GMER 1.0.15.15163 -
http://www.gmer.netRootkit scan 2009-10-24 22:54:51
Windows 6.0.6001 Service Pack 1
Running: svchost1.exe; Driver: C:\Users\DEFAUL~1.ABC\AppData\Local\Temp\kxldypoc.sys
---- System - GMER 1.0.15 ----
Code 8815C520 ZwEnumerateKey
Code 87FC22F0 ZwFlushInstructionCache
Code 87F423FE ZwSaveKey
Code 880B9A1E ZwSaveKeyEx
Code 87FEE40D IofCallDriver
Code 87DDDFD6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCompleteRequest 83247FE2 5 Bytes JMP 87DDDFDB
.text ntkrnlpa.exe!IofCallDriver 832C9F6F 5 Bytes JMP 87FEE412
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 833C030B 5 Bytes JMP 87FC22F4
PAGE ntkrnlpa.exe!ZwEnumerateKey 83415BAC 5 Bytes JMP 8815C524
PAGE ntkrnlpa.exe!ZwSaveKey 83463573 5 Bytes JMP 87F42402
PAGE ntkrnlpa.exe!ZwSaveKeyEx 8346367A 5 Bytes JMP 880B9A22
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\GameSpy\Comrade\Comrade.exe[3268] KERNEL32.dll!LoadLibraryExW 76EB30C3 7 Bytes JMP 10005230 C:\Program Files\GameSpy\Comrade\rscoree.dll (rscoree/Remotesoft, Inc.)
.text C:\Program Files\GameSpy\Comrade\Comrade.exe[3268] USER32.dll!ShowWindow 7563D80A 5 Bytes JMP 0AE62880 C:\Program Files\GameSpy\Comrade\wpffix.dll
.text C:\Program Files\GameSpy\Comrade\Comrade.exe[3268] WS2_32.dll!sendto 757667C5 5 Bytes JMP 064733C0 C:\Program Files\GameSpy\Comrade\DetectLib.dll
.text C:\Program Files\GameSpy\Comrade\Comrade.exe[3268] WS2_32.dll!WSASendTo 7577A474 5 Bytes JMP 06473400 C:\Program Files\GameSpy\Comrade\DetectLib.dll
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- Processes - GMER 1.0.15 ----
Library C:\Users\Public\svchost1.exe (*** hȋdden *** ) @ C:\Users\Public\svchost1.exe [3948] 0x00400000
---- Services - GMER 1.0.15 ----
Service C:\Windows\system32\drivers\gasfkymxtcrqpu.sys (*** hȋdden *** ) [SYSTEM] gasfkymdpuspsx <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\00158315a318 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet001\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet003\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00158315a318
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main\injector@svchost.exe
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkymdpuspsx\modules@gasfkywsp8p.dll \systemroot\system32\gasfkypwqvbqie.dll
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet005\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main\injector@svchost.exe
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gasfkymdpuspsx\modules@gasfkywsp8p.dll \systemroot\system32\gasfkypwqvbqie.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main\injector@svchost.exe
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gasfkymdpuspsx\modules@gasfkywsp8p.dll \systemroot\system32\gasfkypwqvbqie.dll
Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\00158315a318 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx@imagepath \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main@aid 10149
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main@sid 0
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main\injector@* gasfkywsp8.dll
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main\injector@svchost.exe
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkymxtcrqpu.sys
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfkycmd.dll \systemroot\system32\gasfkycgksorqr.dll
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfkylog.dat \systemroot\system32\gasfkyiexedupr.dat
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfkywsp.dll \systemroot\system32\gasfkymycvetyb.dll
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfky.dat \systemroot\system32\gasfkynfumcfjw.dat
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfkywsp8.dll \systemroot\system32\gasfkyngtlexhw.dll
Reg HKLM\SYSTEM\ControlSet008\Services\gasfkymdpuspsx\modules@gasfkywsp8p.dll \systemroot\system32\gasfkypwqvbqie.dll
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler@Heartbeat 0x8A 0xE4 0x13 0x74 ...
---- Files - GMER 1.0.15 ----
File C:\Users\DEFAULT.ABC_RANGE-1\AppData\Local\Temp\gasfky000 0 bytes
File C:\Windows\System32\drivers\gasfkymxtcrqpu.sys 68096 bytes executable <-- ROOTKIT !!!
File C:\Windows\System32\gasfkycgksorqr.dll 41984 bytes executable
File C:\Windows\System32\gasfkyiexedupr.dat 75022 bytes
File C:\Windows\System32\gasfkymycvetyb.dll 19456 bytes executable
File C:\Windows\System32\gasfkynfumcfjw.dat 43 bytes
File C:\Windows\System32\gasfkyngtlexhw.dll 21504 bytes
File C:\Windows\System32\gasfkypwqvbqie.dll 21504 bytes executable
File C:\Windows\Temp\gasfkyomtdxnertr.tmp 43 bytes
File C:\Windows\Temp\gasfkypwqetvtdbf.tmp 43 bytes
---- EOF - GMER 1.0.15 ----