GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2016-05-04 18:31:39
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST320LT0 rev.0010 298,09GB
Running: zr1ur0jh.exe; Driver: C:\Users\Grzegorz\AppData\Local\Temp\ugldrpoc.sys


---- User code sections - GMER 2.2 ----

.text   C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[828] C:\Windows\system32\kernel32.dll!SetUnhandledExceptionFilter                                     0000000077559040 4 bytes [C3, 00, 00, 00]
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                          00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                            00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                          00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                          00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                             00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                      00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                             00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                      00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                            00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                 00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                          00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                            00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                               00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                            00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                          00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                      00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                      00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                     00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                       00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                     00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                     00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                        00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                 00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                        00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                 00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                       00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                            00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                     00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                       00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                          00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                       00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                     00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                 00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                 00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                             00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                               00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                             00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                             00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                         00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                         00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                               00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                    00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                             00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                               00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                  00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                               00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                             00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                         00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1548] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                         00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\SysWOW64\rpcnet.exe[3880] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82                                                                            00000000739017fa 2 bytes CALL 774411a9 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\SysWOW64\rpcnet.exe[3880] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88                                                                        0000000073901860 2 bytes CALL 774411a9 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\SysWOW64\rpcnet.exe[3880] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98                                                                      0000000073901942 2 bytes JMP 76e17089 C:\Windows\syswow64\WS2_32.dll
.text   C:\Windows\SysWOW64\rpcnet.exe[3880] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109                                                                     000000007390194d 2 bytes JMP 76e1cba6 C:\Windows\syswow64\WS2_32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17                        00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17                          00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17                        00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42                        00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17                           00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17                    00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17                           00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17                    00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17                          00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17                               00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17                        00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17                          00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17                             00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17                          00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17                        00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20                    00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[4392] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31                    00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll
.text   C:\WINDOWS\SYSWOW64\VMNAT.EXE[4836] C:\WINDOWS\SYSWOW64\SHFOLDER.dll!SHGetFolderPathW + 4                                                                 0000000069ee13b0 2 bytes JMP 75d55628 C:\Windows\syswow64\SHELL32.dll
.text   C:\WINDOWS\SYSWOW64\VMNAT.EXE[4836] C:\WINDOWS\SYSWOW64\SHFOLDER.dll!SHGetFolderPathW + 20                                                                0000000069ee13c0 2 bytes CALL 75589cee C:\Windows\syswow64\msvcrt.dll
.text   ...                                                                                                                                                       * 20
.text   C:\WINDOWS\SYSWOW64\VMNAT.EXE[4836] C:\WINDOWS\SYSWOW64\SHFOLDER.dll!SHGetFolderPathA + 22                                                                0000000069ee153e 2 bytes CALL 75de7744 C:\Windows\syswow64\SHELL32.dll
.text   C:\WINDOWS\SYSWOW64\VMNAT.EXE[4836] C:\WINDOWS\SYSWOW64\SHFOLDER.dll!SHGetFolderPathA + 43                                                                0000000069ee1553 2 bytes CALL 774410ff C:\Windows\syswow64\kernel32.dll
?       C:\Windows\system32\mssprxy.dll [5016] entry point in ".rdata" section                                                                                    0000000074f671e6
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                  00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                   00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                            00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                   00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                            00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                  00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                       00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                  00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                     00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                  00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                            00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                            00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17      00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17        00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17      00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42      00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17         00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17  00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17         00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17  00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17        00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17             00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17      00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17        00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17           00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17        00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17      00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20  00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5312] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31  00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                00000000759e1401 2 bytes JMP 7746b233 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                  00000000759e1419 2 bytes JMP 7746b35e C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                00000000759e1431 2 bytes JMP 774e9011 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                00000000759e144a 2 bytes CALL 774448ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                       * 9
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                   00000000759e14dd 2 bytes JMP 774e890a C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                            00000000759e14f5 2 bytes JMP 774e8ae0 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                   00000000759e150d 2 bytes JMP 774e8800 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                            00000000759e1525 2 bytes JMP 774e8bca C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                  00000000759e153d 2 bytes JMP 7745fcc0 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                       00000000759e1555 2 bytes JMP 77466907 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                00000000759e156d 2 bytes JMP 774e90c9 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                  00000000759e1585 2 bytes JMP 774e8c2a C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                     00000000759e159d 2 bytes JMP 774e87c4 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                  00000000759e15b5 2 bytes JMP 7745fd59 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                00000000759e15cd 2 bytes JMP 7746b2f4 C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                            00000000759e16b2 2 bytes JMP 774e8f8c C:\Windows\syswow64\kernel32.dll
.text   c:\Firebird\bin\fbserver.exe[5680] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                            00000000759e16bd 2 bytes JMP 774e8759 C:\Windows\syswow64\kernel32.dll

