Sorry I've just finished scanning with gmer and here're the results
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-09-16 01:54:32
Sorry I've just finished Gmer scan, here it is..
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 WDC_WD3200BEVT-22ZCT0 rev.11.01A11
Running: 74riufr2.exe; Driver: C:\Users\Black666\AppData\Local\Temp\uwroikog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x89988BDC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x8998A538]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x8998A78E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x8998AA08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x8998945C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x89989B3E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x89989F48]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x89989604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x89989E20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x899887E2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x89989CDC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x8998899E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x8998A07A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0x8998BCBC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x899890FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x899891FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x89989D7E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x8998B6AE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x8998C67E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x8998975E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x8998B740]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x8998BD70]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x89989FEA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x899894DE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x89989EB8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x89988DE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x8998BCE6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x8998A11C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x89988D06]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x8998AC4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x8998C088]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x8998B9D6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x8998A4A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x8998A36C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x8998B44E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x8998C560]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x89989878]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x89989318]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x8998ACFE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x8998B83A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x8998C1C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x8998C2AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x8998C3D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x8998B5DA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x89988F5A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x89988EB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x8998BF3E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x8998903A]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 8384D349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83886D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 8388DD8C 4 Bytes [DC, 8B, 98, 89]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 8388DDB4 8 Bytes [38, A5, 98, 89, 8E, A7, 98, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1143 8388DDF8 4 Bytes [08, AA, 98, 89]
.text ntkrnlpa.exe!KeRemoveQueueEx + 116F 8388DE24 4 Bytes [5C, 94, 98, 89]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 8388DE48 4 Bytes [3E, 9B, 98, 89]
.text ...
? System32\Drivers\spxz.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 94FB9DB9 5 Bytes JMP 86E834E0
.text D:\CyberLink\PowerDVD9\PowerDVD9\NavFilter\000.fcl section is writeable [0x98A01000, 0x2892, 0xE8000020]
.vmp2 D:\CyberLink\PowerDVD9\PowerDVD9\NavFilter\000.fcl entry point in ".vmp2" section [0x98A24050]
---- User code sections - GMER 1.0.15 ----
? C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] C:\Windows\SYSTEM32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: KERNELBASE.dll
.text C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] USER32.dll!NotifyWinEvent + 6AE 7699D66C 4 Bytes [E0, 13, 38, 6D]
? C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] C:\Windows\SYSTEM32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: KERNELBASE.dll
.text C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] USER32.dll!NotifyWinEvent + 6AE 7699D66C 4 Bytes [E0, 13, 38, 6D]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [89690042] \SystemRoot\System32\Drivers\spxz.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [896906D6] \SystemRoot\System32\Drivers\spxz.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [89690800] \SystemRoot\System32\Drivers\spxz.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8969013E] \SystemRoot\System32\Drivers\spxz.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] 001F0240
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] 001F02B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] 001F0320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] 001F0390
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] 001F07F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] 001F0860
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] 001F0B00
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] 001F0B70
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] 001F0BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] 001F0C50
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 00670DA0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] 001F0CC0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] 00670E10
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameA] 00670E80
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA] 00670EF0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00670F60
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 76230860
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 762308D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] 76230940
