GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-06-03 14:58:02
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3500418AS rev.CC38
Running: lq9k9k6t.exe; Driver: C:\Users\GEBRUI~1\AppData\Local\Temp\uxldrpob.sys


---- System - GMER 1.0.15 ----

INT 0x51  ?                                                                                                                                             C32D47D0
INT 0x61  ?                                                                                                                                             C32D4550
INT 0x62  ?                                                                                                                                             C45FFA50
INT 0x71  ?                                                                                                                                             C45DECD0
INT 0x72  ?                                                                                                                                             C45FFCD0
INT 0x82  ?                                                                                                                                             C45FF2D0
INT 0x92  ?                                                                                                                                             C32D4050
INT 0xA2  ?                                                                                                                                             C45DEA50
INT 0xB0  ?                                                                                                                                             C45DE550
INT 0xB1  ?                                                                                                                                             C32D4CD0
INT 0xB2  ?                                                                                                                                             C32D42D0

---- Kernel code sections - GMER 1.0.15 ----

?         System32\drivers\uwpjxfym.sys                                                                                                                 Het systeem kan het opgegeven pad niet vinden. !
.sptd1    C:\Windows\System32\Drivers\sptd.sys                                                                                                          entry point in ".sptd1" section [0xC8586B2E]
.text     C:\Windows\system32\DRIVERS\atikmdag.sys                                                                                                      section is writeable [0xCEA06000, 0x267978, 0xE8000020]
.text     USBPORT.SYS!DllUnload                                                                                                                         CEF7C41B 5 Bytes  JMP C44311C8 
.text     aniectil.SYS!A0DB34FC6FE35D429A28ADDE5467D4D7                                                                                                 C8BDC9B0 48 Bytes  [8A, 10, 72, 1F, 8E, 0F, 8F, ...]
INIT      aniectil.SYS!A0DB34FC6FE35D429A28ADDE5467D4D7 + 968E                                                                                          C8BE603E 32 Bytes  [00, 00, 00, 00, 00, 00, 00, ...]
INIT      aniectil.SYS!A0DB34FC6FE35D429A28ADDE5467D4D7 + 9EC4                                                                                          C8BE6874 3 Bytes  [00, 00, 00]
INIT      aniectil.SYS!A0DB34FC6FE35D429A28ADDE5467D4D7 + A338                                                                                          C8BE6CE8 12 Bytes  [00, 00, 00, 00, 00, 00, 00, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
?         C:\Windows\System32\Drivers\aniectil.SYS                                                                                                      suspicious PE modification