---- Kernel IAT/EAT - GMER 2.2 ----

IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                                                            [fffff8800108be94] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                                                                   [fffff8800108bc38] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                                                                  [fffff8800108c654] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong]                                                                                  [fffff8800108ca50] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                                                           [fffff8800108c8ac] \SystemRoot\System32\Drivers\sptd.sys [.text]

---- Devices - GMER 2.2 ----

Device  \FileSystem\Ntfs \Ntfs                                                                                                                                    fffffa800490f2c0
Device  \FileSystem\fastfat \Fat                                                                                                                                  fffffa80078562c0
Device  \Driver\usbehci \Device\USBPDO-1                                                                                                                          fffffa800786c2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{75F8173B-512C-4C8E-BFE6-430A6513DEC7}                                                                                  fffffa800743b2c0
Device  \Driver\usbehci \Device\USBFDO-0                                                                                                                          fffffa800786c2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{AF6BF556-D825-4D56-B5B5-40CCC4F452A8}                                                                                  fffffa800743b2c0
Device  \Driver\usbehci \Device\USBFDO-1                                                                                                                          fffffa800786c2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{86340B25-80B3-4636-B0E7-955EB3CC61C0}                                                                                  fffffa800743b2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{DE444D89-9DA0-4B1C-9A0A-21CF28A49D2A}                                                                                  fffffa800743b2c0
Device  \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                                   fffffa800743b2c0
Device  \Driver\usbehci \Device\USBPDO-0                                                                                                                          fffffa800786c2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{FAB965E2-4CF8-4E99-A8D3-0BDA5C74825B}                                                                                  fffffa800743b2c0

---- Threads - GMER 2.2 ----

Thread  C:\Windows\system32\svchost.exe [1356:1676]                                                                                                               000007fefceb1a70
Thread  C:\Windows\system32\svchost.exe [1356:1680]                                                                                                               000007fefceb1a70
Thread  C:\Windows\system32\svchost.exe [1356:1692]                                                                                                               000007fefceb1a70
Thread  C:\Windows\system32\svchost.exe [1356:1700]                                                                                                               000007fef8c22c70
Thread  C:\Windows\system32\svchost.exe [1356:1704]                                                                                                               000007fef8c51000
Thread  C:\Windows\system32\svchost.exe [1356:1712]                                                                                                               000007fef8c2fb40
Thread  C:\Windows\system32\svchost.exe [1356:1724]                                                                                                               000007fef8c41d20
Thread  C:\Windows\system32\svchost.exe [1356:1728]                                                                                                               000007fef8c2f6f0
Thread  C:\Windows\system32\svchost.exe [1356:2640]                                                                                                               000007fefa5135c0
Thread  C:\Windows\system32\svchost.exe [1356:2644]                                                                                                               000007fefa515600
Thread  C:\Windows\system32\svchost.exe [1356:6032]                                                                                                               000007fef0ca2888
Thread  C:\Windows\system32\svchost.exe [1356:6052]                                                                                                               000007fef0c42940
Thread  C:\Windows\system32\WLANExt.exe [1444:1540]                                                                                                               00000000007f86e4
Thread  C:\Windows\system32\WLANExt.exe [1444:1544]                                                                                                               00000000007f86e4
Thread  C:\Windows\System32\svchost.exe [2592:2100]                                                                                                               000007fef4aa0360
Thread  C:\Windows\System32\svchost.exe [2592:2072]                                                                                                               000007fef4a7e460
Thread  C:\Windows\System32\svchost.exe [2592:2164]                                                                                                               000007fef4a7e450
Thread  C:\Windows\System32\svchost.exe [2592:336]                                                                                                                000007fef4a45570
Thread  C:\Windows\System32\svchost.exe [2592:1196]                                                                                                               000007fef4a7a130
Thread  C:\Windows\System32\svchost.exe [2592:1424]                                                                                                               000007fef4a45560
Thread  C:\Windows\System32\svchost.exe [2592:1296]                                                                                                               000007fef4ac82a0
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:2820]                                                     000000007797c6d7
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3168]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3528]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:1868]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3580]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:1348]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3728]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3772]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3760]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3196]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4384]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4388]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4532]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4536]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4612]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4616]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4620]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4624]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4628]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:3496]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4400]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4216]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:2296]                                                     00000000779929b1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5196]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5200]                                                     00000000779929b1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5204]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5460]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5492]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5496]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5500]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5504]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5508]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5512]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5536]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4284]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:4280]                                                     00000000744529e1
Thread  C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [240:5796]                                                     0000000077995c71

