GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-19 21:26:36
Windows 5.1.2600 Dodatek Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\system32\windev-55df-2c97.sys ZwEnumerateKey <-- ROOTKIT !
SSDT \??\C:\WINDOWS\system32\windev-55df-2c97.sys ZwEnumerateValueKey <-- ROOTKIT !
SSDT \??\C:\WINDOWS\system32\windev-55df-2c97.sys ZwQueryDirectoryFile <-- ROOTKIT !
---- Kernel code sections - GMER 1.0.12 ----
? C:\WINDOWS\System32\DRIVERS\update.sys
---- Devices - GMER 1.0.12 ----
Device \Driver\aswTdi \Device\AswUdpFilter IRP_MJ_DEVICE_CONTROL [F3E6C7A0] windev-55df-2c97.sys
Device \Driver\aswTdi \Device\ASWTDI IRP_MJ_DEVICE_CONTROL [F3E6C7A0] windev-55df-2c97.sys
Device \Driver\aswTdi \Device\AswTcpFilter IRP_MJ_DEVICE_CONTROL [F3E6C7A0] windev-55df-2c97.sys
---- Services - GMER 1.0.12 ----
Service C:\WINDOWS\system32\windev-55df-2c97.sys ( ***hidden*** ) [AUTO] windev-55df-2c97 <-- ROOTKIT !
---- Registry - GMER 1.0.12 ----
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97@NextInstance 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@Service windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@DeviceDesc windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000\Control@ActiveService windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@Service windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@DeviceDesc windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-55DF-2C97@NextInstance 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@Start 2
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97\Enum@0 Root\LEGACY_WINDEV-55DF-2C97\0000
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-55DF-2C97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-55DF-2C97@NextInstance 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@Service windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@DeviceDesc windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-55DF-2C97@NextInstance 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@Start 2
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet003\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97@NextInstance 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@Service windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@DeviceDesc windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000\Control@ActiveService windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@Service windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97\0000@DeviceDesc windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-55DF-2C97@NextInstance 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@Start 2
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@ErrorControl 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@DisplayName windev-55df-2c97
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97\Enum@0 Root\LEGACY_WINDEV-55DF-2C97\0000
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@ImagePath \??\C:\WINDOWS\system32\windev-55df-2c97.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-55df-2c97@DisplayName windev-55df-2c97
---- Files - GMER 1.0.12 ----
File C:\WINDOWS\system32\windev-55df-2c97.sys <-- ROOTKIT !
File C:\WINDOWS\system32\windev-peers.ini
ADS D:\muzyka\Nowy folder\Sumptuastic - Ju:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS D:\muzyka\Nowy folder\Sumptuastic - Moja si:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS D:\muzyka\Nowy folder\Sumptuastic - Zanim za:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS D:\Tapety i zdjecia\Filmiki i fotki z Madzi:SummaryInformation