---- User code sections - GMER 1.0.15 ----

.text     C:\Program Files\Pando Networks\Media Booster\PMB.exe[2060] kernel32.dll!SetUnhandledExceptionFilter                                          765AA8C5 5 Bytes  [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtCreateFile + 6                                        77DC424A 4 Bytes  [28, 00, 2A, 00] {SUB [EAX], AL; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtCreateFile + B                                        77DC424F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 1 Byte  [28]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 4 Bytes  [28, 03, 2A, 00] {SUB [EBX], AL; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtMapViewOfSection + B                                  77DC499F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenFile + 6                                          77DC4A2A 4 Bytes  [68, 00, 2A, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenFile + B                                          77DC4A2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenProcess + 6                                       77DC4AAA 4 Bytes  [A8, 01, 2A, 00] {TEST AL, 0x1; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenProcess + B                                       77DC4AAF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenProcessToken + B                                  77DC4ABF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenProcessTokenEx + 6                                77DC4ACA 4 Bytes  [A8, 02, 2A, 00] {TEST AL, 0x2; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenProcessTokenEx + B                                77DC4ACF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenThread + 6                                        77DC4B1A 4 Bytes  [68, 01, 2A, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenThread + B                                        77DC4B1F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenThreadToken + 6                                   77DC4B2A 4 Bytes  [68, 02, 2A, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenThreadToken + B                                   77DC4B2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtOpenThreadTokenEx + B                                 77DC4B3F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtQueryAttributesFile + 6                               77DC4BCA 4 Bytes  [A8, 00, 2A, 00] {TEST AL, 0x0; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtQueryAttributesFile + B                               77DC4BCF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtQueryFullAttributesFile + B                           77DC4C7F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtSetInformationFile + 6                                77DC515A 4 Bytes  [28, 01, 2A, 00] {SUB [ECX], AL; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtSetInformationFile + B                                77DC515F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtSetInformationThread + 6                              77DC51AA 4 Bytes  [28, 02, 2A, 00] {SUB [EDX], AL; SUB AL, [EAX]}
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtSetInformationThread + B                              77DC51AF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 1 Byte  [68]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 4 Bytes  [68, 03, 2A, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] ntdll.dll!NtUnmapViewOfSection + B                                77DC544F 1 Byte  [E2]
.text     C:\Program Files\OO Software\Defrag\oodag.exe[2548] kernel32.dll!SetUnhandledExceptionFilter                                                  765AA8C5 5 Bytes  JMP 00402FB0 C:\Program Files\OO Software\Defrag\oodag.exe (O&O Defrag Agent (Win32)/O&O Software GmbH)
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtCreateFile + 6                                        77DC424A 4 Bytes  [28, 00, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtCreateFile + B                                        77DC424F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 1 Byte  [28]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 4 Bytes  [28, 03, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtMapViewOfSection + B                                  77DC499F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenFile + 6                                          77DC4A2A 4 Bytes  [68, 00, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenFile + B                                          77DC4A2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenProcess + 6                                       77DC4AAA 4 Bytes  [A8, 01, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenProcess + B                                       77DC4AAF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenProcessToken + B                                  77DC4ABF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenProcessTokenEx + 6                                77DC4ACA 4 Bytes  [A8, 02, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenProcessTokenEx + B                                77DC4ACF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenThread + 6                                        77DC4B1A 4 Bytes  [68, 01, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenThread + B                                        77DC4B1F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenThreadToken + 6                                   77DC4B2A 4 Bytes  [68, 02, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenThreadToken + B                                   77DC4B2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtOpenThreadTokenEx + B                                 77DC4B3F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtQueryAttributesFile + 6                               77DC4BCA 4 Bytes  [A8, 00, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtQueryAttributesFile + B                               77DC4BCF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtQueryFullAttributesFile + B                           77DC4C7F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtSetInformationFile + 6                                77DC515A 4 Bytes  [28, 01, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtSetInformationFile + B                                77DC515F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtSetInformationThread + 6                              77DC51AA 4 Bytes  [28, 02, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtSetInformationThread + B                              77DC51AF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 1 Byte  [68]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 4 Bytes  [68, 03, 35, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] ntdll.dll!NtUnmapViewOfSection + B                                77DC544F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtCreateFile + 6                                        77DC424A 4 Bytes  [28, 00, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtCreateFile + B                                        77DC424F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 1 Byte  [28]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 4 Bytes  [28, 03, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtMapViewOfSection + B                                  77DC499F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenFile + 6                                          77DC4A2A 4 Bytes  [68, 00, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenFile + B                                          77DC4A2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenProcess + 6                                       77DC4AAA 4 Bytes  [A8, 01, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenProcess + B                                       77DC4AAF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenProcessToken + B                                  77DC4ABF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenProcessTokenEx + 6                                77DC4ACA 4 Bytes  [A8, 02, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenProcessTokenEx + B                                77DC4ACF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenThread + 6                                        77DC4B1A 4 Bytes  [68, 01, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenThread + B                                        77DC4B1F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenThreadToken + 6                                   77DC4B2A 4 Bytes  [68, 02, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenThreadToken + B                                   77DC4B2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtOpenThreadTokenEx + B                                 77DC4B3F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtQueryAttributesFile + 6                               77DC4BCA 4 Bytes  [A8, 00, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtQueryAttributesFile + B                               77DC4BCF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtQueryFullAttributesFile + B                           77DC4C7F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtSetInformationFile + 6                                77DC515A 4 Bytes  [28, 01, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtSetInformationFile + B                                77DC515F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtSetInformationThread + 6                              77DC51AA 4 Bytes  [28, 02, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtSetInformationThread + B                              77DC51AF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 1 Byte  [68]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 4 Bytes  [68, 03, 2F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] ntdll.dll!NtUnmapViewOfSection + B                                77DC544F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + 6                                        77DC424A 4 Bytes  [28, 00, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + B                                        77DC424F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 1 Byte  [28]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 4 Bytes  [28, 03, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + B                                  77DC499F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + 6                                          77DC4A2A 4 Bytes  [68, 00, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + B                                          77DC4A2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + 6                                       77DC4AAA 4 Bytes  [A8, 01, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + B                                       77DC4AAF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + B                                  77DC4ABF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + 6                                77DC4ACA 4 Bytes  [A8, 02, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + B                                77DC4ACF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + 6                                        77DC4B1A 4 Bytes  [68, 01, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + B                                        77DC4B1F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + 6                                   77DC4B2A 4 Bytes  [68, 02, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + B                                   77DC4B2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + B                                 77DC4B3F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + 6                               77DC4BCA 4 Bytes  [A8, 00, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + B                               77DC4BCF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + B                           77DC4C7F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + 6                                77DC515A 4 Bytes  [28, 01, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + B                                77DC515F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + 6                              77DC51AA 4 Bytes  [28, 02, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + B                              77DC51AF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 1 Byte  [68]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 4 Bytes  [68, 03, 3F, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + B                                77DC544F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtCreateFile + 6                                        77DC424A 4 Bytes  [28, 00, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtCreateFile + B                                        77DC424F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 1 Byte  [28]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtMapViewOfSection + 6                                  77DC499A 4 Bytes  [28, 03, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtMapViewOfSection + B                                  77DC499F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenFile + 6                                          77DC4A2A 4 Bytes  [68, 00, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenFile + B                                          77DC4A2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenProcess + 6                                       77DC4AAA 4 Bytes  [A8, 01, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenProcess + B                                       77DC4AAF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenProcessToken + B                                  77DC4ABF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenProcessTokenEx + 6                                77DC4ACA 4 Bytes  [A8, 02, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenProcessTokenEx + B                                77DC4ACF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenThread + 6                                        77DC4B1A 4 Bytes  [68, 01, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenThread + B                                        77DC4B1F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenThreadToken + 6                                   77DC4B2A 4 Bytes  [68, 02, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenThreadToken + B                                   77DC4B2F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtOpenThreadTokenEx + B                                 77DC4B3F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtQueryAttributesFile + 6                               77DC4BCA 4 Bytes  [A8, 00, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtQueryAttributesFile + B                               77DC4BCF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtQueryFullAttributesFile + B                           77DC4C7F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtSetInformationFile + 6                                77DC515A 4 Bytes  [28, 01, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtSetInformationFile + B                                77DC515F 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtSetInformationThread + 6                              77DC51AA 4 Bytes  [28, 02, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtSetInformationThread + B                              77DC51AF 1 Byte  [E2]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 1 Byte  [68]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtUnmapViewOfSection + 6                                77DC544A 4 Bytes  [68, 03, 26, 00]
.text     C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] ntdll.dll!NtUnmapViewOfSection + B                                77DC544F 1 Byte  [E2]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT       \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                                                     [C8491F12] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT       \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong]                                                                     [C8492232] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT       \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                                                      [C8491730] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT       \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                                              [C84920F0] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT       \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort]                                                                     [C8491856] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT       \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                                               [C8491914] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT       \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                                                            [C84A5EB0] \SystemRoot\System32\Drivers\sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)

