kgji1m9z.exe; Driver: C:\Users\x\AppData\Local\Temp\fxdoruoc.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKey + 13D1 82E4A349 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E83D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text sptd.sys 88C11001 31 Bytes [17, 22, 83, 34, B2, 22, 83, ...] .text sptd.sys 88C11024 26 Bytes JMP F2C00582 .text sptd.sys 88C1103F 77 Bytes [83, A0, 6A, E4, 82, 77, 28, ...] .text sptd.sys 88C1108D 91 Bytes [85, E4, 82, 15, 35, E4, 82, ...] .text sptd.sys 88C110E9 173 Bytes [5B, E4, 82, D7, E4, EA, 82, ...] .text ... .sptd2 C:\Windows\System32\Drivers\sptd.sys entry point in ".sptd2" section [0x88CBB9E3] ? C:\Windows\System32\Drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces. .text USBPORT.SYS!DllUnload 95387DB9 5 Bytes JMP 85EF0410 .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA4271300, 0x3B6D8, 0xE8000020] .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA42B4300, 0x1BEE, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtCreateFile + 6 773955CE 4 Bytes [28, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtCreateFile + B 773955D3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtMapViewOfSection + 6 77395C2E 1 Byte [28] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtMapViewOfSection + 6 77395C2E 4 Bytes [28, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtMapViewOfSection + B 77395C33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenFile + 6 77395CDE 4 Bytes [68, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenFile + B 77395CE3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenProcess + 6 77395D8E 4 Bytes [A8, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenProcess + B 77395D93 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenProcessToken + 6 77395D9E 4 Bytes CALL 763964A4 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenProcessToken + B 77395DA3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenProcessTokenEx + 6 77395DAE 4 Bytes [A8, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenProcessTokenEx + B 77395DB3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenThread + 6 77395E0E 4 Bytes [68, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenThread + B 77395E13 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenThreadToken + 6 77395E1E 4 Bytes [68, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenThreadToken + B 77395E23 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenThreadTokenEx + 6 77395E2E 4 Bytes CALL 76396535 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtOpenThreadTokenEx + B 77395E33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtQueryAttributesFile + 6 77395F3E 4 Bytes [A8, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtQueryAttributesFile + B 77395F43 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtQueryFullAttributesFile + 6 77395FEE 4 Bytes CALL 763966F3 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtQueryFullAttributesFile + B 77395FF3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtSetInformationFile + 6 7739663E 4 Bytes [28, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtSetInformationFile + B 77396643 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtSetInformationThread + 6 7739669E 4 Bytes [28, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtSetInformationThread + B 773966A3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 1 Byte [68] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 4 Bytes [68, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2068] ntdll.dll!NtUnmapViewOfSection + B 773969C3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtCreateFile + 6 773955CE 4 Bytes [28, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtCreateFile + B 773955D3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtMapViewOfSection + 6 77395C2E 1 Byte [28] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtMapViewOfSection + 6 77395C2E 4 Bytes [28, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtMapViewOfSection + B 77395C33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenFile + 6 77395CDE 4 Bytes [68, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenFile + B 77395CE3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenProcess + 6 77395D8E 4 Bytes [A8, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenProcess + B 77395D93 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenProcessToken + 6 77395D9E 4 Bytes CALL 763964A4 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenProcessToken + B 77395DA3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenProcessTokenEx + 6 77395DAE 4 Bytes [A8, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenProcessTokenEx + B 77395DB3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenThread + 6 77395E0E 4 Bytes [68, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenThread + B 77395E13 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenThreadToken + 6 77395E1E 4 Bytes [68, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenThreadToken + B 77395E23 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenThreadTokenEx + 6 77395E2E 4 Bytes CALL 76396535 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtOpenThreadTokenEx + B 77395E33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtQueryAttributesFile + 6 77395F3E 4 Bytes [A8, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtQueryAttributesFile + B 77395F43 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtQueryFullAttributesFile + 6 77395FEE 4 Bytes CALL 763966F3 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtQueryFullAttributesFile + B 77395FF3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtSetInformationFile + 6 7739663E 4 Bytes [28, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtSetInformationFile + B 77396643 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtSetInformationThread + 6 7739669E 4 Bytes [28, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtSetInformationThread + B 773966A3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 1 Byte [68] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 4 Bytes [68, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[2684] ntdll.dll!NtUnmapViewOfSection + B 773969C3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtCreateFile + 6 773955CE 4 Bytes [28, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtCreateFile + B 773955D3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtMapViewOfSection + 6 77395C2E 1 Byte [28] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtMapViewOfSection + 6 77395C2E 4 Bytes [28, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtMapViewOfSection + B 77395C33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenFile + 6 77395CDE 4 Bytes [68, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenFile + B 77395CE3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenProcess + 6 77395D8E 4 Bytes [A8, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenProcess + B 77395D93 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenProcessToken + 6 77395D9E 4 Bytes CALL 763964A4 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenProcessToken + B 77395DA3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenProcessTokenEx + 6 77395DAE 4 Bytes [A8, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenProcessTokenEx + B 77395DB3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenThread + 6 77395E0E 4 Bytes [68, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenThread + B 77395E13 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenThreadToken + 6 77395E1E 4 Bytes [68, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenThreadToken + B 77395E23 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenThreadTokenEx + 6 77395E2E 4 Bytes CALL 76396535 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtOpenThreadTokenEx + B 77395E33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtQueryAttributesFile + 6 77395F3E 4 Bytes [A8, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtQueryAttributesFile + B 77395F43 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtQueryFullAttributesFile + 6 77395FEE 4 Bytes CALL 763966F3 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtQueryFullAttributesFile + B 77395FF3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtSetInformationFile + 6 7739663E 4 Bytes [28, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtSetInformationFile + B 77396643 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtSetInformationThread + 6 7739669E 4 Bytes [28, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtSetInformationThread + B 773966A3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 1 Byte [68] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 4 Bytes [68, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3768] ntdll.dll!NtUnmapViewOfSection + B 773969C3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + 6 773955CE 4 Bytes [28, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + B 773955D3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6 77395C2E 1 Byte [28] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6 77395C2E 4 Bytes [28, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + B 77395C33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + 6 77395CDE 4 Bytes [68, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + B 77395CE3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + 6 77395D8E 4 Bytes [A8, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + B 77395D93 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + 6 77395D9E 4 Bytes CALL 763964A4 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + B 77395DA3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + 6 77395DAE 4 Bytes [A8, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + B 77395DB3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + 6 77395E0E 4 Bytes [68, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + B 77395E13 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + 6 77395E1E 4 Bytes [68, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + B 77395E23 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + 6 77395E2E 4 Bytes CALL 76396535 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + B 77395E33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + 6 77395F3E 4 Bytes [A8, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + B 77395F43 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + 6 77395FEE 4 Bytes CALL 763966F3 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + B 77395FF3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + 6 7739663E 4 Bytes [28, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + B 77396643 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + 6 7739669E 4 Bytes [28, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + B 773966A3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 1 Byte [68] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 4 Bytes [68, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + B 773969C3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtCreateFile + 6 773955CE 4 Bytes [28, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtCreateFile + B 773955D3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtMapViewOfSection + 6 77395C2E 1 Byte [28] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtMapViewOfSection + 6 77395C2E 4 Bytes [28, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtMapViewOfSection + B 77395C33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenFile + 6 77395CDE 4 Bytes [68, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenFile + B 77395CE3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenProcess + 6 77395D8E 4 Bytes [A8, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenProcess + B 77395D93 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenProcessToken + 6 77395D9E 4 Bytes CALL 763964A4 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenProcessToken + B 77395DA3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenProcessTokenEx + 6 77395DAE 4 Bytes [A8, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenProcessTokenEx + B 77395DB3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenThread + 6 77395E0E 4 Bytes [68, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenThread + B 77395E13 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenThreadToken + 6 77395E1E 4 Bytes [68, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenThreadToken + B 77395E23 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenThreadTokenEx + 6 77395E2E 4 Bytes CALL 76396535 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtOpenThreadTokenEx + B 77395E33 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtQueryAttributesFile + 6 77395F3E 4 Bytes [A8, 00, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtQueryAttributesFile + B 77395F43 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtQueryFullAttributesFile + 6 77395FEE 4 Bytes CALL 763966F3 .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtQueryFullAttributesFile + B 77395FF3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtSetInformationFile + 6 7739663E 4 Bytes [28, 01, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtSetInformationFile + B 77396643 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtSetInformationThread + 6 7739669E 4 Bytes [28, 02, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtSetInformationThread + B 773966A3 1 Byte [E2] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 1 Byte [68] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtUnmapViewOfSection + 6 773969BE 4 Bytes [68, 03, 07, 00] .text C:\Users\x\AppData\Local\Google\Chrome\Application\chrome.exe[4032] ntdll.dll!NtUnmapViewOfSection + B 773969C3 1 Byte [E2] ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88C1270C] \SystemRoot\System32\Drivers\sptd.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88C12EEE] \SystemRoot\System32\Drivers\sptd.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong] [88C1320E] \SystemRoot\System32\Drivers\sptd.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88C130CC] \SystemRoot\System32\Drivers\sptd.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88C128F0] \SystemRoot\System32\Drivers\sptd.sys ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [715D2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [715B5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [715B56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [715D24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [715C8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [715C4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [715C506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [715C5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [715C6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [715C826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [715C87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [715C901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [715CE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1948] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [715C4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 84C651E8 Device \FileSystem\fastfat \FatCdrom 87303430 Device \Driver\usbohci \Device\USBPDO-0 85FBA430 Device \Driver\usbohci \Device\USBPDO-1 85FBA430 Device \Driver\usbehci \Device\USBPDO-2 85E36430 Device \Driver\usbohci \Device\USBPDO-3 85FBA430 Device \Driver\NetBT \Device\NetBT_Tcpip_{833A79E9-FD03-4E84-B84D-A78866F6272C} 85E0D1E8 Device \Driver\usbohci \Device\USBPDO-4 85FBA430 Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) Device \Driver\usbehci \Device\USBPDO-5 85E36430 Device \Driver\usbohci \Device\USBPDO-6 85FBA430 AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) Device \Driver\NetBT \Device\NetBT_Tcpip_{99F25937-20F4-4A25-B8F7-7FB51A28381D} 85E0D1E8 Device \Driver\cdrom \Device\CdRom0 85DF41E8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84C631E8 Device \Driver\atapi \Device\Ide\IdePort0 84C631E8 Device \Driver\atapi \Device\Ide\IdePort1 84C631E8 Device \Driver\atapi \Device\Ide\IdePort2 84C631E8 Device \Driver\atapi \Device\Ide\IdePort3 84C631E8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 84C631E8 AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) Device \Driver\NetBT \Device\NetBt_Wins_Export 85E0D1E8 Device \Driver\USBSTOR \Device\00000077 85EE2430 Device \Driver\USBSTOR \Device\00000078 85EE2430 Device \Driver\USBSTOR \Device\00000079 85EE2430 Device \Driver\usbohci \Device\USBFDO-0 85FBA430 Device \Driver\USBSTOR \Device\0000007a 85EE2430 Device \Driver\usbohci \Device\USBFDO-1 85FBA430 Device \Driver\USBSTOR \Device\0000007b 85EE2430 Device \Driver\usbehci \Device\USBFDO-2 85E36430 Device \Driver\usbohci \Device\USBFDO-3 85FBA430 Device \Driver\usbohci \Device\USBFDO-4 85FBA430 Device \Driver\usbehci \Device\USBFDO-5 85E36430 Device \Driver\usbohci \Device\USBFDO-6 85FBA430 Device \FileSystem\fastfat \Fat 87303430 AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Menedżer filtrów systemu plików firmy Microsoft/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 2 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0x17 0x35 0xE8 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9E 0x46 0xE8 0x04 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x91 0x17 0x35 0xE8 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9E 0x46 0xE8 0x04 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x36 0x4A 0xC3 0x9A ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x06 0xFD 0xD9 0x85 ... ---- EOF - GMER 1.0.15 ----