ADS D:\Tapety i zdjecia\Filmiki i fotki z Madzi:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
---- EOF - GMER 1.0.12 ----
[/code]
[color=darkblue][size=75]Złączono Posta: 19.05.2007 (Sob) 21:32[/size][/color]
usługi + pokazuj wszytsko
GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-19 21:29:25
Windows 5.1.2600 Dodatek Service Pack 2
---- Services - GMER 1.0.12 ----
Service [sYSTEM] Aavmker4
Service [DISABLED] Abiosdsk
Service [DISABLED] abp480n5
Service C:\WINDOWS\System32\DRIVERS\ACPI.sys [bOOT] ACPI
Service [DISABLED] ACPIEC
Service [DISABLED] adpu160m
Service C:\WINDOWS\system32\drivers\aec.sys [MANUAL] aec
Service C:\WINDOWS\System32\drivers\afd.sys [sYSTEM] AFD
Service [DISABLED] Aha154x
Service [DISABLED] aic78u2
Service [DISABLED] aic78xx
Service C:\WINDOWS\System32\svchost.exe [AUTO] Alerter
Service C:\WINDOWS\System32\alg.exe [MANUAL] ALG
Service [DISABLED] AliIde
Service C:\WINDOWS\System32\DRIVERS\amdk7.sys [sYSTEM] AmdK7
Service [DISABLED] amsint
Service C:\WINDOWS\system32\svchost.exe [MANUAL] AppMgmt
Service [DISABLED] asc
Service [DISABLED] asc3350p
Service [DISABLED] asc3550
Service [AUTO] aswMon2
Service [sYSTEM] aswTdi
Service C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [AUTO] aswUpdSv
Service C:\WINDOWS\System32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac
Service C:\WINDOWS\System32\DRIVERS\atapi.sys [bOOT] atapi
Service [DISABLED] Atdisk
Service C:\WINDOWS\System32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] AudioSrv
Service C:\WINDOWS\System32\DRIVERS\audstub.sys [MANUAL] audstub
Service C:\Program Files\Alwil Software\Avast4\ashServ.exe [AUTO] avast! Antivirus
Service BattC
Service [sYSTEM] Beep
Service C:\WINDOWS\System32\svchost.exe [DISABLED] BITS
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Browser
Service [DISABLED] cbidf2k
Service [DISABLED] cd20xrnt
Service [sYSTEM] Cdaudio
Service [DISABLED] Cdfs
Service C:\WINDOWS\System32\DRIVERS\cdrom.sys [sYSTEM] Cdrom
Service [sYSTEM] Changer
Service C:\WINDOWS\system32\cisvc.exe [DISABLED] CiSvc
Service C:\WINDOWS\system32\clipsrv.exe [DISABLED] ClipSrv
Service [DISABLED] CmdIde
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] COMSysApp
Service ContentFilter
Service ContentIndex
Service [DISABLED] Cpqarray
Service C:\WINDOWS\system32\svchost.exe [AUTO] CryptSvc
Service C:\WINDOWS\System32\drivers\ctac32k.sys [MANUAL] ctac32k
Service C:\WINDOWS\system32\drivers\ctaud2k.sys [MANUAL] ctaud2k
Service System32\drivers\ctdvda2k.sys [MANUAL] ctdvda2k
Service C:\WINDOWS\System32\DRIVERS\ctljystk.sys [MANUAL] ctljystk
Service C:\WINDOWS\System32\drivers\ctprxy2k.sys [MANUAL] ctprxy2k
Service C:\WINDOWS\System32\drivers\ctsfm2k.sys [MANUAL] ctsfm2k
Service [DISABLED] dac2w2k
Service [DISABLED] dac960nt
Service C:\WINDOWS\system32\svchost.exe [AUTO] DcomLaunch
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dhcp
Service C:\WINDOWS\System32\DRIVERS\disk.sys [bOOT] Disk
Service C:\Program Files\Executive Software\DiskeeperLite\DKService.exe [MANUAL] Diskeeper
Service C:\WINDOWS\System32\dmadmin.exe [MANUAL] dmadmin
Service C:\WINDOWS\System32\drivers\dmboot.sys [DISABLED] dmboot
Service C:\WINDOWS\System32\drivers\dmio.sys [bOOT] dmio
Service C:\WINDOWS\System32\drivers\dmload.sys [bOOT] dmload
Service C:\WINDOWS\System32\svchost.exe [MANUAL] dmserver
Service C:\WINDOWS\system32\drivers\DMusic.sys [MANUAL] DMusic
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dnscache
Service [DISABLED] dpti2o
Service C:\WINDOWS\system32\drivers\drmkaud.sys [MANUAL] drmkaud
Service C:\WINDOWS\System32\drivers\emupia2k.sys [MANUAL] emupia
