Apostate
Topic Starter
I think I got this while on Pirates Bay torrent site. My Firefox had been acting up so I went on IE 8…Oh well, here are the logs:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:17:18.80 on Sun 07/19/2009
Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3006.1841 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\DNA\btdna.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Apostate\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\School\LIT451\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig?hl=en
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\apostate\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: []
mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\HP UT"
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [PrnStatusMX] c:\program files\hewlett-packard\prnstatusmx\PrnStatusMX.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
LSP: bmnet.dll
Trusted Zone: navy.mil
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5471/mcfscan.cab
TCP: NameServer = 85.255.112.168,85.255.112.146
TCP: {0C884745-7C02-4B88-B0E9-E6D62C852DA5} = 85.255.112.168,85.255.112.146
TCP: {879A08F0-5235-4DAC-B437-13FDD3ED1FFA} = [removed],[removed]
TCP: {D506B85D-476D-461D-8154-B2B8F25424F9} = 85.255.112.168,85.255.112.146
================= FIREFOX ===================
FF - ProfilePath - c:\users\apostate\appdata\roaming\mozilla\firefox\profiles\2btyf4cw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\apostate\appdata\local\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-19 130936]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-19 348752]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2008-8-16 13824]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2008-8-16 35840]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2009-5-19 121344]
S3 CAATT;AT&T Con App Svc;c:\program files\at&t\communication manager\ConAppsSvc.exe [2009-5-19 125440]
S3 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\turbine\turbine download manager\TurbineMessageService.exe [2009-4-3 255472]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\turbine\turbine download manager\TurbineNetworkService.exe [2009-4-3 218608]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-4-8 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-4-8 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2009-4-8 23680]
=============== Created Last 30 ================
2009-07-19 18:02 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-07-19 18:02 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-07-19 18:02 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-19 18:02 a-d—– c:\programdata\TEMP
2009-07-19 18:02 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-07-19 18:02 –d—– c:\program files\common files\PC Tools
2009-07-19 18:02 –d—– c:\users\apostate\appdata\roaming\PC Tools
2009-07-19 18:02 –d—– c:\programdata\PC Tools
2009-07-19 18:02 –d—– c:\program files\Spyware Doctor
2009-07-19 18:02 –d—– c:\progra~2\PC Tools
2009-07-19 15:50 48,989 a——- c:\program files\Uninstall.exe
2009-07-15 16:48 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-15 16:48 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-15 16:48 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-15 16:48 10,240 a——- c:\windows\system32\dciman32.dll
2009-06-27 18:56 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-27 18:56 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-27 18:56 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-27 18:56 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-27 18:56 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-27 18:56 11,264 a——- c:\windows\system32\icardres.dll
2009-06-27 18:56 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-27 18:56 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-27 18:51 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-27 18:51 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-27 18:51 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-27 18:51 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-27 18:51 83,968 a——- c:\windows\system32\mscories.dll
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-06-23 18:56 0 a—h— c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-06-23 18:46 –d—– c:\users\apostate\appdata\roaming\Bytemobile
2009-06-23 18:45 –d—– c:\users\apostate\appdata\roaming\Sierra Wireless
2009-06-23 18:43 26,496 a——- c:\windows\system32\drivers\RimSerial.sys
2009-06-23 18:43 –d—– c:\program files\common files\Motorola Shared
2009-06-23 18:42 –d—– c:\program files\common files\PctelEapPeer Authentication
2009-06-23 18:42 –d—– C:\Research in Motion
2009-06-23 18:42 –d—– c:\program files\common files\Research in Motion
2009-06-23 18:42 –d—– c:\programdata\AT&T
2009-06-23 18:42 –d—– c:\program files\Sierra Wireless Inc
2009-06-23 18:42 –d—– c:\program files\AT&T
2009-06-23 18:42 –d—– c:\progra~2\AT&T
2009-06-23 18:39 –d—– c:\program files\Option
2009-06-22 12:07 156 a——- c:\windows\Twunk001.MTX
2009-06-22 12:07 3 a——- c:\windows\Twain001.Mtx
2009-06-22 12:07 0 a——- c:\windows\Twunk002.MTX
==================== Find3M ====================
2009-07-19 18:16 68,276 a——- c:\programdata\nvModes.dat
2009-07-19 18:16 68,276 a——- c:\progra~2\nvModes.dat
2009-06-23 18:45 143,360 a——- c:\windows\inf\infstrng.dat
2009-06-23 18:45 143,360 a——- c:\windows\inf\infstor.dat
2009-06-23 18:45 86,016 a——- c:\windows\inf\infpub.dat
2009-05-19 14:51 719,360 a——- c:\windows\system32\bmutil.dll
2009-05-19 14:51 475,136 a——- c:\windows\system32\bmnet.dll