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameW] 762309B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] 001F0D30
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] 001F0DA0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 76230A20
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] 76230A90
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] 76230B00
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 76230B70
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 76230BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 76230C50
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] 77CA0940
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] 77CA09B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] 77CA0A20
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!VirtualFree] 77CA0B00
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleFileNameW] 00680400
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 00680470
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 006804E0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 00680550
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] 006805C0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 00680630
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] 006806A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!HeapFree] 77CA0CC0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] 00680710
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00680780
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] 00200780
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] 00690320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] 00690390
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] 00690400
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] 002007F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!HeapFree] 002008D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameA] 00690470
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameW] 006904E0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] 00690550
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 006905C0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 00690630
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 006906A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] 00690710
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 00690780
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 006907F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] 00200940
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] 002009B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] 00200A20
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00690BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00690C50
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!HeapFree] 77CA02B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!VirtualAlloc] 77CA0320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 762304E0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetModuleFileNameW] 762301D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 76230390
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] 76230320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] 762302B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] 76230240
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] 762300F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!HeapFree] 77CA02B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] 76230400
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 762304E0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 76230390
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] 76230240
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] 762302B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!FreeLibrary] 762300F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetModuleFileNameW] 762301D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetModuleFileNameA] 76230160
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateThread] 77CA01D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryExA] 76230320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] 762300F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] 76230240
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[380] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 762304E0
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [745C2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [745A5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [745A56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [745C24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [745B8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [745B4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [745B506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [745B5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [745B6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [745B826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [745B87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [745B901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [745BE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [745B4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[2856] @ C:\Windows\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [75C3FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] 00180240
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] 001802B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] 00180320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] 00180390
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] 001807F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] 00180860
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] 00180B00
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] 00180B70
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] 00180BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] 00180C50
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 003B0DA0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateThread] 00180CC0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] 003B0E10
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameA] 003B0E80
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA] 003B0EF0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 003B0F60
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 76230860
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 762308D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] 76230940
