Tanglang1989
Topic Starter
I hope I am doing this correctly. The topic in which I am dealing with this is here:
http://forums.whatthetech.com/Blue_Screen_…762#entry630762
(for more info on what has been done so far)
I've ran all the programs you said in that "are you infected" thingy… though dds says that it doesn't support my OS (which is XP).
So here is Malwarebyte: … sorry, it is in Finnish. Well, nothing found anyhow. (Haitallisia kohteita ei löydetty = No malware found)
Malwarebytes' Anti-Malware 1.44
Tietokantaversio: 3807
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
28.2.2010 20:49:32
mbam-log-2010-02-28 (20-49-32).txt
Tarkistustyyppi: Pikatarkistus
Tarkistetut kohteet: 118598
Kulunut aika: 16 minute(s), 30 second(s)
Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 0
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 0
Saastuneita tiedostoja: 0
Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)
Saastuneita tiedostoja:
(Haitallisia kohteita ei löydetty)
And here's GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-28 21:43:12
Windows 5.1.2600 Service Pack 3
Running: cy6t22e9.exe; Driver: C:\DOCUME~1\KEVING~1\LOCALS~1\Temp\fgpyikod.sys
—- System - GMER 1.0.15 —-
SSDT spjm.sys ZwCreateKey [0xF74E40E0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateProcess [0xB5E83CD6]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateProcessEx [0xB5E83CF0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateThread [0xB5E82E8C]
SSDT spjm.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spjm.sys ZwEnumerateValueKey [0xF74FD132]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwLoadDriver [0xB5E831BC]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwMapViewOfSection [0xB5E82BCC]
SSDT spjm.sys ZwOpenKey [0xF74E40C0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwOpenSection [0xB5E835EE]
SSDT spjm.sys ZwQueryKey [0xF74FD20A]
SSDT spjm.sys ZwQueryValueKey [0xF74FD08A]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwRenameKey [0xB5E8488C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSetSystemInformation [0xB5E8343E]
SSDT spjm.sys ZwSetValueKey [0xF74FD29C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSuspendProcess [0xB5E82A4C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSuspendThread [0xB5E82EC0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSystemDebugControl [0xB5E83042]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwTerminateProcess [0xB5E829A6]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwTerminateThread [0xB5E82B06]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwWriteVirtualMemory [0xB5E82F86]
INT 0x63 ? 89591BF8
INT 0x73 ? 8979BBF8
INT 0xB4 ? 89591BF8
Code fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation) IoCreateDevice
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!_abnormal_termination + 108 804E2774 8 Bytes CALL 688B182E
.text ntoskrnl.exe!_abnormal_termination + 169 804E27D5 3 Bytes [CD, 4F, F7]
.text ntoskrnl.exe!_abnormal_termination + 440 804E2AAC 12 Bytes CALL 687CEB66
.text ntoskrnl.exe!_abnormal_termination + 450 804E2ABC 8 Bytes CALL 68793176
PAGE ntoskrnl.exe!IoCreateDevice 8059FA51 5 Bytes JMP BAF41FFA fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
? spjm.sys Määritettyä tiedostoa ei löydy. !
