GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-09-20 19:17:14 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-5 SAMSUNG_HD080HJ rev.ZH100-41 74,53GB Running: 11ntnd5u.exe; Driver: C:\Users\Maszek\AppData\Local\Temp\ufdiypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076881401 2 bytes JMP 75caeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076881419 2 bytes JMP 75cbb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076881431 2 bytes JMP 75d38609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007688144a 2 bytes CALL 75c91dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768814dd 2 bytes JMP 75d37efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768814f5 2 bytes JMP 75d380d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007688150d 2 bytes JMP 75d37df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076881525 2 bytes JMP 75d381c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007688153d 2 bytes JMP 75caf088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076881555 2 bytes JMP 75cbb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007688156d 2 bytes JMP 75d386c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076881585 2 bytes JMP 75d38222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007688159d 2 bytes JMP 75d37db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768815b5 2 bytes JMP 75caf121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768815cd 2 bytes JMP 75cbb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768816b2 2 bytes JMP 75d38584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768816bd 2 bytes JMP 75d37d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076881401 2 bytes JMP 75caeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076881419 2 bytes JMP 75cbb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076881431 2 bytes JMP 75d38609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007688144a 2 bytes CALL 75c91dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768814dd 2 bytes JMP 75d37efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768814f5 2 bytes JMP 75d380d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007688150d 2 bytes JMP 75d37df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076881525 2 bytes JMP 75d381c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007688153d 2 bytes JMP 75caf088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076881555 2 bytes JMP 75cbb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007688156d 2 bytes JMP 75d386c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076881585 2 bytes JMP 75d38222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007688159d 2 bytes JMP 75d37db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768815b5 2 bytes JMP 75caf121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768815cd 2 bytes JMP 75cbb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768816b2 2 bytes JMP 75d38584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768816bd 2 bytes JMP 75d37d4d C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076881401 2 bytes JMP 75caeb26 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076881419 2 bytes JMP 75cbb513 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076881431 2 bytes JMP 75d38609 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007688144a 2 bytes CALL 75c91dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768814dd 2 bytes JMP 75d37efe C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768814f5 2 bytes JMP 75d380d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007688150d 2 bytes JMP 75d37df4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076881525 2 bytes JMP 75d381c2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007688153d 2 bytes JMP 75caf088 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076881555 2 bytes JMP 75cbb885 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007688156d 2 bytes JMP 75d386c1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076881585 2 bytes JMP 75d38222 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007688159d 2 bytes JMP 75d37db8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768815b5 2 bytes JMP 75caf121 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768815cd 2 bytes JMP 75cbb29f C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768816b2 2 bytes JMP 75d38584 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768816bd 2 bytes JMP 75d37d4d C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82 0000000073a917fa 2 bytes CALL 75c91199 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88 0000000073a91860 2 bytes CALL 75c91199 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98 0000000073a91942 2 bytes JMP 75d8c29f C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109 0000000073a9194d 2 bytes JMP 75d8418d C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076881401 2 bytes JMP 75caeb26 