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameW] 762309B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] 00180D30
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] 00180DA0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 76230A20
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] 76230A90
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] 76230B00
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 76230B70
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 76230BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 76230C50
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] 77CA0940
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] 77CA09B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] 77CA0A20
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!VirtualFree] 77CA0B00
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleFileNameW] 003C0400
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 003C0470
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 003C04E0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 003C0550
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] 003C05C0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 003C0630
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] 003C06A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!HeapFree] 77CA0CC0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] 003C0710
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 003C0780
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] 00190780
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] 003D0320
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] 003D0390
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] 003D0400
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] 001907F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!HeapFree] 001908D0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameA] 003D0470
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameW] 003D04E0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] 003D0550
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 003D05C0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 003D0630
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 003D06A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] 003D0710
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 003D0780
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 003D07F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] 00190940
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] 001909B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] 00190A20
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 003D0BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe[4044] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 003D0C50
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 867551F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FD634057-BDCF-48D6-AD8C-4048E4E57A17} 86BFF348
Device \Driver\volmgr \Device\VolMgrControl 85A7B1F8
Device \Driver\ACPI_HAL \Device\000000eb halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-0 86EE5500
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EE47BBC-1EBD-4A53-BE50-9ABDCEACE4ED} 86BFF348
Device \Driver\usbuhci \Device\USBPDO-1 86EE5500
Device \Driver\NetBT \Device\NetBT_Tcpip_{63CC81C0-8B43-4059-A9D0-8250ED59801A} 86BFF348
Device \Driver\usbehci \Device\USBPDO-2 86E42500
Device \Driver\usbuhci \Device\USBPDO-3 86EE5500
Device \Driver\usbuhci \Device\USBPDO-4 86EE5500
AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\usbuhci \Device\USBPDO-5 86EE5500
Device \Driver\usbehci \Device\USBPDO-6 86E42500
Device \Driver\volmgr \Device\HarddiskVolume1 85A7B1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\volmgr \Device\HarddiskVolume2 85A7B1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom0 86AEF1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85A7D1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-4 85A7D1F8
Device \Driver\atapi \Device\Ide\IdePort0 85A7D1F8
Device \Driver\atapi \Device\Ide\IdePort1 85A7D1F8
Device \Driver\atapi \Device\Ide\IdePort2 85A7D1F8
Device \Driver\atapi \Device\Ide\IdePort3 85A7D1F8
Device \Driver\atapi \Device\Ide\IdePort4 85A7D1F8
Device \Driver\msahci \Device\Ide\PciIde1Channel0 85A7E1F8
Device \Driver\msahci \Device\Ide\PciIde1Channel1 85A7E1F8
Device \Driver\msahci \Device\Ide\PciIde1Channel2 85A7E1F8
Device \Driver\volmgr \Device\HarddiskVolume3 85A7B1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom1 86AEF1F8
Device \Driver\volmgr \Device\HarddiskVolume4 85A7B1F8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\cdrom \Device\CdRom2 86AEF1F8
Device \Driver\cdrom \Device\CdRom3 86AEF1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 86BFF348
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\usbuhci \Device\USBFDO-0 86EE5500
Device \Driver\usbuhci \Device\USBFDO-1 86EE5500
Device \Driver\usbehci \Device\USBFDO-2 86E42500
Device \Driver\usbuhci \Device\USBFDO-3 86EE5500
Device \Driver\usbuhci \Device\USBFDO-4 86EE5500
Device \Driver\usbuhci \Device\USBFDO-5 86EE5500
Device \Driver\usbehci \Device\USBFDO-6 86E42500
Device \FileSystem\cdfs \Cdfs CD54C1F8
---- Processes - GMER 1.0.15 ----
Library C:\ProgramData\Kaspersky (*** hidden *** ) @ C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe [380] 0x07A90000
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001dd9ff22f3
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001dd9ff22f3@001baff08988 0xA7 0x7D 0x82 0xB9 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001dd9ff22f3@c8979fd41aa2 0x36 0x40 0xDC 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001dd9ff22f3@00174b50ab21 0xBB 0x7B 0x2B 0xB8 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001dd9ff22f3@2cd2e77db0ba 0xA2 0x21 0xDA 0xAD ...