PAGENPNP NDIS.SYS!NdisRegisterProtocol BAF1217F 5 Bytes JMP BAF41E0C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisOpenAdapter BAF12399 5 Bytes JMP BAF42394 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisCloseAdapter BAF1C642 5 Bytes JMP BAF41F18 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisDeregisterProtocol BAF1C821 5 Bytes JMP BAF421B0 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisReturnPackets BAF1F810 5 Bytes JMP BAF42C0C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisRequest BAF1F97B 5 Bytes JMP BAF425AC fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSend BAF22986 5 Bytes JMP BAF4358C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSendPackets BAF229A3 5 Bytes JMP BAF4365E fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisTransferData BAF229BE 5 Bytes JMP BAF42D0A fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoCreateVc BAF29186 5 Bytes JMP BAF41E76 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoDeleteVc BAF2A557 5 Bytes JMP BAF41EE4 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoSendPackets BAF2AAF1 5 Bytes JMP BAF43376 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
.text USBPORT.SYS!DllUnload B9B428AC 5 Bytes JMP 895911D8
.text a1oa948f.SYS A9FFC386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text a1oa948f.SYS A9FFC3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text a1oa948f.SYS A9FFC3C4 3 Bytes [00, 80, 02]
.text a1oa948f.SYS A9FFC3C9 1 Byte [30]
.text a1oa948f.SYS A9FFC3C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, …] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text …
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0E36000C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 0E36100C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0E36200C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 0E36300C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 0E36700C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 0E36500C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 0E36600C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 0E36800C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 0E36400C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 0E36A00C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 0E36900C
.text C:\WINDOWS\system32\winlogon.exe[552] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 010F000C
.text C:\WINDOWS\system32\winlogon.exe[552] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 010F100C
.text C:\WINDOWS\system32\winlogon.exe[552] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 010F200C
.text C:\WINDOWS\system32\winlogon.exe[552] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 010F300C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 010F700C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 010F500C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 010F600C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 010F800C
.text C:\WINDOWS\system32\winlogon.exe[552] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 010F400C
.text C:\WINDOWS\system32\winlogon.exe[552] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 010FA00C
.text C:\WINDOWS\system32\winlogon.exe[552] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 010F900C
.text C:\WINDOWS\system32\lsass.exe[608] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DD000C
.text C:\WINDOWS\system32\lsass.exe[608] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00DD100C
.text C:\WINDOWS\system32\lsass.exe[608] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DD200C
.text C:\WINDOWS\system32\lsass.exe[608] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 00DD300C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 00DD700C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 00DD500C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 00DD600C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00DD800C
.text C:\WINDOWS\system32\lsass.exe[608] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00DD400C
.text C:\WINDOWS\system32\lsass.exe[608] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 00DDA00C
.text C:\WINDOWS\system32\lsass.exe[608] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 00DD900C
.text C:\WINDOWS\System32\alg.exe[1740] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B2000C
.text C:\WINDOWS\System32\alg.exe[1740] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00B2100C
.text C:\WINDOWS\System32\alg.exe[1740] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B2200C
.text C:\WINDOWS\System32\alg.exe[1740] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 00B2300C
.text C:\WINDOWS\System32\alg.exe[1740] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00B2400C
.text C:\WINDOWS\System32\alg.exe[1740] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 00B2A00C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 00B2700C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 00B2500C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 00B2600C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00B2800C
.text C:\WINDOWS\System32\alg.exe[1740] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 00B2900C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D900C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D700C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D500C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D600C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D800C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 027B000C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 027B100C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 027B200C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 027B300C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 027B400C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 027BA00C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 027B700C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 027B500C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 027B600C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 027B800C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 027B900C
.text C:\WINDOWS\Explorer.EXE[2208] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0294000C
.text C:\WINDOWS\Explorer.EXE[2208] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 0294100C
.text C:\WINDOWS\Explorer.EXE[2208] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0294200C
.text C:\WINDOWS\Explorer.EXE[2208] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 0294300C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 0294700C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 0294500C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 0294600C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 0294800C
.text C:\WINDOWS\Explorer.EXE[2208] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 0294400C
.text C:\WINDOWS\Explorer.EXE[2208] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 0294A00C
.text C:\WINDOWS\Explorer.EXE[2208] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 0294900C
.text C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE[2364] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA000C
.text C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE[2364] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00BA100C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D900C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D700C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D500C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D600C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D800C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 011D000C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 011D100C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011D200C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 011D300C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 011D400C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 011DA00C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 011D700C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 011D500C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 011D600C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 011D800C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 011D900C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D500C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D800C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D600C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D700C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D900C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 03D7000C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 03D7100C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 03D7200C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 03D7300C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 03D7700C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 03D7500C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 03D7600C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 03D7800C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 03D7400C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 03D7A00C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 03D7900C
—- Kernel IAT/EAT - GMER 1.0.15 —-
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8979B2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F750FDDC] spjm.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F750FE30] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74E5042] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74E513E] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74E50C0] spjm.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74E5800] spjm.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74E56D6] spjm.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 895912D8
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlInitUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!swprintf] 001CBA86
