GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-28 01:23:19
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 85F44068 ZwEnumerateKey
Code 85EE7068 ZwFlushInstructionCache
Code 85F2E066 IofCallDriver
Code 85F73066 IofCompleteRequest
Code 85EFF065 ZwSaveKey
Code 85E72065 ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 85F2E06B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 85F7306B
.text ntkrnlpa.exe!ZwSaveKey 80500D68 5 Bytes JMP 85EFF06A
.text ntkrnlpa.exe!ZwSaveKeyEx 80500D7C 5 Bytes JMP 85E7206A
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 85EE706C
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 5 Bytes JMP 85F4406C
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\wbem\unsecapp.exe[144] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FE000A
.text C:\WINDOWS\system32\wbem\unsecapp.exe[144] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FF000A
.text C:\WINDOWS\System32\alg.exe[152] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B1000A
.text C:\WINDOWS\System32\alg.exe[152] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00B2000A
.text C:\Program Files\Internet Explorer\iexplore.exe[436] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FB000A
.text C:\Program Files\Internet Explorer\iexplore.exe[436] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FC000A
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[436] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10012230
.text C:\Program Files\Internet Explorer\iexplore.exe[436] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10012070
.text C:\Program Files\Internet Explorer\iexplore.exe[436] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10012050
.text C:\Program Files\Internet Explorer\iexplore.exe[436] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10012030
.text C:\Program Files\Internet Explorer\iexplore.exe[436] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 0107000A
.text C:\Program Files\Internet Explorer\iexplore.exe[436] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 0118000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[484] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BD000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[484] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00C0000A
.text C:\Program Files\Java\jre6\bin\java.exe[552] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00CC000A
.text C:\Program Files\Java\jre6\bin\java.exe[552] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00CD000A
.text C:\WINDOWS\system32\winlogon.exe[680] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0096000A
.text C:\WINDOWS\system32\winlogon.exe[680] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0097000A
.text C:\WINDOWS\system32\services.exe[728] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00A6000A
.text C:\WINDOWS\system32\services.exe[728] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00A7000A
.text C:\WINDOWS\system32\lsass.exe[740] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00AD000A
.text C:\WINDOWS\system32\lsass.exe[740] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00B0000A
.text C:\Documents and Settings\K\Desktop\kj26ptdp.exe[1064] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EC000A
.text C:\Documents and Settings\K\Desktop\kj26ptdp.exe[1064] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00ED000A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1272] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00F5000A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1272] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\spoolsv.exe[1320] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D6000A
.text C:\WINDOWS\system32\spoolsv.exe[1320] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00D7000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1448] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BB000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1448] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BC000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1464] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BF000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1464] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00C0000A
.text C:\Program Files\Java\jre6\bin\jqs.exe[1504] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BC000A
.text C:\Program Files\Java\jre6\bin\jqs.exe[1504] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BD000A
.text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1560] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E2000A
.text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1560] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E3000A
.text C:\WINDOWS\Explorer.EXE[1604] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00DE000A
.text C:\WINDOWS\Explorer.EXE[1604] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\IoctlSvc.exe[1608] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BA000A
.text C:\WINDOWS\system32\IoctlSvc.exe[1608] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00BB000A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1644] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00A3000A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1644] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00A4000A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1684] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E5000A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[1684] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E6000A
.text C:\WINDOWS\system32\wdfmgr.exe[1732] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 009F000A
.text C:\WINDOWS\system32\wdfmgr.exe[1732] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00A0000A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2100] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FD000A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2100] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FE000A
.text C:\WINDOWS\RTHDCPL.EXE[2108] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 01F9000A
.text C:\WINDOWS\RTHDCPL.EXE[2108] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 01FA000A
.text C:\WINDOWS\system32\igfxpers.exe[2156] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E3000A
.text C:\WINDOWS\system32\igfxpers.exe[2156] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E4000A
.text C:\Program Files\Battery Meter\BTMeter.exe[2196] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0104000A
.text C:\Program Files\Battery Meter\BTMeter.exe[2196] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0105000A
.text C:\Program Files\Wireless Select Switch\WLSS.exe[2236] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EC000A
.text C:\Program Files\Wireless Select Switch\WLSS.exe[2236] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00ED000A
.text C:\WINDOWS\system32\igfxsrvc.exe[2276] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E4000A
.text C:\WINDOWS\system32\igfxsrvc.exe[2276] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E5000A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2300] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E5000A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2300] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E6000A
.text C:\Program Files\iTunes\iTunesHelper.exe[2344] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E6000A
.text C:\Program Files\iTunes\iTunesHelper.exe[2344] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E7000A
.text C:\WINDOWS\system32\ctfmon.exe[2404] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D7000A
.text C:\WINDOWS\system32\ctfmon.exe[2404] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00D8000A
.text C:\Program Files\Java\jre6\bin\jusched.exe[2428] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E3000A
.text C:\Program Files\Java\jre6\bin\jusched.exe[2428] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E4000A
.text C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe[2444] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00E0000A
.text C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe[2444] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E1000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2488] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EB000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[2488] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00EC000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2508] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00DF000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2508] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00E0000A
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2528] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0125000A
.text C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2528] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0126000A
.text C:\Documents and Settings\K\K.exe[2584] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0125000A
.text C:\Documents and Settings\K\K.exe[2584] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0126000A
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2836] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D7000A
.text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[2836] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00D8000A
.text C:\Program Files\OpenOffice.org 3\program\soffice.exe[2848] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0155000A
.text C:\Program Files\OpenOffice.org 3\program\soffice.exe[2848] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0156000A
.text C:\Program Files\iPod\bin\iPodService.exe[2928] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C3000A
.text C:\Program Files\iPod\bin\iPodService.exe[2928] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00C4000A
.text C:\Program Files\OpenOffice.org 3\program\soffice.bin[2976] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0286000A
.text C:\Program Files\OpenOffice.org 3\program\soffice.bin[2976] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0287000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FB000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FC000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10012230
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10012070
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10012050
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10012030
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 0107000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3756] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 0118000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FB000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FC000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10012230
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10012070
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10012050
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10012030
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 0107000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3788] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 0118000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FB000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FC000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10012230
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10012070
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10012050
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10012030
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 0107000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3916] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 0118000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00FB000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 00FC000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9261 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DC8A9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED2C4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254254 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E40B6CB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E40B5FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E40B668 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E40B4CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E40B530 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E40B72E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E40B592 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED320 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 10012230
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10012070
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10012050
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10012030
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] WININET.dll!HttpAddRequestHeadersA 3D94D02E 5 Bytes JMP 0107000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3920] WININET.dll!HttpAddRequestHeadersW 3D94FF29 5 Bytes JMP 0118000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[436] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1A7B] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\Iexplore.exe[3756] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1A7B] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3920] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1A7B] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\UACewhmqibivk.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [908] 0x01880000
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----
Before it let me copy this, it informed me with a popup: WARNING !!! GMER has found system modification caused by ROOTKIT activity