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????? ??!???????????????????????6???? ???????????????????u?:????????h?????????????h?????H???@???????@???????H???????????????????????????? h?????????????????????????? ???????????????????u?:????????h???????ev????h?????H???@???????@???????H????????????????????????2????:??????????????????????????????????????????????????????:??? ???????o??????????????????????N????????????????o??????????system32\DRIVERS\rfcomm.sys??????????????????????????????????????????????????????l??????p????????j???1????????????????????????????X??????a???t???????????????4????????????????????????????????????????\???????????????8???????????h???????????????????????X??????{???9??????os??t???????????????????????? ?????????????????????????????????? ???????????? ????????????????????????????"?B????????k??? B?????????????e???%SystemRoot%\System32\wshBth.dll????????2?????????????h???????????????????????h???????8??????????g?????? ????? ????? ????? ?????????????????????? ???????o?????????????,????????<???????????SRS Audio Sandbox (WDM)????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ????????-21??z????^??????????????????????????????????????A??GR???????????????"???????????/?;???5?~?~?~?~?~???????????????????E??53??????????????????? ????????????????????F??????????????????????????????????????6??"{???????????n?????? P??????50???????l???????e??????????????? ?????????????????????-??"?????????????????????????????????????????????????????????????????????????????? ?????????????????????1????????????????????? ???????????????????i?1?????????????????????????????e??2-??????????????????????????? ?????????????????????1??????????????????????????????????????|??????5??????? ???????????????????i?1?????????????????????????????R??T\??????????????????????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????}"??????????????Microsoft????????????????????*??at??v2.10|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|RPort=443|App=SYSTEM|Name=@peerdistsh.dll,-10006|Desc=@peerdistsh.dll,-11006|EmbedCtxt=@peerdistsh.dll,-9003|??????4??????1????h6D7??cdrom.inf??????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????????WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_KINGSTON&PROD_DATATRAVELER_2.0&REV_PMAP#001D0F0CAAC55B940D0B00D6&0#??????\\?\WpdBusEnumRoot#UMB#2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_KINGSTON&PROD_DATATRAVELER_2.0&REV_PMAP#001D0F0CAAC55B940D0B00D6&0##{10497b1b-ba51-44e5-8318-a65c837b6661}???????????????????????????????? ?????????????????????1????????????&???????????????????????????????????????????????{c7c038ad-1f2d-44d4-b2fe-d912be20e6d5}???????????????????????0??f???????????????????????????????????????????????????????????????????????????????%SystemRoot%\system32\wpdshext.dll,-701?? ??? ??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ??????????????????????????????????????? ??????????????????????WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_KINGSTON&PROD_DATATRAVELER_2.0&REV_PMAP#001D0F0CAAC55B940D0B00D6&0#??????????????????? ???????.??????? ?????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ?????D??????????????????????????????HID-compliant mouse?EE??????2#??????so???????????????????h????6?????????????16??????}????????????s??la??? ???y???_??????d8???????????????h??? ?????????????r?????????????????????E??57???????????"????????????????????????????X??????????????????????7??91????<??????????????????????????????????????????????????????????t????????????????????????????N??????d??????????? ??????? ?????593??????????????? ???????|???????????m?:??????????3?&????????????????????"??? ?????????????????????????????????e????? ???s???|?????|5C??????????????????l???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{56FFFC02-DE66-416E-91D8-E74474CF4920}] DATAGRAM 144????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????A4??MSAFD NetBIOS [\Device\NetB
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ?????????????????F???????4??? p?????????????????6-21-2006???? l????????????? 2????N????????????D??????6?????????????????????????volume.inf?g????????????????3.??6.1.7600.16385??????hid_device_system_mouse?5}???????????D???"????X??????s???i??????25????X???????????????X?????????????????????????????? ???????????????7????????????????????????????????????????????????????????????????????????????????*??????????????????????z??????????????????????????vi???????????1??85????????????????????B???????????????????|????????????????????????????????e??????(?????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0222E46A-A707-40D4-B1B7-96459F268249}] DATAGRAM 111??????????????????D??????p???????????????????????????????????2??b8??????????????????????????????????????t_???????????????????????8??????????Port_#0002.Hub_#0007?i??????????????????????????????? l??????i?????nte??? ???????l???????/????r????????g????? `??????????????????????????c???????????????5??en????.??????????????????????????????#???????????l?????????????????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ????????????? ?????????????????????1????????????????????? ???????????????????u?1??????????????????????$??????n???????%??.NTx86?B-E??? ?????????????????????1????????????????????????????????????????? ???????????????????u?1?????????????????????????????N??????ip??????????????????????? ?????????????????????1????????????&???????????????????????? ?????????????????????1????????????????????????????? ???????????????????u?1????????????????????HUAWEI Mobile???????????????????????????? ?????????????????????1????????????????????? ???????????????????u?1????????????????????????????????????????????????????????m???Microsoft???? ?????????????????????1????????????????????Root\*6TO4MP\0038???? ???????????????????u?1????????H???????????? ?????????????????????1????????????&???????????????????????????????????????????? ?????????????????????1????????????????????? ???????????????????u?1????????????????????? ??????????????????????????????"??? ???????"{??????????? ?????????????????????1??????????????????????z??????1??????????WpdFs??????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Bind ????????? ???????????????? ????-??"???&?????????????????USB\VID_12D1&PID_1446&REV_0000?USB\VID_12D1&PID_1446????{5fdad6f3-cf67-11df-9d6f-b6a7413b6fc5}??????????????????????USB\DevClass_00&SubClass_00&Prot_00?USB\DevClass_00&SubClass_00?USB\DevClass_00?USB\COMPOSITE???????? ?????????????????????1??L????????? ?????????????J?????????????????????????????\Device\{63CC81C0-8B43-4059-A9D0-8250ED59801A}?\Device\{8F4D9D4E-7FF0-47B4-9F96-67122FAD0E70}?\Device\{DA66FDD8-0AD3-402C-A3C9-ED3383E05A92}?\Device\{2C4D1543-2B80-4F68-BAEB-FCC959326E88}?\Device\{DF5C1CD0-6517-4873-9679-7D9E3728C1DA}?\Device\{785C512F-EF30-4A49-883F-3906748338B2}?\Device\{E6A5CD5D-E858-4D6A-A4C6-0ABA3CEA6A03}?\Device\{6EE47BBC-1EBD-4A53-BE50-9ABDCEACE4ED}?\Device\{FD634057-BDCF-48D6-AD8C-4048E4E57A17}??CC???????????B???h??? ???????/?????????????,??????(??????????????????$???????n??????????????????NT???????????D??????????????????????????#???????????????????????? ?????????????????????1????????????????????input.inf:Standard.NTx86:HID_Inst:6.1.7601.