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSetEvent] C61AEB00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 001C8986
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 86C61200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00001C8B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmFreeMappingAddress] 96868801
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 001CB286
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnmapIoSpace] 88968B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 8900001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IofCompleteRequest] 001CA496
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCompareUnicodeString] C6168B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IofCallDriver] 001CC186
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 428A0A00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] C286880C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoConnectInterrupt] 8B00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDetachDevice] 24A48DFA
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeEvent] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeCancelTimer] 8D3F0304
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] CB033043
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlInitAnsiString] 0673C13B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] C13B0003
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoQueueWorkItem] 8366FA72
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapIoSpace] 75000E7B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoReportDetectedDevice] 307B8D00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00AA840F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 83660000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!NlsMbCodePageTag] 6A000E7A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoRequestPowerIrp] C6647400
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 001CC386
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 4F8B0200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!sprintf] 968D5140
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00001C98
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObfDereferenceObject] 22F6E852
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 478B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 50016A40
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwClose] 1CB48E8D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] E8510000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 000022E4
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 6A18538B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 868D5200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoCreateDevice] 00001CA0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 22D2E850
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 4B8B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 51016A18
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwOpenKey] 1CBC968D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlFreeUnicodeString] E8520000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartTimer] 000022C0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeTimer] 8A05478A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInitializeTimer] 001CC38E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeDpc] 30C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeSpinLock] 1CC58688
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInitializeIrp] 80E90000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwCreateKey] C6000000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 001CC386
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 438B0100
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwSetValueKey] 8E8D5018
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00001C98
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 2292E851
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartPacket] 538B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 52016A18
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 1CB4868D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeMdl] E8500000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnlockPages] 00002280
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 8A05478A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 001CC38E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 18C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 1CC58688
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSynchronizeExecution] 43EB0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartNextPacket] 320C538A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeBugCheckEx] 88F93BC0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 001CC396
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSetTimer] F6317300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_allmul] 74070647
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmProbeAndLockPages] 75C0841A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_except_handler3] 05578A0B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoSetPowerState] 968801B0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 00001CC5
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 57B60F66
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 533B6604
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_aulldiv] 03087408
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!strstr] 72F93B3F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_strupr] 8A09EBDA
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeQuerySystemTime] 86880547
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 00001CC5
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeTickCount] 88084B8A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 001CC68E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDeleteDevice] 40578B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 8D52006A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateWorkItem] 001CC886
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateIrp] 11E85000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateMdl] 8B000022
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 001CC08E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmLockPagableDataSection] C4968B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 8900001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 001CCC8E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ExFreePoolWithTag] D0968900
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeIrp] 8B00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeWorkItem] 016A4047
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!InitSafeBootMode] D4C68150
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCompareMemory] 5600001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoCallDriver] 0021E7E8
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!memmove] 18C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmHighestUserAddress] 5D5B5E5F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74F4B90] spjm.sys
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 897971F8
Device \FileSystem\Fastfat \FatCdrom 89110500
Device \FileSystem\Udfs \UdfsCdRom 891D6500
Device \FileSystem\Udfs \UdfsCdRom BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
Device \FileSystem\Udfs \UdfsDisk 891D6500
Device \FileSystem\Udfs \UdfsDisk BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
Device \Driver\Tcpip \Device\Ip fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbohci \Device\USBPDO-0 895851F8
Device \Driver\usbohci \Device\USBPDO-1 895851F8
Device \Driver\usbehci \Device\USBPDO-2 894A91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C4C513B0-EED9-4AE5-B406-1C19213D4FE0} 892CB500
Device \Driver\PCI_PNP6612 \Device\00000047 spjm.sys
Device \Driver\PCI_PNP6612 \Device\00000047 spjm.sys
Device \Driver\Tcpip \Device\Tcp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\sptd \Device\1111024112 spjm.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 897991F8
Device \Driver\Cdrom \Device\CdRom0 89204500
Device \Driver\Cdrom \Device\CdRom1 89204500
Device \Driver\Cdrom \Device\CdRom2 89204500
Device \Driver\NetBT \Device\NetBt_Wins_Export 892CB500
Device \Driver\NetBT \Device\NetbiosSmb 892CB500
Device \Driver\Tcpip \Device\Udp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbohci \Device\USBFDO-0 895851F8
Device \Driver\usbohci \Device\USBFDO-1 895851F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89309500
Device \Driver\Tcpip \Device\IPMULTICAST fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbehci \Device\USBFDO-2 894A91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89309500
Device \Driver\Ftdisk \Device\FtControl 897991F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path0Target0Lun0 897981F8
Device \Driver\a1oa948f \Device\Scsi\a1oa948f1 891F2500
Device \Driver\a1oa948f \Device\Scsi\a1oa948f1Port1Path0Target0Lun0 891F2500
Device \Driver\nvidesm \Device\Scsi\nvidesm1 897981F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path1Target1Lun0 897981F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path1Target0Lun0 897981F8
Device \FileSystem\Fastfat \Fat 89110500
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 89333500
Device \FileSystem\Cdfs \Cdfs BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEE 0x4B 0x66 0x1C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF3 0xD0 0x42 0xEB …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3F 0xCE 0xB3 0x3E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEE 0x4B 0x66 0x1C …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF3 0xD0 0x42 0xEB …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3F 0xCE 0xB3 0x3E …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@oagfhdapkeojcikoaacemeihmdokcb 0x64 0x61 0x6A 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@oakehnoakgldobmknkfilgjnonnhak 0x6B 0x61 0x6A 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@naefbcnbbnpofjbhbcfbeafmeiin 0x6B 0x61 0x6A 0x64 …
—- EOF - GMER 1.0.15 —-
So.. um.. what now?
