GMER 1.0.15.14966 -
http://www.gmer.netRootkit scan 2009-03-30 21:48:38
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwAllocateVirtualMemory [0xF3DC30F0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwAssignProcessToJobObject [0xF3DC36E0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwConnectPort [0xF3DC2370]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateFile [0xF3DCFE80]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateKey [0xF3DCE1B0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreatePort [0xF3DC21D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateProcess [0xF3DBFA10]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateProcessEx [0xF3DBFDE0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateSection [0xF3DBF520]
SSDT F7C882CC ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwDebugActiveProcess [0xF3DC17B0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwDeleteFile [0xF3DD09C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwDeleteKey [0xF3DCE760]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwDeleteValueKey [0xF3DCF0B0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwEnumerateKey [0xF3DCFE20]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwEnumerateValueKey [0xF3DCFE50]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwLoadDriver [0xF3DC2BC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwOpenFile [0xF3DD05D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwOpenKey [0xF3DCE9A0]
SSDT F7C882B8 ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwOpenSection [0xF3DBF7A0]
SSDT F7C882BD ZwOpenThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwProtectVirtualMemory [0xF3DC3390]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwQueryKey [0xF3DCFDC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwQueryValueKey [0xF3DCFDF0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwReplaceKey [0xF3DCF8A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwRequestWaitReplyPort [0xF3DC2750]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwRestoreKey [0xF3DCFB00]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwResumeThread [0xF3DC1E80]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSaveKey [0xF3DCFDA0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSetContextThread [0xF3DC15D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSetSystemInformation [0xF3DC1930]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSetValueKey [0xF3DCE9C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwShutdownSystem [0xF3DC2AC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSuspendProcess [0xF3DC2030]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSuspendThread [0xF3DC1CB0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSystemDebugControl [0xF3DC1B10]
SSDT F7C882C7 ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwTerminateThread [0xF3DC1400]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwUnloadDriver [0xF3DC2DE0]
SSDT F7C882C2 ZwWriteVirtualMemory
INT 0x62 ? 867DABF8
INT 0x63 ? 867DABF8
INT 0x63 ? 867DABF8
INT 0x63 ? 867DABF8
INT 0x82 ? 867DABF8
INT 0x83 ? 86435F00
INT 0x84 ? 86435F00
INT 0x94 ? 86435F00
INT 0xA4 ? 86435F00
Code \??\C:\DOCUME~1\Emiliano\IMPOST~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 241C 80501C54 12 Bytes [D0, 21, DC, F3, 10, FA, DB, ...] {SHL BYTE [ECX], 0x1; FDIVR ST(3), ST; ADC DL, BH; FCOMI ST, ST(3); LOOPNZ 0x7; FCOMI ST, ST(3)}
.text ntkrnlpa.exe!ZwCallbackReturn + 2540 80501D78 4 Bytes JMP 59731159
.text ntkrnlpa.exe!ZwCallbackReturn + 2740 80501F78 4 Bytes JMP 94D71359
.text ntkrnlpa.exe!ZwCallbackReturn + 2758 80501F90 12 Bytes [30, 20, DC, F3, B0, 1C, DC, ...] {XOR [EAX], AH; FDIVR ST(3), ST; MOV AL, 0x1c; FDIVR ST(3), ST; ADC [EBX], BL; FDIVR ST(3), ST}
? spkv.sys Impossibile trovare il file specificato. !
.text USBPORT.SYS!DllUnload F66BA8AC 5 Bytes JMP 864354E0
.text ajssphvu.SYS F664D386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text ajssphvu.SYS F664D3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text ajssphvu.SYS F664D3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text ajssphvu.SYS F664D3C9 1 Byte [2E]
.text ajssphvu.SYS F664D3C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
? C:\DOCUME~1\Emiliano\IMPOST~1\Temp\catchme.sys Impossibile trovare il file specificato. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS Impossibile trovare il file specificato. !
---- User code sections - GMER 1.0.15 ----
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avguard.exe[180] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avesvc.exe[304] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\wdfmgr.exe[504] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\csrss.exe[512] KERNEL32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text C:\WINDOWS\system32\winlogon.exe[536] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text ...
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BF0001
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[636] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\svchost.exe[744] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text C:\Programmi\Java\jre6\bin\jqs.exe[816] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\CDBurnerXP\NMSAccessU.exe[1004] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\svchost.exe[1044] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text C:\WINDOWS\system32\nvsvc32.exe[1100] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text ...