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076881419 2 bytes JMP 75cbb513 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076881431 2 bytes JMP 75d38609 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007688144a 2 bytes CALL 75c91dfa C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768814dd 2 bytes JMP 75d37efe C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768814f5 2 bytes JMP 75d380d8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007688150d 2 bytes JMP 75d37df4 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076881525 2 bytes JMP 75d381c2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007688153d 2 bytes JMP 75caf088 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076881555 2 bytes JMP 75cbb885 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007688156d 2 bytes JMP 75d386c1 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076881585 2 bytes JMP 75d38222 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007688159d 2 bytes JMP 75d37db8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768815b5 2 bytes JMP 75caf121 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768815cd 2 bytes JMP 75cbb29f C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768816b2 2 bytes JMP 75d38584 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[2896] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768816bd 2 bytes JMP 75d37d4d C:\Windows\syswow64\kernel32.dll ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef4a8741c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef4a85f10] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef4a85674] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef4a85e2c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef4a87f48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef4a86a38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef4a86ee8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef4a87b58] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef4a87ea0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef4a878b0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef4a84fb4] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef4a85d38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2560] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef4a87584] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [2412:3144] 000007fef355ac4c Thread C:\Windows\System32\svchost.exe [2412:3280] 000007fef3c29688 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind ????-8??storage\volume?-C9??????????????????????WPD FileSystem Volume Driver????????????????????? ?????????????????????0????????????&????????????????????C???????????????????m??????????????????????????????????????????? ???????????????????s?0????????????????????? ?????????????????????0????????????&????????????????????6??? ?????????????????????0????????????????????????????? ?????????????????????0????????????????????????????? ???????? ????????????0????????????&????????????????????1??? ?????????????????????0?????????????????????????????????????????????C??????????????????????"Tcpip" "{4FB25CA5-3CB1-4A79-93F9-F96C8FDBC6A3}"?"Tcpip" "{F2F45009-5BDC-4F57-B386-D4949C790AA0}"?"Tcpip" "{40850293-7CE0-45A3-BF48-B6E1822E4854}"?"Tcpip" "{33230448-3B1E-4E90-87CF-A6AD54B64026}"?"Tcpip" "{744C42B8-78C9-4165-B699-6BBF26590CFD}"?"Tcpip" "{69B045DD-F48A-4D51-992C-E5EB257483E0}"?"Tcpip" "{A21E84ED-C0FA-497F-A095-C12A0A265E45}"?"Tcpip" "{87A9A03A-1654-41E7-BBB2-08C760FEB806}"?"Tcpip" "{447A10E4-1AEF-4226-9891-A44908696DBE}"?"Tcpip Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route ????????????????????????????te??? ???????@????????????????????$?N???????????????? ???????|?????????????:????????????&????????????????????M??Microsoft 6to4 Adapter??????????????????????????????????????????????????? ???????s???????????????????????????????3??????????6to4mp.ndi??14??? ???????@????????????????????$?N???????????{34679EC1-02DE-4C0D-9438-2DBDF9A61FA4}??????????????????????????? ???????3??????14??????????????????????????????????????????????? ????????????????????????"?????p???????????{4d36e972-e325-11ce-bfc1-08002be10318}??????? ????????????????????????????$?N???????????{4d36e972-e325-11ce-bfc1-08002be10318}\0210?????{D5C63D48-73D8-4ED9-9FD5-23A065D1B4A6}???-??????????? ??????????? ?????????????????????????????????????e????? ?????????????????????0????????????&???????????????????????? ?????????????????????0??????*?6??? ???????????????????nettun.inf:Microsoft.NTamd64:6to4mp.ndi:6.1.7600.16385:*6to4mp??????? ?????????????????????0????????????&????????????????????d??? ?????????????????????0??????????????? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export ?????{??Net??????????y????????????????e??????????y???z??????TD??????11??????