Thanks
http://forums.whatthetech.com/Blue_Screen_…762#entry630762
(for more info on what has been done so far)
I've ran all the programs you said in that "are you infected" thingy… though dds says that it doesn't support my OS (which is XP).
So here is Malwarebyte: … sorry, it is in Finnish. Well, nothing found anyhow. (Haitallisia kohteita ei löydetty = No malware found)
Malwarebytes' Anti-Malware 1.44
Tietokantaversio: 3807
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
28.2.2010 20:49:32
mbam-log-2010-02-28 (20-49-32).txt
Tarkistustyyppi: Pikatarkistus
Tarkistetut kohteet: 118598
Kulunut aika: 16 minute(s), 30 second(s)
Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 0
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 0
Saastuneita tiedostoja: 0
Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)
Saastuneita tiedostoja:
(Haitallisia kohteita ei löydetty)
And here's GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-28 21:43:12
Windows 5.1.2600 Service Pack 3
Running: cy6t22e9.exe; Driver: C:\DOCUME~1\KEVING~1\LOCALS~1\Temp\fgpyikod.sys
—- System - GMER 1.0.15 —-
SSDT spjm.sys ZwCreateKey [0xF74E40E0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateProcess [0xB5E83CD6]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateProcessEx [0xB5E83CF0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwCreateThread [0xB5E82E8C]
SSDT spjm.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spjm.sys ZwEnumerateValueKey [0xF74FD132]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwLoadDriver [0xB5E831BC]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwMapViewOfSection [0xB5E82BCC]
SSDT spjm.sys ZwOpenKey [0xF74E40C0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwOpenSection [0xB5E835EE]
SSDT spjm.sys ZwQueryKey [0xF74FD20A]
SSDT spjm.sys ZwQueryValueKey [0xF74FD08A]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwRenameKey [0xB5E8488C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSetSystemInformation [0xB5E8343E]
SSDT spjm.sys ZwSetValueKey [0xF74FD29C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSuspendProcess [0xB5E82A4C]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSuspendThread [0xB5E82EC0]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwSystemDebugControl [0xB5E83042]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwTerminateProcess [0xB5E829A6]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwTerminateThread [0xB5E82B06]
SSDT \??\C:\Program Files\Elisa Tietoturvapalvelu\HIPS\drivers\fshs.sys (HIPS 32-bit kernel module/F-Secure Corporation) ZwWriteVirtualMemory [0xB5E82F86]
INT 0x63 ? 89591BF8
INT 0x73 ? 8979BBF8
INT 0xB4 ? 89591BF8
Code fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation) IoCreateDevice
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!_abnormal_termination + 108 804E2774 8 Bytes CALL 688B182E
.text ntoskrnl.exe!_abnormal_termination + 169 804E27D5 3 Bytes [CD, 4F, F7]
.text ntoskrnl.exe!_abnormal_termination + 440 804E2AAC 12 Bytes CALL 687CEB66
.text ntoskrnl.exe!_abnormal_termination + 450 804E2ABC 8 Bytes CALL 68793176
PAGE ntoskrnl.exe!IoCreateDevice 8059FA51 5 Bytes JMP BAF41FFA fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
? spjm.sys Määritettyä tiedostoa ei löydy. !
