Reg HKLM\SYSTEM\ControlSet006\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@imagepath \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main@aid 10099
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrcmd.dll \systemroot\system32\geyekroswbvuto.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrlog.dat \systemroot\system32\geyekrvpxuxcve.dat
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrwsp.dll \systemroot\system32\geyekrwiigvcwd.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@imagepath \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main@aid 10099
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrcmd.dll \systemroot\system32\geyekroswbvuto.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrlog.dat \systemroot\system32\geyekrvpxuxcve.dat
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrwsp.dll \systemroot\system32\geyekrwiigvcwd.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@start 1
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@type 1
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@group file system
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@imagepath \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main@aid 10099
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main@sid 0
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrcmd.dll \systemroot\system32\geyekroswbvuto.dll
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrlog.dat \systemroot\system32\geyekrvpxuxcve.dat
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrwsp.dll \systemroot\system32\geyekrwiigvcwd.dll
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION E32589FD12BE0D4F597AFD0BE6FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC79338EDD5E5BE2F6E667A2D97226D213B55504911C3324D50297A7D96BA154257028FB08244BFCE12D69FC4688B236E05809E8777990457CD486DC831D5FFA097129EC6E92BA968DA7BF5EC1BA074A5A6E3D664490F3BCE694177E010CC0A8013179C3229A61055121D06E19A2674128161A519722BB8FA0B5876A554AAE3D0F4677092CBDD69FC2EF36FE7A54358D950895E267F13968CDF14D635C6C8ABCCB8CB3A6E88327E18F313E42E866CB418441DB3978C73416A2C59010400DA7CB629FF3ED8D7652EDF8C0EC523BF37797EA804C55687365086C732F7A03484A3892E332901E254D8451C477AB9B1EF8EB50C97B1DA6427AD507003811F8C1AF6E2E7D1C27F2A17E900323482D890805C0D466AF5A778B17B965B371264B9D06811E58122D3C84C21B09077F9B57D846B9A662E538F025508F0E1BD2717586712A5CA1A901F9E5EA5673DFEDA0AB3D59200D8DCA4A016EAF5C9B89088BC92A87C1F84B2EE683E53A9466611AC780E3CDE0E0FBC406E5C634C33C92F1F26D39D3C7970C9C060227E7CE1C013F812701A90C8F866BC234124F8FB010A60C576A56DE6D5EA469F1CFA1215EFA4C2240CB66D719C78740533
---- Files - GMER 1.0.15 ----
File C:\Users\Mark & Adriana\AppData\Local\Temp\geyekr000 0 bytes
File C:\Windows\System32\drivers\geyekrsbmxtfyx.sys 66048 bytes
File C:\Windows\Temp\geyekreqewgtxxti.tmp 18432 bytes
File C:\Windows\Temp\geyekrgrekyqlxqw.tmp 18432 bytes
File C:\Windows\Temp\geyekrnxifftxxsv.tmp 18432 bytes
---- EOF - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd@imagepath \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main@aid 10099
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrcmd.dll \systemroot\system32\geyekroswbvuto.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrlog.dat \systemroot\system32\geyekrvpxuxcve.dat
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekrwsp.dll \systemroot\system32\geyekrwiigvcwd.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd@imagepath \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main@aid 10099
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrcmd.dll \systemroot\system32\geyekroswbvuto.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrlog.dat \systemroot\system32\geyekrvpxuxcve.dat
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekrwsp.dll \systemroot\system32\geyekrwiigvcwd.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@start 1
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@type 1
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@group file system
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd@imagepath \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main@aid 10099
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main@sid 0
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrsbmxtfyx.sys
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrcmd.dll \systemroot\system32\geyekroswbvuto.dll
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrlog.dat \systemroot\system32\geyekrvpxuxcve.dat
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekrwsp.dll \systemroot\system32\geyekrwiigvcwd.dll
Reg HKLM\SYSTEM\ControlSet009\Services\geyekrfrvqidfd\modules@geyekr.dat \systemroot\system32\geyekreetmbfnm.dat
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG11.00.00.01WORKSTATION E32589FD12BE0D4F597AFD0BE6FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC79338EDD5E5BE2F6E667A2D97226D213B55504911C3324D50297A7D96BA154257028FB08244BFCE12D69FC4688B236E05809E8777990457CD486DC831D5FFA097129EC6E92BA968DA7BF5EC1BA074A5A6E3D664490F3BCE694177E010CC0A8013179C3229A61055121D06E19A2674128161A519722BB8FA0B5876A554AAE3D0F4677092CBDD69FC2EF36FE7A54358D950895E267F13968CDF14D635C6C8ABCCB8CB3A6E88327E18F313E42E866CB418441DB3978C73416A2C59010400DA7CB629FF3ED8D7652EDF8C0EC523BF37797EA804C55687365086C732F7A03484A3892E332901E254D8451C477AB9B1EF8EB50C97B1DA6427AD507003811F8C1AF6E2E7D1C27F2A17E900323482D890805C0D466AF5A778B17B965B371264B9D06811E58122D3C84C21B09077F9B57D846B9A662E538F025508F0E1BD2717586712A5CA1A901F9E5EA5673DFEDA0AB3D59200D8DCA4A016EAF5C9B89088BC92A87C1F84B2EE683E53A9466611AC780E3CDE0E0FBC406E5C634C33C92F1F26D39D3C7970C9C060227E7CE1C013F812701A90C8F866BC234124F8FB010A60C576A56DE6D5EA469F1CFA1215EFA4C2240CB66D719C78740533
---- Files - GMER 1.0.15 ----
File C:\Users\Mark & Adriana\AppData\Local\Temp\geyekr000 0 bytes
File C:\Windows\System32\drivers\geyekrsbmxtfyx.sys 66048 bytes
File C:\Windows\Temp\geyekreqewgtxxti.tmp 18432 bytes
File C:\Windows\Temp\geyekrgrekyqlxqw.tmp 18432 bytes
File C:\Windows\Temp\geyekrnxifftxxsv.tmp 18432 bytes
---- EOF - GMER 1.0.15 ----