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Domain|App=%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe|Name=@FirewallAPI.dll,-31313|Desc=@FirewallAPI.dll,-31316|EmbedCtxt=@FirewallAPI.dll,-31252|??????v2.10|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|Profile=Domain|App=%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe|Name=@FirewallAPI.dll,-31317|Desc=@FirewallAPI.dll,-31320|EmbedCtxt=@FirewallAPI.dll,-31252|?????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|Profile=Public|LPort=2177|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\system32\svchost.exe|Svc=Qwave|Name=@FirewallAPI.dll,-31253|Desc=@FirewallAPI.dll,-31256|EmbedCtxt=@FirewallAPI.dll,-31252|???v2.10|Action=Allow|Active=FALSE|Dir=Out|Protocol=17|Profile=Private|Profile=Public|RPort=2177|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\system32\svchost.exe|Svc=Qwave|Name=@FirewallAPI.dll,-31257|Desc=@FirewallAPI.dll,-31260|EmbedCtxt=@Fire Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????hwdatacard??????????????????????????????????HUAWEI Mobile Connect - 3G Application Interface????????p???????????????????????? ?????????????????????0????????????????????? ?????????????????????0????????b?????????????b?????????????HUAWEI Mobile Connect - 3G Application Interface????@oem3.inf,%qcomdevice00%;HUAWEI Mobile Connect - 3G Application Interface???????????????????? ?????????????????????0????????????&????????????????????????????????????????????????????????????????????e??{fd557e9f-dc04-11e1-b671-806e6f6e6963}??????tunnel??????? ???????????????????????????? ?*???????????? ?????????????????????????????????s????Composite.Dev???? ??????????r?????>??r??????????????%SystemRoot%\System32\umpo.dll???????r??????????????????????? ???????q???????????r???????? ?F?????????????????F??r??????????????%SystemRoot%\System32\netevent.dll???????????????????????????r?r????? ???????q???????????r???????? ?N???????t?????D??r??????????????%SystemRoot%\System32\ntprint.dll????????????????????????r?r?r???r?r?????r????????????????N??r??????????????{747EF6FD-E535-4d16-B510-42C90F6873A1}??????? ???????q???????????r??????????N?????????????????????N??r??????????????{5B33145C-1C66-49F3-B4CA-F563C165F2C0}???????r??????????????????????? ???????q???????????r???????? ???????????r??????????r??????????????%SystemRoot%\System Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind ???????????? 3???????????????4????????????\??????????????????????5???????????u?????????"?????????m???????????????????l??????????????11?745??{36fc9e60-c465-11cf-8056-444553540000}??????{00000000-0000-0000-ffff-ffffffffffff}??????? l?????????????????? l?????????????????????????? ???????m?????m?????m????????????????????????sros??\??\USB#ROOT_HUB#4&eb66714&0#{f18a0e88-c30c-11d0-8815-00a0c906bed8}??4??? ???????m?????????????,???????????????d???????m????? ???????m???????????????????????????????f???m?m?8???m??? ???????m?????m???????0??L????????? ??????????????m???m???m???m?m??? ???????m?????m???????0????????????&???????????????????????? ???????m?????m???????0????????????????????? ???????m???????????m?0?????????????????????????????????????????m??????????usbport.inf:Generic.Section.NTamd64:ROOTHUB.Dev:6.1.7600.16385:usb\root_hub??????m?m???????m????? ???????m?????m???????0?????????????????????m?m????????? ???????m???????????m?0?????????????????????????????????????????m???????????????8?????m????? ???????m?????m??????? Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route ????s?????N???????????D?????11?5C4???|???????????????????????????d??11??D9???????y???????????{????X??????{???t???????????????????{?????????????????????????????????????????????s????????$?????????????m?????????os??%systemroot%\system32\w32time.dll???? H?????????????????gencdrom????????????? ??????????????? ???|????????p??????????????4??????????di??? ???g???&???????&??tunnel??"{??*6to4mp?6E??int?ri???????????????????????????????????????e??6-21-2006????????????????????????|??????t???? ???????{?????????????9?????????????????????????????????a??????am??? ???????{???????????{?9??????(?h????????k??? F??{??????????e???%SystemRoot%\System32\wshtcpip.dll????????????????????????h???????????????????????h???????h??{???0???g??????????????????????????????????????????????????????????????????????????????????? ???????{???????????{?9????????V??????????e??????4??{??????e???CloseTcpIpPerformanceData?????8??{???????t??CollectTcpIpPerformanceData???????F??{???????y??%SystemRoot%\System32\Perfctrs.dll????????2??{??????????OpenTcpIpPe Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export ????????????????????????*6to4mp??????????:???????9????????????????????????N??????d???????????????????B????????????????????????????R??????????????d????:???????????h??????????????????????????????????????t?t?????????t????????????V????????????n????????????????????????????????????????????????????????11??????? ?????????????????????????????? ???????????????Type?????? ???????????c?????Network Address?????? ?????????????????????????????? ????????????? ???????????c??????????????????????t??????????????????int??????????????????e??tunnel????????