PAGENPNP NDIS.SYS!NdisRegisterProtocol BAF1217F 5 Bytes JMP BAF41E0C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisOpenAdapter BAF12399 5 Bytes JMP BAF42394 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisCloseAdapter BAF1C642 5 Bytes JMP BAF41F18 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisDeregisterProtocol BAF1C821 5 Bytes JMP BAF421B0 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisReturnPackets BAF1F810 5 Bytes JMP BAF42C0C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisRequest BAF1F97B 5 Bytes JMP BAF425AC fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSend BAF22986 5 Bytes JMP BAF4358C fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSendPackets BAF229A3 5 Bytes JMP BAF4365E fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisTransferData BAF229BE 5 Bytes JMP BAF42D0A fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoCreateVc BAF29186 5 Bytes JMP BAF41E76 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoDeleteVc BAF2A557 5 Bytes JMP BAF41EE4 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoSendPackets BAF2AAF1 5 Bytes JMP BAF43376 fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
.text USBPORT.SYS!DllUnload B9B428AC 5 Bytes JMP 895911D8
.text a1oa948f.SYS A9FFC386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text a1oa948f.SYS A9FFC3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text a1oa948f.SYS A9FFC3C4 3 Bytes [00, 80, 02]
.text a1oa948f.SYS A9FFC3C9 1 Byte [30]
.text a1oa948f.SYS A9FFC3C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, …] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text …
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0E36000C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 0E36100C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0E36200C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[336] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 0E36300C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 0E36700C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 0E36500C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 0E36600C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 0E36800C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 0E36400C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 0E36A00C
.text C:\WINDOWS\system32\SearchIndexer.exe[336] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 0E36900C
.text C:\WINDOWS\system32\winlogon.exe[552] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 010F000C
.text C:\WINDOWS\system32\winlogon.exe[552] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 010F100C
.text C:\WINDOWS\system32\winlogon.exe[552] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 010F200C
.text C:\WINDOWS\system32\winlogon.exe[552] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 010F300C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 010F700C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 010F500C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 010F600C
.text C:\WINDOWS\system32\winlogon.exe[552] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 010F800C
.text C:\WINDOWS\system32\winlogon.exe[552] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 010F400C
.text C:\WINDOWS\system32\winlogon.exe[552] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 010FA00C
.text C:\WINDOWS\system32\winlogon.exe[552] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 010F900C
.text C:\WINDOWS\system32\lsass.exe[608] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DD000C
.text C:\WINDOWS\system32\lsass.exe[608] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00DD100C
.text C:\WINDOWS\system32\lsass.exe[608] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DD200C
.text C:\WINDOWS\system32\lsass.exe[608] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 00DD300C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 00DD700C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 00DD500C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 00DD600C
.text C:\WINDOWS\system32\lsass.exe[608] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00DD800C
.text C:\WINDOWS\system32\lsass.exe[608] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00DD400C
.text C:\WINDOWS\system32\lsass.exe[608] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 00DDA00C
.text C:\WINDOWS\system32\lsass.exe[608] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 00DD900C
.text C:\WINDOWS\System32\alg.exe[1740] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B2000C
.text C:\WINDOWS\System32\alg.exe[1740] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00B2100C
.text C:\WINDOWS\System32\alg.exe[1740] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B2200C
.text C:\WINDOWS\System32\alg.exe[1740] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 00B2300C
.text C:\WINDOWS\System32\alg.exe[1740] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00B2400C
.text C:\WINDOWS\System32\alg.exe[1740] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 00B2A00C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 00B2700C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 00B2500C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 00B2600C
.text C:\WINDOWS\System32\alg.exe[1740] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 00B2800C
.text C:\WINDOWS\System32\alg.exe[1740] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 00B2900C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D900C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D700C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D500C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D600C
.text C:\WINDOWS\system32\CTsvcCDA.exe[1828] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D800C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 027B000C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 027B100C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 027B200C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 027B300C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 027B400C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 027BA00C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 027B700C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 027B500C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 027B600C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 027B800C
.text C:\Program Files\Common Files\Iconix\IconixService.exe[1908] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 027B900C
.text C:\WINDOWS\Explorer.EXE[2208] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0294000C
.text C:\WINDOWS\Explorer.EXE[2208] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 0294100C
.text C:\WINDOWS\Explorer.EXE[2208] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0294200C
.text C:\WINDOWS\Explorer.EXE[2208] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 0294300C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 0294700C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 0294500C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 0294600C
.text C:\WINDOWS\Explorer.EXE[2208] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 0294800C