.text C:\Programmi\Tall Emu\Online Armor\oacat.exe[1280] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00780001
.text C:\Programmi\Tall Emu\Online Armor\oacat.exe[1280] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Tall Emu\Online Armor\oacat.exe[1280] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E
.text C:\Programmi\Tall Emu\Online Armor\oacat.exe[1280] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avmailc.exe[1304] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1316] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\svchost.exe[1372] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text C:\Programmi\Tall Emu\Online Armor\oasrv.exe[1496] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BE0001
.text C:\Programmi\Tall Emu\Online Armor\oasrv.exe[1496] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E
.text C:\Programmi\Tall Emu\Online Armor\oasrv.exe[1496] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00A10001
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\avgnt.exe[1504] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE[1728] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\spoolsv.exe[1824] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BE0001
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[1832] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Emiliano\Desktop\930yxccq.exe[1860] user32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\Programmi\Google\Update\GoogleUpdate.exe[1868] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D
.text C:\Programmi\Avira\AntiVir PersonalEdition Premium\sched.exe[1912] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\explorer.exe[2200] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D80001
.text C:\WINDOWS\explorer.exe[2200] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\explorer.exe[2200] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\explorer.exe[2200] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\explorer.exe[2200] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\explorer.exe[2200] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\explorer.exe[2200] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\ctfmon.exe[2536] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AF0001
.text C:\WINDOWS\system32\ctfmon.exe[2536] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ctfmon.exe[2536] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2536] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\ctfmon.exe[2536] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[2536] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[2536] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F60001
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\Programmi\Trend Micro\HijackThis\HijackThis.exe[3204] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AE0001
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\NOTEPAD.EXE[3468] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F11001E
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0E001E
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E
.text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[3552] user32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F14001E
.text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3940] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01460001
.text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3940] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3940] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E
.text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3940] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E
.text C:\WINDOWS\System32\alg.exe[3972] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73DC040] spkv.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73DC13C] spkv.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73DC0BE] spkv.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73DC7FC] spkv.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73DC6D2] spkv.sys
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\ajssphvu.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73EC048] spkv.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F769E3B0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F769E410] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F769E6C0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F769E700] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F769E6C0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F769E410] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F769E3B0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [F769E3B0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [F769E410] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [F769E700] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [F769E6C0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F769E6C0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F769E700] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F769E3B0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F769E410] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 867D91F8
Device \Driver\Tcpip \Device\Ip OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd)
Device \Driver\usbohci \Device\USBPDO-0 86434500
Device \Driver\PCI_PNP0202 \Device\00000044 spkv.sys
Device \Driver\PCI_PNP0202 \Device\00000044 spkv.sys
Device \Driver\usbohci \Device\USBPDO-1 86434500
Device \Driver\NetBT \Device\NetBT_Tcpip_{16E52BDD-70B7-4EDC-AFA4-457EDD9642A9} 8657A1F8
Device \Driver\usbohci \Device\USBPDO-2 86434500
Device \Driver\usbehci \Device\USBPDO-3 8640B1F8
Device \Driver\Tcpip \Device\Tcp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd)
Device \Driver\NetBT \Device\NetBT_Tcpip_{FD691ED0-1EEB-45F8-BA73-7495A21952DA} 8657A1F8
Device \Driver\sptd \Device\2168940202 spkv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 8676F1F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\Ftdisk \Device\HarddiskVolume2 8676F1F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\Cdrom \Device\CdRom0 865441F8
Device \Driver\usbstor \Device\00000065 865F4500
Device \Driver\Cdrom \Device\CdRom1 865441F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 8676F1F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\Ftdisk \Device\HarddiskVolume4 8676F1F8
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\usbstor \Device\00000068 865F4500
Device \Driver\usbstor \Device\00000069 865F4500
Device \Driver\NetBT \Device\NetBt_Wins_Export 8657A1F8
Device \Driver\NetBT \Device\NetbiosSmb 8657A1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{117A47B0-3B87-4523-98D2-B0C78980ECFA} 8657A1F8
Device \Driver\Tcpip \Device\Udp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd)
Device \Driver\Tcpip \Device\RawIp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd)
Device \Driver\usbstor \Device\0000006a 865F4500
Device \Driver\usbstor \Device\0000006b 865F4500
Device \Driver\usbohci \Device\USBFDO-0 86434500
Device \Driver\usbohci \Device\USBFDO-1 86434500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 865911F8
Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd)
Device \Driver\usbohci \Device\USBFDO-2 86434500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 865911F8
Device \Driver\usbehci \Device\USBFDO-3 8640B1F8
Device \Driver\Ftdisk \Device\FtControl 8676F1F8
Device \Driver\ajssphvu \Device\Scsi\ajssphvu1Port4Path0Target0Lun0 863FF1F8
Device \Driver\ajssphvu \Device\Scsi\ajssphvu1 863FF1F8
Device \FileSystem\Cdfs \Cdfs 865BA1F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x5E 0x98 0x65 0xA8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDF 0xBD 0xC4 0x6A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x41 0x62 0x45 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x5E 0x98 0x65 0xA8 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xDF 0xBD 0xC4 0x6A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDF 0x41 0x62 0x45 ...
---- EOF - GMER 1.0.15 ----