2009-05-19 14:51 118,784 a——- c:\windows\system32\bmwebcfg.exe
2009-05-19 14:51 8,464 a——- c:\windows\system32\SpOrder.Dll
2009-05-19 14:51 126,976 a——- c:\windows\system32\bmdumpd.bin
2009-05-19 14:50 137,752 a——- c:\windows\system32\PCTIN50.dll
2009-05-19 14:50 32,408 a——- c:\windows\system32\PCTINDIS5.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-05-01 17:02 90,112 a——- c:\windows\system32\dpl100.dll
2009-05-01 17:02 823,296 a——- c:\windows\system32\divx_xx0c.dll
2009-05-01 17:02 823,296 a——- c:\windows\system32\divx_xx07.dll
2009-05-01 17:02 815,104 a——- c:\windows\system32\divx_xx0a.dll
2009-05-01 17:02 811,008 a——- c:\windows\system32\divx_xx16.dll
2009-05-01 17:02 802,816 a——- c:\windows\system32\divx_xx11.dll
2009-05-01 17:02 685,056 a——- c:\windows\system32\DivX.dll
2009-04-30 08:37 293,376 a——- c:\windows\system32\psisdecd.dll
2009-04-30 08:37 428,544 a——- c:\windows\system32\EncDec.dll
2009-04-23 08:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-04-21 07:55 2,033,152 a——- c:\windows\system32\win32k.sys
2009-01-25 15:08 102,364 a——- c:\users\apostate\appdata\roaming\nvModes.dat
2008-06-12 09:08 665,600 a——- c:\windows\inf\drvindex.dat
2008-06-03 01:19 0 a——- c:\users\apostate\appdata\roaming\wklnhst.dat
2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-07-25 16:32 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-07-25 16:32 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-07-25 16:32 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
============= FINISH: 19:17:46.32 ===============
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-19 19:24:38
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x80789282]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x80789474]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x80788F32]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8078967C]
Code 877B0318 ZwEnumerateKey
Code 87846250 ZwFlushInstructionCache
Code 8779F225 IofCallDriver
Code 8743E2BE IofCompleteRequest
Code 8779FBFD ZwSaveKey
Code 877E7485 ZwSaveKeyEx
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!IofCompleteRequest 81E74FE2 5 Bytes JMP 8743E2C3
.text ntkrnlpa.exe!ZwSaveKey 81E91664 5 Bytes JMP 8779FC02
.text ntkrnlpa.exe!ZwSaveKeyEx 81E91678 5 Bytes JMP 877E748A
.text ntkrnlpa.exe!KeSetTimerEx + 43C 81EF3A00 8 Bytes [82, 92, 78, 80, 74, 94, 78, …]
.text ntkrnlpa.exe!KeSetTimerEx + 854 81EF3E18 4 Bytes [32, 8F, 78, 80]
.text ntkrnlpa.exe!KeSetTimerEx + 918 81EF3EDC 4 Bytes [7C, 96, 78, 80] {JL 0xffffffffffffff98; JS 0xffffffffffffff84}
.text ntkrnlpa.exe!IofCallDriver 81EF6F6F 5 Bytes JMP 8779F22A
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\system32\svchost.exe[200] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[200] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[200] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[556] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[556] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[556] KERNEL32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[608] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[608] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\wininit.exe[608] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[620] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[620] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[620] KERNEL32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[652] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\services.exe[652] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[672] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsass.exe[672] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsm.exe[680] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[680] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsm.exe[680] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\winlogon.exe[724] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[724] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\winlogon.exe[724] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[860] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[860] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[860] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[992] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[992] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[992] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1016] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1016] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1016] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\nvvsvc.exe[1056] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1072] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1072] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1140] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1140] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1236] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1236] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1236] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1268] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1268] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] kernel32.dll!CreateThread + 1A 778946E2 4 Bytes CALL 0044AD11 