---- Registry - GMER 2.2 ----

Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{F5C79404-C849-4E21-B506-1244F9E89F2D}\Connection@Name               isatap.{75F8173B-512C-4C8E-BFE6-430A6513DEC7}
Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind                  \Device\{C5C851DC-B01D-456D-95B4-137E741A5659}?\Device\{F5C79404-C849-4E21-B506-1244F9E89F2D}?\Device\{A77BF19D-09DA-4A3E-AF41-F417747ECD85}?\Device\{A91C8D1C-D21F-4B96-AB90-1B9ABF32307A}?\Device\{901955FC-2284-4675-B028-949F29A2083D}?\Device\{A46EBB14-94C0-4BD4-8A99-2C2A20C28866}?
Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route                 "{C5C851DC-B01D-456D-95B4-137E741A5659}"?"{F5C79404-C849-4E21-B506-1244F9E89F2D}"?"{A77BF19D-09DA-4A3E-AF41-F417747ECD85}"?"{A91C8D1C-D21F-4B96-AB90-1B9ABF32307A}"?"{901955FC-2284-4675-B028-949F29A2083D}"?"{A46EBB14-94C0-4BD4-8A99-2C2A20C28866}"?
Reg     HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export                \Device\TCPIP6TUNNEL_{C5C851DC-B01D-456D-95B4-137E741A5659}?\Device\TCPIP6TUNNEL_{F5C79404-C849-4E21-B506-1244F9E89F2D}?\Device\TCPIP6TUNNEL_{A77BF19D-09DA-4A3E-AF41-F417747ECD85}?\Device\TCPIP6TUNNEL_{A91C8D1C-D21F-4B96-AB90-1B9ABF32307A}?\Device\TCPIP6TUNNEL_{901955FC-2284-4675-B028-949F29A2083D}?\Device\TCPIP6TUNNEL_{A46EBB14-94C0-4BD4-8A99-2C2A20C28866}?
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f4b7e213701c                                                                               
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f4b7e213701c@9420535ee4cc                                                                  0xDC 0xEB 0xF0 0xF3 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f4b7e213701c@943af08fbd1d                                                                  0x79 0xEC 0x8A 0x91 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f4b7e213701c@4c257876061b                                                                  0x13 0x1D 0xD4 0x44 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f4b7e213701c@9ce6e724944b                                                                  0x28 0x4B 0xEE 0x25 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{F5C79404-C849-4E21-B506-1244F9E89F2D}@InterfaceName                                    isatap.{75F8173B-512C-4C8E-BFE6-430A6513DEC7}
Reg     HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{F5C79404-C849-4E21-B506-1244F9E89F2D}@ReusableType                                     0
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f4b7e213701c (not active ControlSet)                                                           
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f4b7e213701c@9420535ee4cc                                                                      0xDC 0xEB 0xF0 0xF3 ...
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f4b7e213701c@943af08fbd1d                                                                      0x79 0xEC 0x8A 0x91 ...
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f4b7e213701c@4c257876061b                                                                      0x13 0x1D 0xD4 0x44 ...
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f4b7e213701c@9ce6e724944b                                                                      0x28 0x4B 0xEE 0x25 ...

---- Disk sectors - GMER 2.2 ----

Disk    \Device\Harddisk0\DR0                                                                                                                                     unknown MBR code

---- EOF - GMER 2.2 ----