Service C:\WINDOWS\System32\svchost.exe [DISABLED] ERSvc
Service C:\WINDOWS\system32\services.exe [AUTO] Eventlog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] EventSystem
Service [DISABLED] Fastfat
Service C:\WINDOWS\System32\svchost.exe [DISABLED] FastUserSwitchingCompatibility
Service C:\WINDOWS\System32\DRIVERS\fdc.sys [MANUAL] Fdc
Service [sYSTEM] Fips
Service C:\WINDOWS\System32\DRIVERS\flpydisk.sys [MANUAL] Flpydisk
Service C:\WINDOWS\system32\drivers\fltmgr.sys [bOOT] FltMgr
Service [sYSTEM] Fs_Rec
Service C:\WINDOWS\System32\DRIVERS\ftdisk.sys [bOOT] Ftdisk
Service C:\WINDOWS\System32\DRIVERS\gameenum.sys [MANUAL] gameenum
Service C:\WINDOWS\System32\DRIVERS\gmer.sys [MANUAL] gmer
Service C:\WINDOWS\System32\DRIVERS\msgpc.sys [MANUAL] Gpc
Service C:\WINDOWS\system32\drivers\ha10kx2k.sys [MANUAL] ha10kx2k
Service C:\WINDOWS\System32\drivers\hap16v2k.sys [MANUAL] hap16v2k
Service C:\WINDOWS\System32\svchost.exe [DISABLED] helpsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] HidServ
Service [DISABLED] hpn
Service C:\WINDOWS\System32\Drivers\HTTP.sys [MANUAL] HTTP
Service C:\WINDOWS\System32\svchost.exe [MANUAL] HTTPFilter
Service [sYSTEM] i2omgmt
Service [DISABLED] i2omp
Service C:\WINDOWS\System32\DRIVERS\i8042prt.sys [sYSTEM] i8042prt
Service C:\WINDOWS\System32\DRIVERS\imapi.sys [sYSTEM] Imapi
Service C:\WINDOWS\System32\imapi.exe [MANUAL] ImapiService
Service inetaccs
Service [DISABLED] ini910u
Service Inport
Service [DISABLED] IntelIde
Service C:\WINDOWS\system32\drivers\ip6fw.sys [MANUAL] ip6fw
Service C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver
Service C:\WINDOWS\System32\DRIVERS\ipinip.sys [MANUAL] IpInIp
Service C:\WINDOWS\System32\DRIVERS\ipnat.sys [MANUAL] IpNat
Service C:\WINDOWS\System32\DRIVERS\ipsec.sys [sYSTEM] IPSec
Service C:\WINDOWS\System32\DRIVERS\irenum.sys [MANUAL] IRENUM
Service ISAPISearch
Service C:\WINDOWS\System32\DRIVERS\isapnp.sys [bOOT] isapnp
Service C:\WINDOWS\System32\DRIVERS\kbdclass.sys [sYSTEM] Kbdclass
Service C:\WINDOWS\system32\drivers\kmixer.sys [MANUAL] kmixer
Service [bOOT] KSecDD
Service C:\WINDOWS\System32\svchost.exe [MANUAL] lanmanserver
Service C:\WINDOWS\System32\svchost.exe [MANUAL] lanmanworkstation
Service [sYSTEM] lbrtfdc
Service ldap
Service LicenseService
Service C:\WINDOWS\System32\svchost.exe [DISABLED] LmHosts
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Messenger
Service [sYSTEM] mnmdd
Service C:\WINDOWS\System32\mnmsrvc.exe [DISABLED] mnmsrvc
Service [MANUAL] Modem
Service C:\WINDOWS\System32\DRIVERS\mouclass.sys [sYSTEM] Mouclass
Service [bOOT] MountMgr
Service [DISABLED] mraid35x
Service C:\WINDOWS\System32\DRIVERS\mrxdav.sys [MANUAL] MRxDAV
Service C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [sYSTEM] MRxSmb
Service C:\WINDOWS\System32\msdtc.exe [MANUAL] MSDTC
Service [sYSTEM] Msfs
Service C:\WINDOWS\system32\msiexec.exe [MANUAL] MSIServer
Service C:\WINDOWS\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV
Service C:\WINDOWS\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK
Service C:\WINDOWS\system32\drivers\MSPQM.sys [MANUAL] MSPQM
Service C:\WINDOWS\System32\DRIVERS\mssmbios.sys [MANUAL] mssmbios
Service [bOOT] Mup
Service [bOOT] NDIS
Service C:\WINDOWS\System32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi
Service C:\WINDOWS\System32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio
Service C:\WINDOWS\System32\DRIVERS\ndiswan.sys [MANUAL] NdisWan
Service [MANUAL] NDProxy
Service C:\WINDOWS\System32\DRIVERS\netbios.sys [sYSTEM] NetBIOS
Service C:\WINDOWS\System32\DRIVERS\netbt.sys [MANUAL] NetBT