---- User IAT/EAT - GMER 1.0.15 ----

IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                          [74CC7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                           [74D0B4E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                       [74CCBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                 [74CBF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                           [74CC75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                        [74CBE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                            [74CF73F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                               [74CCDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                       [74CBFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                        [74CBFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                         [74CB71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                                 [74D4CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                    [74CEC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                       [74CBD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                 [74CB6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                [74CB687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Windows\Explorer.EXE[376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                   [74CC2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT       C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[2132] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  00010010
IAT       C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3776] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  00010010
IAT       C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3792] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  00010010
IAT       C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3864] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  00010010
IAT       C:\Users\Gebruiker\AppData\Local\Google\Chrome\Application\chrome.exe[3904] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  00010010

---- Devices - GMER 1.0.15 ----

Device    \FileSystem\Ntfs \Ntfs                                                                                                                        C295E1E8
Device    \Driver\netbt \Device\NetBT_Tcpip_{473ED2F3-9CB5-42B7-A913-FEB5FA80FA58}                                                                      C48071E8
Device    \Driver\PCI_PNP5458 \Device\00000043                                                                                                          sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
Device    \Driver\PCI_PNP5458 \Device\00000043                                                                                                          sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
Device    \Driver\usbohci \Device\USBPDO-0                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBPDO-1                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBPDO-2                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBPDO-3                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBPDO-4                                                                                                              C45341E8
Device    \Driver\usbehci \Device\USBPDO-5                                                                                                              C4535430
Device    \Driver\cdrom \Device\CdRom0                                                                                                                  C44401E8
Device    \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0                                                                                                   C295D1E8
Device    \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3                                                                                                   C295D1E8
Device    \Driver\atapi \Device\Ide\IdePort0                                                                                                            C295D1E8
Device    \Driver\atapi \Device\Ide\IdePort1                                                                                                            C295D1E8
Device    \Driver\atapi \Device\Ide\IdePort2                                                                                                            C295D1E8
Device    \Driver\atapi \Device\Ide\IdePort3                                                                                                            C295D1E8
Device    \Driver\netbt \Device\NetBt_Wins_Export                                                                                                       C48071E8
Device    \Driver\Smb \Device\NetbiosSmb                                                                                                                C46E2430
Device    \Driver\iScsiPrt \Device\RaidPort0                                                                                                            C45561E8
Device    \Driver\usbohci \Device\USBFDO-0                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBFDO-1                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBFDO-2                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBFDO-3                                                                                                              C45341E8
Device    \Driver\usbohci \Device\USBFDO-4                                                                                                              C45341E8
Device    \Driver\usbehci \Device\USBFDO-5                                                                                                              C4535430
Device    \Driver\aniectil \Device\Scsi\aniectil1                                                                                                       C441A1E8
Device    \FileSystem\cdfs \Cdfs                                                                                                                        C4F3E1E8