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Windows\System32\spoolsv.exe[1620] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1620] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\spoolsv.exe[1620] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1644] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1644] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1644] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[2060] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[2060] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[2060] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\taskeng.exe[2368] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2368] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\taskeng.exe[2368] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\rundll32.exe[2580] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\rundll32.exe[2580] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\rundll32.exe[2580] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[4036] kernel32.dll!CreateThread + 1A 778946E2 4 Bytes CALL 0044AB89 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!SetWindowsHookExW 761D7B69 5 Bytes JMP 6DAC9271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!CallNextHookEx 761D8C33 5 Bytes JMP 6DABC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!UnhookWindowsHookEx 762008BE 5 Bytes JMP 6DA34284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] ole32.dll!CoCreateInstance 760AE188 5 Bytes JMP 6DACD330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!SetWindowsHookExW 761D7B69 5 Bytes JMP 6DAC9271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!CallNextHookEx 761D8C33 5 Bytes JMP 6DABC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!UnhookWindowsHookEx 762008BE 5 Bytes JMP 6DA34284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] ole32.dll!CoCreateInstance 760AE188 5 Bytes JMP 6DACD330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[4036] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[4036] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000078 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
—- Disk sectors - GMER 1.0.15 —-
Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:17:18.80 on Sun 07/19/2009
Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3006.1841 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\DNA\btdna.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Apostate\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\School\LIT451\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig?hl=en
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\apostate\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: []
mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\HP UT"
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [PrnStatusMX] c:\program files\hewlett-packard\prnstatusmx\PrnStatusMX.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
LSP: bmnet.dll
Trusted Zone: navy.mil
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5471/mcfscan.cab
TCP: NameServer = 85.255.112.168,85.255.112.146
TCP: {0C884745-7C02-4B88-B0E9-E6D62C852DA5} = 85.255.112.168,85.255.112.146
TCP: {879A08F0-5235-4DAC-B437-13FDD3ED1FFA} = [removed],[removed]
TCP: {D506B85D-476D-461D-8154-B2B8F25424F9} = 85.255.112.168,85.255.112.146
================= FIREFOX ===================
FF - ProfilePath - c:\users\apostate\appdata\roaming\mozilla\firefox\profiles\2btyf4cw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\apostate\appdata\local\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-19 130936]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-19 348752]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2008-8-16 13824]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2008-8-16 35840]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2009-5-19 121344]
S3 CAATT;AT&T Con App Svc;c:\program files\at&t\communication manager\ConAppsSvc.exe [2009-5-19 125440]
S3 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\turbine\turbine download manager\TurbineMessageService.exe [2009-4-3 255472]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\turbine\turbine download manager\TurbineNetworkService.exe [2009-4-3 218608]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-4-8 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-4-8 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2009-4-8 23680]
=============== Created Last 30 ================
2009-07-19 18:02 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-07-19 18:02 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-07-19 18:02 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-19 18:02 a-d—– c:\programdata\TEMP
2009-07-19 18:02 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-07-19 18:02 –d—– c:\program files\common files\PC Tools
2009-07-19 18:02 –d—– c:\users\apostate\appdata\roaming\PC Tools
2009-07-19 18:02 –d—– c:\programdata\PC Tools
2009-07-19 18:02 –d—– c:\program files\Spyware Doctor
2009-07-19 18:02 –d—– c:\progra~2\PC Tools
2009-07-19 15:50 48,989 a——- c:\program files\Uninstall.exe
2009-07-15 16:48 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-15 16:48 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-15 16:48 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-15 16:48 10,240 a——- c:\windows\system32\dciman32.dll
2009-06-27 18:56 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-27 18:56 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-27 18:56 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-27 18:56 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-27 18:56 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-27 18:56 11,264 a——- c:\windows\system32\icardres.dll