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Route ????????? ??????????????????6to4mp.ndi?fs???tunnel??????{80D9E3FF-6F7B-4B76-95FE-223E30E968CE}???}??? ??????????????????????????? ?????????ter????????????????????????$?????????????????ROOT\*6TO4MP\0125???????????????????????????????????????????? ???????????????????????????????t??????????????????????????????? ???????.??????nb??6.1.7600.16385?;Fi???????????-???????A??????????? ??????????????????????????? ??????????????????usbport.inf_x86_neutral_ba59fa32fc6a596d?????`?`?`?`?f?f?b????????????N????????????D????Microsoft???????6.1.7601.17514????????N???????????D??????????????????e????H??????????????????????????????h??????s???????????@%systemroot%\system32\rascfg.dll,-32007????????????????????kb????.????????g????? ??r???????????x???HIDClass?1??hid\vid_1532&pid_0015&mi_01??u??????????????????????????@system32\DRIVERS\BthEnum.sys,#1;Bluetooth Peripheral Device????@system32\DRIVERS\BthEnum.sys,#1;Bluetooth Peripheral Device????@system32\drivers\BthEnum.sys,#1;Bluetooth Peripheral Device????BTHENUM\{00005005-0000-1000
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Export ?????????8?@?@?@?????@??? ???????:?????;??????????V?????????&???????????????????????? ???????;??????????????????????????+??????????????????????0????? ???????:?????;???????1????????????????????? ???????;???????????9?1?????????????????????????????-??E5???????;???3??8C??Microsoft????????;???-???????A??? ???;???0??????????? ???????????????????,????????"???!????????????????????????????????????????????????:?;????,??????????????????????????????5????`?????????????System???6???2?2?2?:????Net??????2?2?2?;?????;???;??????????????@nettcpip.inf,%ms_tcpip.tunnel.displayname%;Internet Protocol (TCP/IP) - Tunnels?????? ??;???f??????????ms_tcpip_tunnel??????;?;?;?;?;?;?;???????;???????????????????????C???????N???;???????;???5?????Pbf??? ???????0??????????? ?????????????????????'???????????? ??????????????????;???????????????;?;?;cp??? ???????0?????;?????;?9?????? ?????&??????????????????????????9???1???1???1???9???/???0???2???2???;???:???;???9???1???1???:???9???1??ptp????????????8?ms_l2tp??????????TCPIP6TUNNEL?n??? ???????9?
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Export ????en??? ???????/?????????????-??????????7???????????6DCF???????????4??????57????<??????R????h?????? ?????????????????????,????????z?????????????4Local Area Connection* 147???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6Microsoft 6to4 Adapter #131???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Export ??????????????X??????????t??????os??Net??z???????????????????????????????|????X???????????????6?????????????????ta????????????????????????????X??????a????????????????????????N??????{?????|?|??s?????????????????????`???????????????????????????????.?????????????????????????????????????????????????????????????????????????? ???????s????????????????|??????????????s????????????????????m??????????z???o??s???????????????????????????????????????11???????????????????????????t??? ???????o?????????????,????????l???????????????????????????????????????????t?????????????????????????l???????????h?????%SystemRoot%\system32\svchost.exe -k HsfXAudioService?????"????????????e????HsfXAudioService????? 4?????????????????NT AUTHORITY\LocalService?????????????????????L????????????n????User-mode gate for Modem Speakerphone???? ??????????????????????????????B??? ???????????? B?????????????????C:\Windows\system32\XAudio32.dll???????????????????n????ServiceMain?????? ??????????????????????????????????????????????????????????? ???????o?