---- Registry - GMER 1.0.15 ----

Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                          
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                               C:\Program Files\DAEMON Tools Lite\
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                               0x00 0x00 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                               0
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                            0xB2 0x23 0xB0 0xA5 ...
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)                                 
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                                                      0x20 0x01 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                                                   0xA1 0xF7 0x49 0xDA ...
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)                            
Reg       HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                                              0x7C 0x91 0x8F 0x42 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                          
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                               C:\Program Files\DAEMON Tools Lite\
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                               0x00 0x00 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                               0
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                            0xB2 0x23 0xB0 0xA5 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)                                 
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                                                      0x20 0x01 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                                                   0xFC 0xAC 0xEE 0xCB ...
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)                            
Reg       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                                              0xDB 0x7C 0xF5 0x9E ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                              
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                           C:\Program Files\DAEMON Tools Lite\
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                           0x00 0x00 0x00 0x00 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                           0
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                        0xB2 0x23 0xB0 0xA5 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                                                     
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                                                  0x20 0x01 0x00 0x00 ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                                               0xFC 0xAC 0xEE 0xCB ...
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                                                
Reg       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                                          0xDB 0x7C 0xF5 0x9E ...
Reg       HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install                                                
Reg       HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs                                           
Reg       HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs@CTE_32 Name                               2455503:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install                                                                                        
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{8C3B52F4-7923-ED8A-218E-2462D7FA8F52}                                           
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{8C3B52F4-7923-ED8A-218E-2462D7FA8F52}\Version 1.1                               
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{8C3B52F4-7923-ED8A-218E-2462D7FA8F52}\Version 1.1@dat                           806585365:{0451132E-7AC3-8CF9-3B99-4CF55517DF90}
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System                                                                                         
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG14.00.00.01PROFESSIONAL                                                         160E0828BEFC558AF28684D7D40414AAFE282A9CC6C9057D68E63037A9E6AB7D2233590AC7385A126E674832C9C76171B4B61630B850960F2ABA43A74E46AA254F8771A116FBCBC0AFCF70F0DD4C9AE5811D9A1375DBF0458C1904B0C162F0FB605E712919116FE6DEE4AB26F5FAA4039372154EF8163362DF289AF8B54779AFEB9170FCD885BB3CF7D01C0B8FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5C8EDD5E5BE2F6E667C038D530D6EB3452A38793D2848D126B1AE0D41379E0905FF7176023711B1B3A8941651577E359A5767FCD4C6D73176ADC1B5647311A24DC7FFC313B521F3722066DB5F75CED6FBC4B3122242A925BF0BB6774C3CA04146FC2BE448F7EC3E7DEC97CBBA1B44895A0464E186BA938147DDC73BB7A0A7A708B07294F992892B6F65AF67731C3476C0ECF40180462269BA1A8A59D3633CC6B37D7BFEDA785864E09041E4F9851B439D613A0ED27CB136F054C16731310BDDC0E02B6A05AD18FFEC3D5E3899E294E65DE0140CDDF63293260B81275816E84BDBE98F64BA8CC91BC6C23ECD2DE1B44FB224D22CB8EA906A803A498C247A0CA2E0E712033DCB6E5205A0216BCC8F93B2FAAF0FC61E5A2BCBD4F865FDDFBFA3172D1A681851258576379CEEC3A9B9ECDD41CA7BEE
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{52FE633D-BB0E-2E06-B4FE-B489D587661B}                                                         
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{52FE633D-BB0E-2E06-B4FE-B489D587661B}\Install                                                 
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{52FE633D-BB0E-2E06-B4FE-B489D587661B}\Install\xga-3                                           
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{52FE633D-BB0E-2E06-B4FE-B489D587661B}\Install\xga-3\dat                                       
Reg       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{52FE633D-BB0E-2E06-B4FE-B489D587661B}\Install\xga-3\dat@default                               518022161:{64D9ACF1-C796-BEFD-4D07-EDE79A50D990}
Reg       HKLM\SOFTWARE\Microsoft\Windows Install VBX                                                                                                   
Reg       HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current                                                                                           
Reg       HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install                                                                                   
Reg       HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{8C3B52F4-7923-ED8A-218E-2462D7FA8F52}                                      
Reg       HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{8C3B52F4-7923-ED8A-218E-2462D7FA8F52}\Version 3.x                          
Reg       HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{8C3B52F4-7923-ED8A-218E-2462D7FA8F52}\Version 3.x@dat                      1767914624:{CE6B50C6-A698-B17D-58EE-48DB0A200568}
Reg       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smase._dll                                                     
Reg       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smase._dll@AplicationGoo                                       28??a2?253d???6761?
Reg       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smase._dll@ChkAppHelp                                          {A2DEBB11-1DFA-FD98-3353-5A3C7446E960}
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Najdluzsza Podróz                                                      
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Najdluzsza Podróz@SlowInfoCache                                        0x28 0x02 0x00 0x00 ...
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Najdluzsza Podróz@Changed                                              0

---- Files - GMER 1.0.15 ----

File      C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Cache\f_005f30                                                               30449 bytes
File      C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0061cf                                                               40193 bytes

---- EOF - GMER 1.0.15 ----