2009-06-27 18:56 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-27 18:56 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-27 18:51 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-27 18:51 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-27 18:51 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-27 18:51 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-27 18:51 83,968 a——- c:\windows\system32\mscories.dll
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-06-23 19:25 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-06-23 18:56 0 a—h— c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-06-23 18:46 –d—– c:\users\apostate\appdata\roaming\Bytemobile
2009-06-23 18:45 –d—– c:\users\apostate\appdata\roaming\Sierra Wireless
2009-06-23 18:43 26,496 a——- c:\windows\system32\drivers\RimSerial.sys
2009-06-23 18:43 –d—– c:\program files\common files\Motorola Shared
2009-06-23 18:42 –d—– c:\program files\common files\PctelEapPeer Authentication
2009-06-23 18:42 –d—– C:\Research in Motion
2009-06-23 18:42 –d—– c:\program files\common files\Research in Motion
2009-06-23 18:42 –d—– c:\programdata\AT&T
2009-06-23 18:42 –d—– c:\program files\Sierra Wireless Inc
2009-06-23 18:42 –d—– c:\program files\AT&T
2009-06-23 18:42 –d—– c:\progra~2\AT&T
2009-06-23 18:39 –d—– c:\program files\Option
2009-06-22 12:07 156 a——- c:\windows\Twunk001.MTX
2009-06-22 12:07 3 a——- c:\windows\Twain001.Mtx
2009-06-22 12:07 0 a——- c:\windows\Twunk002.MTX
==================== Find3M ====================
2009-07-19 18:16 68,276 a——- c:\programdata\nvModes.dat
2009-07-19 18:16 68,276 a——- c:\progra~2\nvModes.dat
2009-06-23 18:45 143,360 a——- c:\windows\inf\infstrng.dat
2009-06-23 18:45 143,360 a——- c:\windows\inf\infstor.dat
2009-06-23 18:45 86,016 a——- c:\windows\inf\infpub.dat
2009-05-19 14:51 719,360 a——- c:\windows\system32\bmutil.dll
2009-05-19 14:51 475,136 a——- c:\windows\system32\bmnet.dll
2009-05-19 14:51 118,784 a——- c:\windows\system32\bmwebcfg.exe
2009-05-19 14:51 8,464 a——- c:\windows\system32\SpOrder.Dll
2009-05-19 14:51 126,976 a——- c:\windows\system32\bmdumpd.bin
2009-05-19 14:50 137,752 a——- c:\windows\system32\PCTIN50.dll
2009-05-19 14:50 32,408 a——- c:\windows\system32\PCTINDIS5.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-05-01 17:02 90,112 a——- c:\windows\system32\dpl100.dll
2009-05-01 17:02 823,296 a——- c:\windows\system32\divx_xx0c.dll
2009-05-01 17:02 823,296 a——- c:\windows\system32\divx_xx07.dll
2009-05-01 17:02 815,104 a——- c:\windows\system32\divx_xx0a.dll
2009-05-01 17:02 811,008 a——- c:\windows\system32\divx_xx16.dll
2009-05-01 17:02 802,816 a——- c:\windows\system32\divx_xx11.dll
2009-05-01 17:02 685,056 a——- c:\windows\system32\DivX.dll
2009-04-30 08:37 293,376 a——- c:\windows\system32\psisdecd.dll
2009-04-30 08:37 428,544 a——- c:\windows\system32\EncDec.dll
2009-04-23 08:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-04-21 07:55 2,033,152 a——- c:\windows\system32\win32k.sys
2009-01-25 15:08 102,364 a——- c:\users\apostate\appdata\roaming\nvModes.dat
2008-06-12 09:08 665,600 a——- c:\windows\inf\drvindex.dat
2008-06-03 01:19 0 a——- c:\users\apostate\appdata\roaming\wklnhst.dat
2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-07-25 16:32 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-07-25 16:32 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-07-25 16:32 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
============= FINISH: 19:17:46.32 ===============
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-19 19:24:38
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x80789282]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x80789474]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x80788F32]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x8078967C]
Code 877B0318 ZwEnumerateKey
Code 87846250 ZwFlushInstructionCache
Code 8779F225 IofCallDriver
Code 8743E2BE IofCompleteRequest
Code 8779FBFD ZwSaveKey
Code 877E7485 ZwSaveKeyEx
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!IofCompleteRequest 81E74FE2 5 Bytes JMP 8743E2C3
.text ntkrnlpa.exe!ZwSaveKey 81E91664 5 Bytes JMP 8779FC02
.text ntkrnlpa.exe!ZwSaveKeyEx 81E91678 5 Bytes JMP 877E748A
.text ntkrnlpa.exe!KeSetTimerEx + 43C 81EF3A00 8 Bytes [82, 92, 78, 80, 74, 94, 78, …]
.text ntkrnlpa.exe!KeSetTimerEx + 854 81EF3E18 4 Bytes [32, 8F, 78, 80]
.text ntkrnlpa.exe!KeSetTimerEx + 918 81EF3EDC 4 Bytes [7C, 96, 78, 80] {JL 0xffffffffffffff98; JS 0xffffffffffffff84}
.text ntkrnlpa.exe!IofCallDriver 81EF6F6F 5 Bytes JMP 8779F22A
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\system32\svchost.exe[200] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[200] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[200] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe[392] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[556] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[556] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[556] KERNEL32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[608] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[608] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\wininit.exe[608] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[620] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[620] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[620] KERNEL32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[652] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\services.exe[652] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[672] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsass.exe[672] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsm.exe[680] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[680] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsm.exe[680] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\winlogon.exe[724] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[724] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\winlogon.exe[724] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[860] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[860] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[860] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[928] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[992] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[992] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[992] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1016] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1016] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1016] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\nvvsvc.exe[1056] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\nvvsvc.exe[1056] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1072] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1072] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1140] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1140] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[1140] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1156] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1236] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1236] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1236] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1268] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1268] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[1324] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[1420] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] kernel32.dll!CreateThread + 1A 778946E2 4 Bytes CALL 0044AD11 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Windows\System32\spoolsv.exe[1620] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1620] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\spoolsv.exe[1620] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1644] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1644] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1644] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1808] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1848] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1916] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[2060] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[2060] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\svchost.exe[2060] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\SearchIndexer.exe[2120] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2156] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe[2180] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\taskeng.exe[2368] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2368] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\taskeng.exe[2368] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\rundll32.exe[2580] kernel32.dll!LoadLibraryExW 778730C3 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\rundll32.exe[2580] USER32.dll!SetWindowsHookExW 761D7B69 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\rundll32.exe[2580] USER32.dll!SetWindowsHookExA 761FBB0E 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[4036] kernel32.dll!CreateThread + 1A 778946E2 4 Bytes CALL 0044AB89 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5140] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!SetWindowsHookExW 761D7B69 5 Bytes JMP 6DAC9271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!CallNextHookEx 761D8C33 5 Bytes JMP 6DABC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!UnhookWindowsHookEx 762008BE 5 Bytes JMP 6DA34284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5184] ole32.dll!CoCreateInstance 760AE188 5 Bytes JMP 6DACD330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!SetWindowsHookExW 761D7B69 5 Bytes JMP 6DAC9271 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!CallNextHookEx 761D8C33 5 Bytes JMP 6DABC8B9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxIndirectParamW 761DBD25 5 Bytes JMP 6DBEB6FB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!CreateWindowExW 761E3D67 5 Bytes JMP 6DACD2D4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxParamW 761F1FD5 5 Bytes JMP 6D9F51D5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!UnhookWindowsHookEx 762008BE 5 Bytes JMP 6DA34284 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxParamA 762180B2 5 Bytes JMP 6DBEB698 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!DialogBoxIndirectParamA 762183DD 5 Bytes JMP 6DBEB75E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxIndirectA 7622D471 5 Bytes JMP 6DBEB62D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxIndirectW 7622D56B 5 Bytes JMP 6DBEB5C2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxExA 7622D5D1 5 Bytes JMP 6DBEB560 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] USER32.dll!MessageBoxExW 7622D5F5 5 Bytes JMP 6DBEB4FE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5296] ole32.dll!CoCreateInstance 760AE188 5 Bytes JMP 6DACD330 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[1432] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[4036] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[4036] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000078 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
—- Disk sectors - GMER 1.0.15 —-
Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
—- EOF - GMER 1.0.15 —-