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1D 0x3C 0xB1 0x01 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE3 0x30 0x64 0xA7 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xC5 0x9F 0xD0 0xB7 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001dd9ff22f3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001dd9ff22f3@001baff08988 0xA7 0x7D 0x82 0xB9 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001dd9ff22f3@c8979fd41aa2 0x36 0x40 0xDC 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001dd9ff22f3@00174b50ab21 0xBB 0x7B 0x2B 0xB8 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001dd9ff22f3@2cd2e77db0ba 0xA2 0x21 0xDA 0xAD ...
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???p?p??????????????1???tcpipreg????????????Fs_Rec?4?4???????i????X??????&???&???i?i??????X?????????????*6to4mp??A??VgaSave?????????????????? ???????i?????i???????-??(???????????????????sr??????????????????t??????i?i????? ???????i?????i???????-??4??????????????????????????i?i????? ???????i???????????h?-?????????????????????y?????????????????????????i???????? ????o???????????8?????i?????i??????????????? ???????j?????i???????1?????????????????????????????I??el???i??? ???????i???????????i?1?????????????????????????????????????????i???5??????IDE Channel??????i?i???????i????? ???????j?????i???????1????????????????????? ???????i???????????i?1?????????????????????????????5???????????i???5??????mshdc.inf????i?i???????i????? ???????j?????i???????1?????????????????????????????/???/????B??i??????? ??? ???????i???????????i?1?????????????????????????i???5??????atapi_Inst?\ve???i?i? ?????i????? ???????j?????i???????1????????????????????? ???????i???????????i?1????????*?????????????????????????????*??i???8??01??internal_id
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???l?s??? ???????s????????????????????r?p??? ??????????????????????4?????????? ?????????????????Extended Base?????l??s??? ?????????????????????????X???(??????P????????????(??????P???????????????l??s???0?????????????????????????X???(??????P????????????(??????P??????????????????????????????s????l?????????????????/-???????????f??t????s???????s???0??e2??????????????t???Net???????0??s???????????????????????????????????????????'0??s???,???????????????????/???????????????????????????u???s???????s???????????????????????????????????;???10??s????????????????????????????/us.???????????????????????????????30??s?????????????????????????????/?????s?????s???s???????s?????????????????????????????????????s????????H??s???:?????????????????????4?????????? ???????????????????H??s???a???????/???s?s?s?s?s???????s??????????? ???????s???????????s??????????????????????????????0????????????????p???????????????????? ?????????????????????????????????????????????????? ???????o??????????????????????b???????????????????????????????@%Syste
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???t?s???????????????t?????????????????????????x?????????? ??????????? ??????????? ??????????????????????????????????????????t????????????e??????????????????????????? ??????????? ??????????? ??????????? ???????????????????????????????????????x??t???:???????????:???????t?????????????????????????????x?????????? ??????????? ??????????? ??????????????????????????????????????????t???????????????t????x????????d?????????? ??????????? ??????????? ??????????????????????????????????????:???????????????:????`?l??????L?????????? ??????????? ?????????????????????????????????????????????????????????????????????????????????????? ???????t???????????s???????????????????e??@%SystemRoot%\system32\drivers\netbt.sys,-2???????R??????????????d??????????*6to4mp?????DiskDrive????????????????????????????`??????????????COM14???????????PlugPlay????@%systemroot%\system32\drivers\mup.sys,-101?????@%SystemRoot%\system32\drivers\ndis.sys,-200????System32\DRIVERS\netbt.sys??????Tdx?tcpip?????????P??t?????????e????????????????????????????6??