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDE
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDEdsdm
Service C:\WINDOWS\System32\lsass.exe [DISABLED] Netlogon
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Netman
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Nla
Service [sYSTEM] Npfs
Service [DISABLED] Ntfs
Service C:\WINDOWS\System32\lsass.exe [DISABLED] NtLmSsp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] NtmsSvc
Service [sYSTEM] Null
Service C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [MANUAL] nv
Service C:\WINDOWS\System32\nvsvc32.exe [MANUAL] NVSvc
Service C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt
Service C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd
Service C:\WINDOWS\system32\drivers\ctoss2k.sys [MANUAL] ossrv
Service PageDefrag
Service C:\WINDOWS\System32\DRIVERS\parport.sys [MANUAL] Parport
Service [bOOT] PartMgr
Service [AUTO] ParVdm
Service C:\WINDOWS\System32\DRIVERS\pci.sys [bOOT] PCI
Service [sYSTEM] PCIDump
Service [DISABLED] PCIIde
Service [DISABLED] Pcmcia
Service [MANUAL] PDCOMP
Service [MANUAL] PDFRAME
Service [MANUAL] PDRELI
Service [MANUAL] PDRFRAME
Service [DISABLED] perc2
Service [DISABLED] perc2hib
Service PerfDisk
Service PerfNet
Service PerfOS
Service PerfProc
Service C:\WINDOWS\system32\drivers\PfModNT.sys [AUTO] PfModNT
Service C:\WINDOWS\system32\services.exe [AUTO] PlugPlay
Service C:\WINDOWS\System32\lsass.exe [DISABLED] PolicyAgent
Service C:\WINDOWS\System32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport
Service C:\WINDOWS\System32\DRIVERS\processr.sys [sYSTEM] Processor
Service C:\WINDOWS\system32\lsass.exe [AUTO] ProtectedStorage
Service C:\WINDOWS\System32\DRIVERS\psched.sys [MANUAL] PSched
Service C:\WINDOWS\System32\DRIVERS\ptilink.sys [MANUAL] Ptilink
Service C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [bOOT] PxHelp20
Service [DISABLED] ql1080
Service [DISABLED] Ql10wnt
Service [DISABLED] ql12160
Service [DISABLED] ql1240
Service [DISABLED] ql1280
Service [AUTO] QTYHRWSH
Service C:\WINDOWS\System32\DRIVERS\rasacd.sys [sYSTEM] RasAcd
Service C:\WINDOWS\System32\svchost.exe [DISABLED] RasAuto
Service C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasMan
Service C:\WINDOWS\System32\DRIVERS\raspppoe.sys [MANUAL] RasPppoe
Service C:\WINDOWS\System32\DRIVERS\raspti.sys [MANUAL] Raspti
Service C:\WINDOWS\System32\DRIVERS\rdbss.sys [sYSTEM] Rdbss
Service C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [sYSTEM] RDPCDD
Service RDPDD
Service C:\WINDOWS\System32\DRIVERS\rdpdr.sys [MANUAL] rdpdr
Service RDPNP
Service [MANUAL] RDPWD
Service C:\WINDOWS\system32\sessmgr.exe [DISABLED] RDSessMgr
Service C:\WINDOWS\System32\DRIVERS\redbook.sys [sYSTEM] redbook
Service C:\WINDOWS\System32\svchost.exe [DISABLED] RemoteAccess
Service C:\WINDOWS\system32\svchost.exe [DISABLED] RemoteRegistry
Service RPCKDM
Service C:\WINDOWS\System32\locator.exe [MANUAL] RpcLocator
Service C:\WINDOWS\system32\svchost.exe [AUTO] RpcSs
Service C:\WINDOWS\System32\rsvp.exe [DISABLED] RSVP
Service C:\WINDOWS\System32\DRIVERS\RTL8180.SYS [MANUAL] rtl8180
Service C:\WINDOWS\system32\lsass.exe [AUTO] SamSs
Service C:\WINDOWS\System32\SCardSvr.exe [DISABLED] SCardSvr
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Schedule
Service ScsiPort
Service C:\WINDOWS\System32\DRIVERS\secdrv.sys [MANUAL] Secdrv
Service C:\WINDOWS\System32\svchost.exe [DISABLED] seclogon
Service C:\WINDOWS\system32\svchost.exe [AUTO] SENS
Service C:\WINDOWS\System32\DRIVERS\serenum.sys [MANUAL] serenum
Service C:\WINDOWS\System32\DRIVERS\serial.sys [sYSTEM] Serial
