GMER.txt
Sorry for the delay, lots of files to scan and it did crash once.
GMER 1.0.15.14966 -
http://www.gmer.net
Rootkit scan 2009-04-28 12:51:59
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.15 ----
.text tcpip.sys!IPTransmit + 10FC A80FDD3A 6 Bytes CALL BA583FB0 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text tcpip.sys!IPTransmit + 2850 A80FF48E 6 Bytes CALL BA583FB0 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text tcpip.sys!ARPRcv + 5029 A81044DC 6 Bytes CALL BA583FB0 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
.text wanarp.sys B7C483FD 7 Bytes CALL BA584100 Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[216] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\svchost.exe[216] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\svchost.exe[216] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\svchost.exe[216] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\svchost.exe[216] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\svchost.exe[216] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[224] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[224] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[224] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[224] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[224] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Symantec AntiVirus\Rtvscan.exe[224] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\SearchIndexer.exe[428] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\SearchIndexer.exe[428] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\SearchIndexer.exe[428] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\SearchIndexer.exe[428] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\SearchIndexer.exe[428] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\SearchIndexer.exe[428] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\SearchIndexer.exe[428] kernel32.dll!WriteFile 7C810D87 7 Bytes JMP 00C41B19 C:\WINDOWS\system32\mssrch.dll (mssrch.lib/Microsoft Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[552] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[552] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[552] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[552] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[552] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[552] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\System32\alg.exe[684] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\System32\alg.exe[684] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\System32\alg.exe[684] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\System32\alg.exe[684] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\System32\alg.exe[684] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\System32\alg.exe[684] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\services.exe[772] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF94751
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF947E0
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF947ED
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94A67
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF947D6
.text C:\WINDOWS\system32\lsass.exe[784] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF9482E
.text C:\WINDOWS\system32\Ati2evxx.exe[932] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\Ati2evxx.exe[932] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\Ati2evxx.exe[932] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\Ati2evxx.exe[932] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\Ati2evxx.exe[932] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\Ati2evxx.exe[932] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\svchost.exe[956] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\svchost.exe[956] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\svchost.exe[956] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\svchost.exe[956] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\svchost.exe[956] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\svchost.exe[956] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\svchost.exe[1288] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\svchost.exe[1288] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\svchost.exe[1288] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\svchost.exe[1288] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\svchost.exe[1288] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\svchost.exe[1288] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1444] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1444] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1444] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1444] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1444] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe[1444] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1548] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1548] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1548] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1548] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1548] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1548] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\spoolsv.exe[1636] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\spoolsv.exe[1636] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\spoolsv.exe[1636] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\spoolsv.exe[1636] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\spoolsv.exe[1636] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\spoolsv.exe[1636] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1744] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1744] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1744] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1744] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1744] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Symantec AntiVirus\DefWatch.exe[1744] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[1764] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[1764] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[1764] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[1764] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[1764] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe[1764] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Java\jre6\bin\jqs.exe[1788] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Java\jre6\bin\jqs.exe[1788] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Java\jre6\bin\jqs.exe[1788] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Java\jre6\bin\jqs.exe[1788] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Java\jre6\bin\jqs.exe[1788] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Java\jre6\bin\jqs.exe[1788] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\LogMeIn\x86\RaMaint.exe[1828] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\LogMeIn\x86\RaMaint.exe[1828] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\LogMeIn\x86\RaMaint.exe[1828] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\LogMeIn\x86\RaMaint.exe[1828] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\LogMeIn\x86\RaMaint.exe[1828] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\LogMeIn\x86\RaMaint.exe[1828] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1876] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1876] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1876] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1876] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1876] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1876] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\LogMeIn\x86\LMIGuardian.exe[1908] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\LogMeIn\x86\LMIGuardian.exe[1908] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\LogMeIn\x86\LMIGuardian.exe[1908] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