GMER 1.0.12.11889 -
http://www.gmer.net
Rootkit scan 2006-11-23 07:11:08
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- User code sections - GMER 1.0.12 ----
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00BF5B5A
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BF5D3A
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BF5EB0
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BF61EE
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BF60ED
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00BF5FC3
.text C:\WINDOWS\SYSTEM32\winlogon.exe[652] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00BF5C2D
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00A87600
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 009D5D3A
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 009D5EB0
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009D61EE
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009D60ED
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 009D5FC3
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtResumeThread 7C90E45F 5 Bytes JMP 00A87650
.text C:\WINDOWS\explorer.exe[1288] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 009D5C2D
.text C:\WINDOWS\explorer.exe[1288] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10003E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00875B5A
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00875D3A
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00875EB0
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008761EE
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008760ED
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00875FC3
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00875C2D
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe[2068] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00923E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C5B5A
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 008C5D3A
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 008C5EB0
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C61EE
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008C60ED
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 008C5FC3
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C5C2D
.text C:\PROGRA~1\McAfee.com\Agent\mcagent.exe[2084] WS2_32.dll!connect 71AB406A 5 Bytes JMP 016E3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 003A5B5A
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 003A5D3A
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 003A5EB0
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003A61EE
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 003A60ED
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 003A5FC3
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 003A5C2D
.text C:\PROGRA~1\McAfee.com\MPS\mscifapp.exe[2108] WS2_32.dll!connect 71AB406A 5 Bytes JMP 01FD3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00895B5A
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00895D3A
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00895EB0
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008961EE
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008960ED
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00895FC3
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00895C2D
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[2128] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00943E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00865B5A
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00865D3A
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00865EB0
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008661EE
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008660ED
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00865FC3
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00865C2D
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[2136] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00913E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 003C5B5A
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 003C5D3A
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 003C5EB0
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003C61EE
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 003C60ED
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 003C5FC3
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 003C5C2D
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[2144] WS2_32.dll!connect 71AB406A 5 Bytes JMP 02313E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00AE5B5A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00AE5D3A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00AE5EB0
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00AE61EE
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00AE60ED
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00AE5FC3
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00AE5C2D
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[2152] WS2_32.dll!connect 71AB406A 5 Bytes JMP 01363E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00955B5A
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00955D3A
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00955EB0
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009561EE
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009560ED
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00955FC3
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00955C2D
.text C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe[2160] WS2_32.dll!connect 71AB406A 5 Bytes JMP 009E3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00925B5A
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00925D3A
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00925EB0
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009261EE
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009260ED
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00925FC3
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00925C2D
.text C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe[2176] WS2_32.dll!connect 71AB406A 5 Bytes JMP 009B3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00965B5A
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00965D3A
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00965EB0
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009661EE
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009660ED
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00965FC3
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00965C2D
.text C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe[2184] WS2_32.dll!connect 71AB406A 5 Bytes JMP 02933E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00385B5A
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00385D3A
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00385EB0
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003861EE
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 003860ED
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00385FC3
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00385C2D
.text C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe[2192] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10003E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00275B5A
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00275D3A
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00275EB0
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 002761EE
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 002760ED
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00275FC3
.text C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe[2208] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00275C2D
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00885B5A
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00885D3A
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00885EB0
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008861EE
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008860ED
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00885FC3
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00885C2D
.text C:\WINDOWS\SYSTEM32\hkcmd.exe[2224] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00933E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00875B5A
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00875D3A
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00875EB0
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008761EE
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008760ED
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00875FC3
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00875C2D
.text C:\WINDOWS\SYSTEM32\igfxpers.exe[2232] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00923E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00395B5A
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00395D3A
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00395EB0
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003961EE
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 003960ED
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 00395FC3
.text C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe[2240] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00395C2D
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 003A5B5A
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 003A5D3A
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 003A5EB0
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003A61EE
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 003A60ED
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 003A5FC3
.text C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe[2760] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 003A5C2D
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[3548] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00EA3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\SYSTEM32\igfxsrvc.exe[3840] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00D73E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008F5B5A
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 008F5D3A
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 008F5EB0
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008F61EE
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 008F60ED
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtQueryValueKey 7C90E1FE 5 Bytes JMP 008F5FC3
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008F5C2D
.text C:\Documents and Settings\Rick\Desktop\gmer.exe[4032] WS2_32.dll!connect 71AB406A 5 Bytes JMP 012D3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE EF296C8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE EF2937C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ EF28F60A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE EF28FAED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION EF29A958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION EF29D821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA EF2A638A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA EF2A5D49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS EF29FBBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION EF2A0331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION EF2AE4F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL EF296B37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL EF292948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL EF29C46B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN EF2AD79D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL EF2ACC4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP EF2932FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP EF2AD1DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible EF2A81F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F049A701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F049A701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F049A701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F049A701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F049A701] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [F049A89D] tfsnifs.sys
---- Registry - GMER 1.0.12 ----
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{8CBB57C9-9D9A-4BDF-99F2-91DE0D6A1048}
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins@}0F798E0C3F81-127B-6594-0B61-0B81FDB3{ 0x25 0x4A 0x00 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins@}4C3F80904BD4-4ED8-E834-2E2E-5A6392B7{ 0x05 0x30 0x00 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins@mulmd 0x6D 0x0C 0x00 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@dmlum.exe C:\WINDOWS\system32\dmlum.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@dmlum.exe C:\WINDOWS\system32\dmlum.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion@rzdsc 0xC9 0x57 0xBB 0x8C ...
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@system csdzr.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@system csdzr.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@system csdzr.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@system csdzr.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@system csdzr.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@system csdzr.exe
Reg \Registry\USER\S-1-5-21-4286219616-3432336093-1662344221-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\WINDOWS\system32\dmiap.exe dmiap
---- Files - GMER 1.0.12 ----
ADS C:\Documents and Settings\Rick\Desktop\Hijackthis\NoHiding.exe.exe:SummaryInformation
ADS C:\Documents and Settings\Rick\Desktop\Hijackthis\NoHiding.exe.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Program Files\Doras 3-D Driving Adventure\dorarace.exe:{0156560E-1815-FA3F-E64D-8C05FEA2BA59}
File C:\WINDOWS\SYSTEM32\csdzr.exe
File C:\WINDOWS\SYSTEM32\dmlum.exe
---- EOF - GMER 1.0.12 ----