Service [sYSTEM] Sfloppy
Service C:\WINDOWS\system32\svchost.exe [AUTO] SharedAccess
Service C:\WINDOWS\System32\svchost.exe [AUTO] ShellHWDetection
Service [DISABLED] Simbad
Service [DISABLED] Sparrow
Service C:\WINDOWS\system32\drivers\splitter.sys [MANUAL] splitter
Service C:\WINDOWS\system32\spoolsv.exe [DISABLED] Spooler
Service C:\WINDOWS\System32\DRIVERS\sr.sys [DISABLED] sr
Service C:\WINDOWS\System32\svchost.exe [AUTO] srservice
Service C:\WINDOWS\System32\DRIVERS\srv.sys [MANUAL] Srv
Service C:\WINDOWS\System32\svchost.exe [DISABLED] SSDPSRV
Service C:\WINDOWS\System32\svchost.exe [DISABLED] stisvc
Service C:\WINDOWS\System32\DRIVERS\swenum.sys [MANUAL] swenum
Service C:\WINDOWS\system32\drivers\swmidi.sys [MANUAL] swmidi
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] SwPrv
Service swwd
Service [DISABLED] symc810
Service [DISABLED] symc8xx
Service [DISABLED] sym_hi
Service [DISABLED] sym_u3
Service C:\WINDOWS\system32\drivers\sysaudio.sys [MANUAL] sysaudio
Service C:\WINDOWS\system32\smlogsvc.exe [DISABLED] SysmonLog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TapiSrv
Service C:\WINDOWS\System32\DRIVERS\tcpip.sys [sYSTEM] Tcpip
Service [MANUAL] TDPIPE
Service [MANUAL] TDTCP
Service C:\WINDOWS\System32\DRIVERS\termdd.sys [sYSTEM] TermDD
Service C:\WINDOWS\System32\svchost.exe [DISABLED] TermService
Service C:\WINDOWS\System32\svchost.exe [AUTO] Themes
Service C:\WINDOWS\System32\tlntsvr.exe [DISABLED] TlntSvr
Service [DISABLED] TosIde
Service C:\WINDOWS\system32\svchost.exe [MANUAL] TrkWks
Service TSDDD
Service [DISABLED] Udfs
Service [DISABLED] ultra
Service C:\WINDOWS\system32\wdfmgr.exe [DISABLED] UMWdf
Service C:\WINDOWS\System32\DRIVERS\update.sys [MANUAL] Update
Service C:\WINDOWS\System32\svchost.exe [DISABLED] upnphost
Service C:\WINDOWS\System32\ups.exe [DISABLED] UPS
Service C:\WINDOWS\System32\DRIVERS\usbehci.sys [MANUAL] usbehci
Service C:\WINDOWS\System32\DRIVERS\usbhub.sys [MANUAL] usbhub
Service C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR
Service C:\WINDOWS\System32\DRIVERS\usbuhci.sys [MANUAL] usbuhci
Service C:\WINDOWS\System32\drivers\vga.sys [sYSTEM] VgaSave
Service C:\WINDOWS\system32\DRIVERS\viaagp1.sys [bOOT] viaagp1
Service C:\WINDOWS\System32\DRIVERS\viaide.sys [bOOT] ViaIde
Service [bOOT] VolSnap
Service C:\WINDOWS\System32\vssvc.exe [DISABLED] VSS
Service VXD
Service C:\WINDOWS\System32\svchost.exe [DISABLED] W32Time
Service W3SVC
Service C:\WINDOWS\System32\DRIVERS\wanarp.sys [MANUAL] Wanarp
Service [MANUAL] WDICA
Service C:\WINDOWS\system32\drivers\wdmaud.sys [MANUAL] wdmaud
Service C:\WINDOWS\System32\svchost.exe [DISABLED] WebClient
Service C:\WINDOWS\system32\wfquvbmb.vvc [AUTO] WFQUVBMB
Service C:\WINDOWS\system32\wincom32.sys [AUTO] wincom32
Service C:\WINDOWS\system32\windev-55df-2c97.sys (*** hidden *** ) [AUTO] windev-55df-2c97 <-- ROOTKIT
Service C:\WINDOWS\system32\svchost.exe [AUTO] winmgmt
Service [MANUAL] Winsock
Service WinSock2
Service WinTrust
Service C:\WINDOWS\system32\MsPMSPSv.exe [DISABLED] WMDM PMSP Service
Service C:\WINDOWS\System32\svchost.exe [DISABLED] WmdmPmSN
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Wmi
Service WmiApRpl
Service C:\WINDOWS\System32\wbem\wmiapsrv.exe [MANUAL] WmiApSrv
Service C:\WINDOWS\System32\drivers\ws2ifsl.sys [DISABLED] WS2IFSL
Service C:\WINDOWS\System32\svchost.exe [AUTO] wscsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] wuauserv
Service C:\WINDOWS\System32\svchost.exe [AUTO] WZCSVC
Service C:\WINDOWS\System32\svchost.exe [MANUAL] xmlprov
Service {36AE7FDD-8C9D-499F-BE75-88E9CD982069}
---- EOF - GMER 1.0.12 ----