\LogMeIn\x86\LMIGuardian.exe[1908] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\LogMeIn\x86\LMIGuardian.exe[1908] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\LogMeIn\x86\LMIGuardian.exe[1908] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\mnmsrvc.exe[1920] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\mnmsrvc.exe[1920] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\mnmsrvc.exe[1920] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\mnmsrvc.exe[1920] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\mnmsrvc.exe[1920] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\mnmsrvc.exe[1920] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Sygate\SPF\smc.exe[1952] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Sygate\SPF\smc.exe[1952] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Sygate\SPF\smc.exe[1952] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Sygate\SPF\smc.exe[1952] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Sygate\SPF\smc.exe[1952] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Sygate\SPF\smc.exe[1952] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\rundll32.exe[1964] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\rundll32.exe[1964] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\rundll32.exe[1964] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\rundll32.exe[1964] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\rundll32.exe[1964] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\rundll32.exe[1964] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text c:\gmer\gmer.exe[2060] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text c:\gmer\gmer.exe[2060] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text c:\gmer\gmer.exe[2060] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text c:\gmer\gmer.exe[2060] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text c:\gmer\gmer.exe[2060] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text c:\gmer\gmer.exe[2060] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\Ati2evxx.exe[2896] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\Ati2evxx.exe[2896] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\Ati2evxx.exe[2896] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\Ati2evxx.exe[2896] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\Ati2evxx.exe[2896] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\Ati2evxx.exe[2896] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\wscntfy.exe[2984] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\wscntfy.exe[2984] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\wscntfy.exe[2984] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\wscntfy.exe[2984] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\wscntfy.exe[2984] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\wscntfy.exe[2984] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\Explorer.EXE[3048] Explorer.EXE 0101E26B 4 Bytes [FF, 15, 98, 10]
.text C:\WINDOWS\Explorer.EXE[3048] C:\WINDOWS\Explorer.EXE section is writeable [0x01001000, 0x44689, 0xE0000060]
.reloc C:\WINDOWS\Explorer.EXE[3048] C:\WINDOWS\Explorer.EXE section is executable [0x010FB000, 0x8800, 0xE0000040]
.text C:\WINDOWS\Explorer.EXE[3048] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\Explorer.EXE[3048] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\Explorer.EXE[3048] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\Explorer.EXE[3048] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\Explorer.EXE[3048] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\Explorer.EXE[3048] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe[3272] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe[3272] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe[3272] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe[3272] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe[3272] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe[3272] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\Program Files\MMTaskbar\MultiMon.exe[3280] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\Program Files\MMTaskbar\MultiMon.exe[3280] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\Program Files\MMTaskbar\MultiMon.exe[3280] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\Program Files\MMTaskbar\MultiMon.exe[3280] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\Program Files\MMTaskbar\MultiMon.exe[3280] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\Program Files\MMTaskbar\MultiMon.exe[3280] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
.text C:\WINDOWS\system32\HPZipm12.exe[3460] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA4751
.text C:\WINDOWS\system32\HPZipm12.exe[3460] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA47E0
.text C:\WINDOWS\system32\HPZipm12.exe[3460] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA47ED
.text C:\WINDOWS\system32\HPZipm12.exe[3460] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4A67
.text C:\WINDOWS\system32\HPZipm12.exe[3460] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA47D6
.text C:\WINDOWS\system32\HPZipm12.exe[3460] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA482E
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [BA584C90] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [BA584C90] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [BA584C90] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [BA584C90] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [BA584C90] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [BA584A40] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [BA584C90] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [BA584DF0] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [BA584D50] Teefer.sys (Teefer Driver/Sygate Technologies, Inc.)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs Null.SYS
Device \FileSystem\Ntfs \Ntfs 89D42818
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fastfat \FatCdrom 897F0170
AttachedDevice \Driver\Tcpip \Device\Ip wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip Null.SYS
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 Maestro1.sys (KeyMaestro Sys for Windows NT, 2000, .../BTC)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 Maestro1.sys (KeyMaestro Sys for Windows NT, 2000, .../BTC)
AttachedDevice \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Null.SYS
Device \Driver\Cdrom \Device\CdRom0 897341D0
Device \FileSystem\Rdbss \Device\FsWrap 8984EB98
Device \Driver\Cdrom \Device\CdRom1 897341D0
Device \Driver\nvatabus \Device\00000085 89808F00
Device \Driver\nvatabus \Device\00000086 89808F00
Device \Driver\nvatabus \Device\00000087 89808F00
Device \FileSystem\Srv \Device\LanmanServer 8984DFB0
Device \Driver\nvatabus \Device\00000088 89808F00
AttachedDevice \Driver\Tcpip \Device\Udp wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp Null.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp Null.SYS
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8984EDF8
Device \Driver\SYMTDI \Device\SymTDI wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
Device \Driver\SYMTDI \Device\SymTDI Null.SYS
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8984EDF8
Device \Driver\nvatabus \Device\NvAta2 89808F00
Device \FileSystem\Npfs \Device\NamedPipe 899CC0D8
Device \FileSystem\Msfs \Device\Mailslot 8991E0D8
Device \Driver\a347scsi \Device\Scsi\a347scsi1 89716288
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 89716288
Device \FileSystem\Fastfat \Fat 897F0170
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 898B5130
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 898B5130
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 898B5130
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 898B5130
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 898B5130
Device \FileSystem\Cdfs \Cdfs 89868120
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl (size mismatch) 8192/4096 bytes
---- EOF - GMER 1.0.15 ----