GMER 1.0.14.14205 -
http://www.gmer.net
Rootkit scan 2008-05-10 12:15:11
Windows 6.0.6000
---- System -
GMER 1.0.14 ----
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (
ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x8D23213A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (
ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x8D23C5C6]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (
ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x8D23274C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (
ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x8D23D29E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (
ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x8D23CEE2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (
avast! self protection module/ALWIL Software) ZwDuplicateObject [0x8D78C8AA]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x8D23D5D0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x8D2325E4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0x8D78C7C8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0x8D78C83C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x8D23D878]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x8D23DB2A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x8D232898]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x8D23CA6E]
---- Kernel code sections -
GMER 1.0.14 ----
? System32\Drivers\spau.sys Määritettyä tiedostoa ei löydy. !
.text USBPORT.SYS!DllUnload 8C259FEB 5 Bytes JMP 83AA03C0
.text a71ow4rn.SYS 8D172000 22 Bytes [ 8E, 71, 7A, 82, 78, 70, 7A, ... ]
.text a71ow4rn.SYS 8D172017 74 Bytes [ 00, 99, 07, 44, 80, A4, 05, ... ]
.text a71ow4rn.SYS 8D172062 84 Bytes [ 48, 82, 40, 68, 45, 82, 8C, ... ]
.text a71ow4rn.SYS 8D1720B7 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text a71ow4rn.SYS 8D1720CE 80 Bytes [ 00, 00, 27, 00, 00, 00, E0, ... ]
.text ...
---- User code sections -
GMER 1.0.14 ----
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] USER32.dll!DefWindowProcA 75CB05CF 5 Bytes JMP 630016CD C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] USER32.dll!GetSysColorBrush 75CB217F 5 Bytes JMP 6305A5E8 C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] USER32.dll!GetSysColor 75CBABF8 5 Bytes JMP 6305B449 C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] USER32.dll!DefWindowProcW 75CC1D90 5 Bytes JMP 630016FC C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
---- Kernel IAT/EAT -
GMER 1.0.14 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [86B026D2] \SystemRoot\System32\Drivers\spau.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [86B02040] \SystemRoot\System32\Drivers\spau.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [86B027FC] \SystemRoot\System32\Drivers\spau.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [86B020BE] \SystemRoot\System32\Drivers\spau.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [86B0213C] \SystemRoot\System32\Drivers\spau.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [86B12048] \SystemRoot\System32\Drivers\spau.sys
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortNotification] F73BFF33
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortWritePortUchar] B85F0B75
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortWritePortUlong] FFFFFFFE
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 08C25D5E
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 5D8B5300
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortGetScatterGatherList] 74DF3B0C
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortReadPortUchar] 01FB8311
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortStallExecution] 5F5B0C74
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortGetParentBusType] FFFFFEB8
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortRequestCallback] C25D5EFF
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 7E390008
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortGetUnCachedExtension] C7077524
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortCompleteRequest] 01642446
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 7E398D18
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] C7077528
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortMoveMemory] 01902846
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortReadPortUshort] 468B8D18
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 244E8B2C
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 7468016A
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortInitialize] 500000FA
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortGetDeviceBase] C73BD1FF
IAT \SystemRoot\System32\Drivers\a71ow4rn.SYS[ataport.SYS!AtaPortDeviceStateChange] 5F5B0C75
---- User IAT/EAT -
GMER 1.0.14 ----
IAT C:\Windows\system32\services.exe[596] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00070002
IAT C:\Windows\system32\services.exe[596] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 00070000
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (
WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [GDI32.dll!DeleteObject] [6305A5B5] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSysColor] [6305A531] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!CallWindowProcW] [6305648D] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!DefWindowProcW] [61001890] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!GetWindowLongW] [610015E0] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!SetWindowLongW] [61001570] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!GetWindowRect] [6301D39F] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\ole32.dll [USER32.dll!MoveWindow] [6301CF7F] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!DeleteObject] [6305A5B5] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [61001570] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [6305A531] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [61001890] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [61001850] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetWindowLongA] [610015B0] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [61001530] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [GDI32.dll!DeleteObject] [6305A5B5] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!TrackPopupMenuEx] [63027DA4] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!SetWindowLongA] [61001530] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!GetWindowLongA] [610015B0] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!CallWindowProcW] [6305648D] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!DeferWindowPos] [610014A0] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!TrackPopupMenu] [63027D7C] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!GetWindowPlacement] [6301CD6C] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!DrawFrameControl] [6301D920] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!GetSysColorBrush] [6305A5E8] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!MoveWindow] [6301CF7F] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!SetWindowPos] [6301D18A] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!GetSysColor] [6305A531] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!FillRect] [63027A71] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!GetWindowRect] [6301D39F] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!DefWindowProcW] [61001890] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!GetWindowLongW] [610015E0] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!SetWindowLongW] [61001570] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\shell32.dll [USER32.dll!SetScrollInfo] [61001750] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [USER32.dll!DefWindowProcA] [61001850] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [USER32.dll!SetWindowLongA] [61001530] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [USER32.dll!GetWindowLongA] [610015B0] C:\Windows\system32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [USER32.dll!SetWindowPos] [6301D18A] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\WININET.dll [USER32.dll!GetWindowRect] [6301D39F] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!CreateThread] [63027D31] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [63027C10] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [63027C64] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\Ideazon\ZEngine\Zboard.exe[2080] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [63027DC9] C:\Windows\system32\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7414FE0C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7411C53D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7410A31F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [7410CBEF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74108AAA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7411DAB8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74107D8D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74107CF4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74106A4E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7419BE7C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74128A5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [741090CD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74112248] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74112273] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74117724] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74117546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2996] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [7414861D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices -
GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 84C521F8
Device \Driver\netbt \Device\NetBT_Tcpip_{E908E245-0BE5-4896-9D28-3A80FEBAF386} 85F051F8
Device \Driver\volmgr \Device\VolMgrControl 84C4F1F8
Device \Driver\usbuhci \Device\USBPDO-0 85B7B1F8
Device \Driver\usbuhci \Device\USBPDO-1 85B7B1F8
Device \Driver\usbuhci \Device\USBPDO-2 85B7B1F8
Device \Driver\PCI_PNP3716 \Device\00000053 spau.sys
Device \Driver\usbuhci \Device\USBPDO-3 85B7B1F8
Device \Driver\usbehci \Device\USBPDO-4 85B93500
AttachedDevice \Driver\tdx \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
Device \Driver\volmgr \Device\HarddiskVolume1 84C4F1F8
Device \Driver\volmgr \Device\HarddiskVolume2 84C4F1F8
Device \Driver\volmgr \Device\HarddiskVolume3 84C4F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84C511F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 84C511F8
Device \Driver\atapi \Device\Ide\IdePort0 84C511F8
Device \Driver\atapi \Device\Ide\IdePort1 84C511F8
Device \Driver\atapi \Device\Ide\IdePort2 84C511F8
Device \Driver\atapi \Device\Ide\IdePort3 84C511F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 84C511F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-5 84C511F8
Device \Driver\volmgr \Device\HarddiskVolume4 84C4F1F8
Device \Driver\USBSTOR \Device\00000067 85FE1500
Device \Driver\volmgr \Device\HarddiskVolume5 84C4F1F8
Device \Driver\USBSTOR \Device\00000068 85FE1500
Device \Driver\volmgr \Device\HarddiskVolume6 84C4F1F8
Device \Driver\USBSTOR \Device\00000069 85FE1500
Device \Driver\netbt \Device\NetBt_Wins_Export 85F051F8
Device \Driver\Smb \Device\NetbiosSmb 85F8B1F8
Device \Driver\iScsiPrt \Device\RaidPort0 85BDE1F8
Device \Driver\USBSTOR \Device\0000006a 85FE1500
Device \Driver\USBSTOR \Device\0000006b 85FE1500
Device \Driver\usbuhci \Device\USBFDO-0 85B7B1F8
Device \Driver\usbuhci \Device\USBFDO-1 85B7B1F8
Device \Driver\usbuhci \Device\USBFDO-2 85B7B1F8
Device \Driver\usbuhci \Device\USBFDO-3 85B7B1F8
Device \Driver\sptd \Device\2139277466 spau.sys
Device \Driver\usbehci \Device\USBFDO-4 85B93500
Device \Driver\a71ow4rn \Device\Scsi\a71ow4rn1 85D1C1F8
Device \Driver\a71ow4rn \Device\Scsi\a71ow4rn1Port5Path0Target0Lun0 85D1C1F8
Device \FileSystem\cdfs \Cdfs A13461F8
---- Registry -
GMER 1.0.14 ----
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x57 0xEC 0x95 0x7C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xD2 0xA0 0x8C 0x88 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x36 0xB3 0x52 0x20 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x26 0xDF 0xE3 0x78 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6D 0x7E 0x3B 0x6B ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x60 0x93 0xE4 0x58 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC1 0xEB 0xFA 0x1D ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x26 0xDF 0xE3 0x78 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6D 0x7E 0x3B 0x6B ...
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x60 0x93 0xE4 0x58 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x57 0xEC 0x95 0x7C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xD2 0xA0 0x8C 0x88 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x36 0xB3 0x52 0x20 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x26 0xDF 0xE3 0x78 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6D 0x7E 0x3B 0x6B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x60 0x93 0xE4 0x58 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ëcÓw
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ëcÓw@b049C053C7D38EE4AB9A00CB3B5D2472 C?\Program Files\Common Files\Microsoft Shared\Web Folders\PUBPLACE.HTT
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EE52C87977754e64988837C292C7DBDB\Usage@statusexe 950681861
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@CacheSizeInMB 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@CacheStatus 2
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@USBVersion 131072
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@ReadSpeedKBs 757
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@WriteSpeedKBs 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@PhysicalDeviceSizeMB 238472
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@RecommendedCacheSizeMB 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@HasSlowRegions 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@DoRetestDevice 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@DeviceStatus 4
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\kYÌ@LastTestedTime 0xEE 0xE4 0x35 0x17 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@IconServiceLib IconCodecService.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DdeSendTimeout 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DesktopHeapLogging 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@ShutdownWarningDialogTimeout -1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERPostMessageLimit 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@ mnmsrvc
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
---- EOF - GMER 1.0.14 ----