.text C:\WINDOWS\Explorer.EXE[2208] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 0294400C
.text C:\WINDOWS\Explorer.EXE[2208] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 0294A00C
.text C:\WINDOWS\Explorer.EXE[2208] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 0294900C
.text C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE[2364] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA000C
.text C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE[2364] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00BA100C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D900C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D700C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D500C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D600C
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2388] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D800C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 011D000C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 011D100C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011D200C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 011D300C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 011D400C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 011DA00C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 011D700C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 011D500C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 011D600C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 011D800C
.text C:\Program Files\Iconix\OEAddOn\OEdmn_5.exe[2404] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 011D900C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 003D000C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 003D100C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003D200C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 003D300C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D400C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 003D500C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 003D800C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 003D600C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 003D700C
.text C:\Documents and Settings\Kevin Gibbs\Työpöytä\Stuff for the blu screen of death\cy6t22e9.exe[2464] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 003D900C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 03D7000C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 03D7100C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 03D7200C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] kernel32.dll!TerminateThread 7C81CB3B 5 Bytes JMP 03D7300C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!CloseServiceHandle 77DD6CE5 5 Bytes JMP 03D7700C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!OpenServiceW 77DD6FFD 5 Bytes JMP 03D7500C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!ControlService 77DE4A09 5 Bytes JMP 03D7600C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ADVAPI32.dll!CreateServiceW 77E273A9 5 Bytes JMP 03D7800C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 03D7400C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] USER32.dll!DdeConnect 7E3A81C3 5 Bytes JMP 03D7A00C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2472] ole32.dll!CoCreateInstanceEx 774F0526 5 Bytes JMP 03D7900C
—- Kernel IAT/EAT - GMER 1.0.15 —-
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8979B2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F750FDDC] spjm.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F750FE30] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74E5042] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74E513E] spjm.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74E50C0] spjm.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74E5800] spjm.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74E56D6] spjm.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 895912D8
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlInitUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!swprintf] 001CBA86
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSetEvent] C61AEB00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 001C8986
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 86C61200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00001C8B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmFreeMappingAddress] 96868801
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 001CB286
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnmapIoSpace] 88968B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 8900001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IofCompleteRequest] 001CA496
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCompareUnicodeString] C6168B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IofCallDriver] 001CC186
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 428A0A00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] C286880C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoConnectInterrupt] 8B00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDetachDevice] 24A48DFA
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeEvent] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeCancelTimer] 8D3F0304
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] CB033043
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlInitAnsiString] 0673C13B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] C13B0003
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoQueueWorkItem] 8366FA72
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapIoSpace] 75000E7B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoReportDetectedDevice] 307B8D00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00AA840F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 83660000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!NlsMbCodePageTag] 6A000E7A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoRequestPowerIrp] C6647400
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 001CC386
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 4F8B0200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!sprintf] 968D5140
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00001C98
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObfDereferenceObject] 22F6E852
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 478B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 50016A40
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwClose] 1CB48E8D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] E8510000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 000022E4
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 6A18538B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 868D5200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoCreateDevice] 00001CA0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 22D2E850
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 4B8B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 51016A18