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???p????????????????????????????????t????????????????????p?s????mshdc.inf_x86_neutral_f64b9c35a3a5be81??????????????????????????????????????????\SystemRoot\system32\drivers\kbdclass.sys????|?|??????,??o?????????e????\SystemRoot\system32\drivers\kbdhid.sys?????????47??Keyboard Class Driver?????P??o????????h??????t??????Keyboard Class????????T??????????????d??? ???p??????????$????????o??????p???????????system32\DRIVERS\intelppm.sys?ntelppm.sys????????p??????p????????????????????????????????~???????????5???????????s??????????????????????????????????????????????????ta????N??????6????D}????tunnel???????????p??????????PNP_TDI??????????????????????????????????????????p??????????Microsoft?????????????Z??p?????????e?????????o??????????????????????????System32\Drivers\dfsc.sys?????4??p???????????????????????u???|???????????????????????????????|??????????????Auto?????o?p?o?p?p?p?p??????????????????????????????t???RPCSS??.?.???p????????????????4??o????????h???????0??p?????????e??????b??p?????????e?????????p???+???+?????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ????|???????????????????tunnel??????text????????????????????????????????????????????????????????????????3?????????????X?????? ?????????????????????????????????????????????????????????????6????????????????????????0????????????????????????????"???????????????????????????????0???@?????????????????????????????????????????????????????6?????????????????????????6???????????????????????????6??? ?????????????????????????????????????????????????6????????????????????????????6????!????????????????????????6??????(???????????????????????????????!????????????????????????6??????%??????????????????????????0????????????????????????????????????????????????????????$???????????????????????????????.???????????????????????????????????$???????????????????????????????.??????????????????????????????????? ???????????????????????????&??????????????????????????????? ?????????????????????????????????????????????????6?????!????????????????????????6????????????????????????????????????????????????????????????????????????????????6?????%?????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???s????????????SASDIFSV????? ???????????????????????????????? ?&???????????????????????? ??????????????????????????????????&???????????????????????? ??????????????????????????????????&???????????????????????? ??????????????????????????????????&???????????????????????? ??????????????????? ??????????????????????????????????&???????????????????????? ??????????????s???????? ???????p????????????????????L??? ???????????s??????&???????????????????????????????????&??????????????????????????????KLBG?????&???????????????????????????????&??????????????????????????????????????????? ???????p???????? ???????????L????????????????s?????&???????????????????????????????&??????????????????????????????PNP Filter???????&???????????????????????????????????????i???????????????&???????????????????????????????&??????????????????????????????Bluetooth Radio USB Driver???????????&???????????????????????????????o?o?????????o??????????????t????????&???????????????????????????????&???????????????????????????????????????o??????????e;???&?
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind ???p?u???i?i?i????N??i?????????D????? r??o?????????0????{4d36e97d-e325-11ce-bfc1-08002be10318}???????????d???D???e??{4d36e972-e325-11ce-bfc1-08002be10318}??????? ???????i?????????????-??????????????????????s?????? ???????i?????????????-?????????????????f???i?i????????? ???????i?????i???????1??L????????? ??????????????i???i???i??t %1??????? ???????i??????????????PCI\VEN_8086&DEV_2845&REV_03?PCI\VEN_8086&DEV_2845?PCI\VEN_8086&CC_060400?PCI\VEN_8086&CC_0604?PCI\VEN_8086?PCI\CC_060400?PCI\CC_0604????/???i??? ???i??????????s?????N??i?????????D??????X??????????t?????i????@machine.inf,%pci\ven_8086&dev_2845.devicedesc%;Intel® ICH8 Family PCI Express Root Port 4 - 2845??4??????!??????i???????i???????i????@system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,28,3)????????????? ???????i?????i???????-??(???????????????????s??/??? ???????i?????i???????-??4??????????????????????4??? ???????i?????????????-?????????????????????y??? ???????i???????????i?-??????"??????????????????i ??/????????r??/????????|
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route ????????????????????????BTWNULL??????????????????????????????????????????????t???t????P???????????????,????????????????????? ????t???n??????????????????????????????????????et???????????????????????????6??????????system32\DRIVERS\HssDrv.sys?44???????????????????????q???????????????????????????????r?gBl????j??????2???????????????????5?????sbf???????????????e??T_???????????????????????????????????????????????????1??????p???????s????z???e???????????????8??????B9????:??????f?g????????45???????????????????????????????t???4??s???????E4???????????????????????????????s????????????8??????a????hcal??.NTx86????????????????>????????????e?????????t???????????e??Hotspot Shield Helper Miniport???????????o??????p????k?l?s?t???s?s???s??? ????????????????????????????6??????p??????34??34???????????????????z???????{??C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDMINE.DLL?????????????? ???????-?????41E??usb.inf???????H?????????????6E????X??????a???t??????????????????????.NT??e????????????:??????B?gS ???????????"??C9????P????????????n???