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwOpenKey] 1CBC968D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlFreeUnicodeString] E8520000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartTimer] 000022C0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeTimer] 8A05478A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInitializeTimer] 001CC38E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeDpc] 30C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInitializeSpinLock] 1CC58688
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoInitializeIrp] 80E90000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwCreateKey] C6000000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 001CC386
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 438B0100
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ZwSetValueKey] 8E8D5018
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00001C98
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 2292E851
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartPacket] 538B0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 52016A18
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 1CB4868D
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeMdl] E8500000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnlockPages] 00002280
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 8A05478A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 001CC38E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 18C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 1CC58688
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSynchronizeExecution] 43EB0000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoStartNextPacket] 320C538A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeBugCheckEx] 88F93BC0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 001CC396
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeSetTimer] F6317300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_allmul] 74070647
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmProbeAndLockPages] 75C0841A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_except_handler3] 05578A0B
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoSetPowerState] 968801B0
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 00001CC5
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 57B60F66
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 533B6604
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_aulldiv] 03087408
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!strstr] 72F93B3F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!_strupr] 8A09EBDA
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeQuerySystemTime] 86880547
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 00001CC5
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!KeTickCount] 88084B8A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 001CC68E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoDeleteDevice] 40578B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 8D52006A
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateWorkItem] 001CC886
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateIrp] 11E85000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoAllocateMdl] 8B000022
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 001CC08E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmLockPagableDataSection] C4968B00
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 8900001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 001CCC8E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!ExFreePoolWithTag] D0968900
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeIrp] 8B00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!IoFreeWorkItem] 016A4047
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!InitSafeBootMode] D4C68150
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!RtlCompareMemory] 5600001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!PoCallDriver] 0021E7E8
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!memmove] 18C48300
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[ntoskrnl.exe!MmHighestUserAddress] 5D5B5E5F
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\a1oa948f.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74F4B90] spjm.sys
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 897971F8
Device \FileSystem\Fastfat \FatCdrom 89110500
Device \FileSystem\Udfs \UdfsCdRom 891D6500
Device \FileSystem\Udfs \UdfsCdRom BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
Device \FileSystem\Udfs \UdfsDisk 891D6500
Device \FileSystem\Udfs \UdfsDisk BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
Device \Driver\Tcpip \Device\Ip fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbohci \Device\USBPDO-0 895851F8
Device \Driver\usbohci \Device\USBPDO-1 895851F8
Device \Driver\usbehci \Device\USBPDO-2 894A91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C4C513B0-EED9-4AE5-B406-1C19213D4FE0} 892CB500
Device \Driver\PCI_PNP6612 \Device\00000047 spjm.sys
Device \Driver\PCI_PNP6612 \Device\00000047 spjm.sys
Device \Driver\Tcpip \Device\Tcp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\sptd \Device\1111024112 spjm.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 897991F8
Device \Driver\Cdrom \Device\CdRom0 89204500
Device \Driver\Cdrom \Device\CdRom1 89204500
Device \Driver\Cdrom \Device\CdRom2 89204500
Device \Driver\NetBT \Device\NetBt_Wins_Export 892CB500
Device \Driver\NetBT \Device\NetbiosSmb 892CB500
Device \Driver\Tcpip \Device\Udp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbohci \Device\USBFDO-0 895851F8
Device \Driver\usbohci \Device\USBFDO-1 895851F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89309500
Device \Driver\Tcpip \Device\IPMULTICAST fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\usbehci \Device\USBFDO-2 894A91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89309500
Device \Driver\Ftdisk \Device\FtControl 897991F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path0Target0Lun0 897981F8
Device \Driver\a1oa948f \Device\Scsi\a1oa948f1 891F2500
Device \Driver\a1oa948f \Device\Scsi\a1oa948f1Port1Path0Target0Lun0 891F2500
Device \Driver\nvidesm \Device\Scsi\nvidesm1 897981F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path1Target1Lun0 897981F8
Device \Driver\nvidesm \Device\Scsi\nvidesm1Port0Path1Target0Lun0 897981F8
Device \FileSystem\Fastfat \Fat 89110500
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 89333500
Device \FileSystem\Cdfs \Cdfs BsUDF.SYS (UDF File System Driver (WindowsXP)/ahead software)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEE 0x4B 0x66 0x1C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF3 0xD0 0x42 0xEB …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3F 0xCE 0xB3 0x3E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEE 0x4B 0x66 0x1C …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF3 0xD0 0x42 0xEB …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3F 0xCE 0xB3 0x3E …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@oagfhdapkeojcikoaacemeihmdokcb 0x64 0x61 0x6A 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@oakehnoakgldobmknkfilgjnonnhak 0x6B 0x61 0x6A 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47A0EDF4-C995-E679-2068-E30EF0E60185}@naefbcnbbnpofjbhbcfbeafmeiin 0x6B 0x61 0x6A 0x64 …
—- EOF - GMER 1.0.15 —-
So.. um.. what now?
Thanks