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export ??????????????????????8??????5???????????????????????????????????6???f??????57??????????????????????????????0.0.0.0???????:??????O??\*???????????????????????????????????????????4??B-???????????c??????????????????????????????????????uwroikog????2001:0:4137:9e76:30da:249f:8c5b:7afe?6?????,?????????????????????????????????????|???????t?????????????????????????????????????????????????????????q???q???q???q???q???????????q???????q???????q???????q???q???q???q???q?5?q???q???q???????q???q???q???q?????????? ????????????????????????????????????????????????????????????????????????????????????????????????????q???q???q???????????q???????????????????q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???q???????q???q???q???q???q???q???????????????????????????????q???q???q???q???q???q???q???????????q???q???q???q???q???????q???????q???????q???????????q???q???????q???????q???q???????q???????q???????q???????????q???q???q???q???????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export ??????????z?????????????????-9???????????c???????????????9??????????GR????????????????????.?????????????? ?????????????????????-??"?????p?&?????or??{4d36e972-e325-11ce-bfc1-08002be10318}?-B1????$??????|???????0??????disk.inf?????????????t??l????????????0??????????? ??????? ???????????????????????????????????z???{??@disk.inf,%disk_devdesc%;Disk drive???????(??????3??????? ???????|???????????o?:??????????Z?&???????????????????????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|Profile=Public|LPort=RPC|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\system32\vds.exe|Svc=vds|Name=@FirewallAPI.dll,-34502|Desc=@FirewallAPI.dll,-34503|EmbedCtxt=@FirewallAPI.dll,-34501|???v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=System|Name=@FirewallAPI.dll,-31281|Desc=@FirewallAPI.dll,-31284|EmbedCtxt=@FirewallAPI.dll,-31252|??<?<??Root\*6TO4MP\0037???\\?\WpdBusEnumRoot#UMB#2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_HUAWEI&PROD_MMC_STORAGE&REV_2.31
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Export ???s?u???????????????&??tunnel???????????????????????????????$???$??????????RPCSS???????11?p??????????????????????????????????????????????????????????????@FirewallAPI.dll,-23521???????@FirewallAPI.dll,-23522???????MPSSVC?????????????????????????? ??????????? ????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P?????????????P????????????????????????8?p??????????????$??s??????p???Loopback?????????????4??????????????????disk.inf????????????????????????????Keyboard Port???Boot File System?????????????????????????? ??i??????p????????t??int?wa???? ??k??????p????&???p???????????????????????????&???p??????????????????????????? ???????o???????????o????????L????????????????????????????????????????????????????#????????????????????@FirewallAPI.dll,-23501?????????????????????????????????????????????????????????????????????????????????????@FirewallAPI.dll,-23501??????????????????????????&???????????????????????????????&??????????????????????????????? ???????o?????
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1D 0x3C 0xB1 0x01 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE3 0x30 0x64 0xA7 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xC5 0x9F 0xD0 0xB7 ...
---- EOF - GMER 1.0.15 ----