DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:04:00.62 on Tue 04/13/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.171 [GMT -4:00]
AV: avast! antivirus 4.8.1368 [VPS 100413-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Pink Calendar\PinkCal.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\ASTSRV.EXE
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Palo Alto Networks\Pan Connect\PanService.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Photodex\ProShowGold\progold3\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Red NoteBook\RedNoteBook.exe
C:\Documents and Settings\AndiL\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.refdesk.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BayScribeObj Class: {5e028439-81c7-4b82-bc74-25156306f532} - c:\program files\bayscribe\bayscribe.dll
BHO: My Web Search Bar BHO: {8eab99c1-f9ec-4b64-a4ba-d9bcae8779c2} - c:\program files\mywebsearchwb\bar\1.bin\W6BAR.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {9404901D-06DA-4B23-A0EE-3EA4F64EC9B3} - No File
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [FinePrint Dispatcher v5] c:\windows\system32\spool\drivers\w32x86\3\fpdisp5a.exe
mRun: [F5D9050] c:\program files\belkin\f5d9050\Belkinwcui.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SBAutoUpdate] "c:\program files\spywareblaster\sbautoupdate.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\andil\startm~1\programs\startup\pinkcal.lnk - c:\program files\pink calendar\PinkCal.exe
IE: c:\progra~1\common~1\btlink\btlink.dll//iemenu
IE: Add to Evernote - c:\program files\evernote\evernote3\enbar.dll/2000
IE: Add to EverNote - c:\program files\evernote\evernote\enbar.dll/2000
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: GuruNet… - file:c:\program files\gurunet\html\atiemenu.htm
IE: Locate Spot on Map by GPS - c:\program files\opanda\iexif 2.3\IExifMap.htm
IE: View Exif/GPS/IPTC with IExif - c:\program files\opanda\iexif 2.3\IExifCom.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - c:\program files\evernote\evernote3\enbar.dll
Trusted Zone: adp.com
Trusted Zone: aol.com\free
Trusted Zone: dictaphone.com
Trusted Zone: ichart.com
Trusted Zone: nuance.com
Trusted Zone: seormc.org\connect
Trusted Zone: transcendservices.com
Trusted Zone: trcr.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/0/f/b/0fb0fab9-7f09-4bb6-86d8-8e791ba99ac5/VirtualEarth3D.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} - hxxp://www.pestscan.com/scanner/axscanner.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos2.walmart.com/WalmartActivia.cab
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
DPF: {53D40FAA-4E21-459F-AA87-E4D97FC3245A} - hxxps://www.transcendservices.com/help/Agent/setup.exe
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.adoramapix.com/components/aurigma/ImageUploader5.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - hxxp://toolbar.google.com/data/GoogleActivate.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9DDB393E-A5C2-40F7-A37F-4957CAC7C65C} - hxxp://workportal01.trcr.com/clientinstall/production/BTClient/ActiveXLoader.CAB
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {EF2E2523-5E55-4A8F-A0C9-0F2B7457290C} - hxxps://mls.trcr.com/CABS/SWTrackerCTL.CAB
DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} - hxxp://samsclubus.pnimedia.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: LMIinit - LMIinit.dll
AppInit_DLLs: WIKI.DLL c:\progra~1\google\google~3\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 relog_ap
LSA: Notification Packages = :\windows\system32\srrstr.dll cecli scecli scecli scecli
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-7 114768]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [2009-1-7 57344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-7 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-7 138680]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-8-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-1-24 47640]
R2 PanService;PanService;c:\program files\palo alto networks\pan connect\PanService.exe [2009-8-31 950272]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-11 3032360]
R3 PanSvd;Pan Virtual Miniport;c:\windows\system32\drivers\pansvd.sys [2009-8-31 27136]
R3 StreamSurge;StreamSurge Driver (miniport);c:\windows\system32\drivers\ss.sys [2008-8-20 19968]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-31 135664]
S3 APL531;OVT Scanner;c:\windows\system32\drivers\ov550i.sys [2006-7-31 580992]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-7 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-7 352920]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2008-9-21 14336]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-1-4 30192]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-12-11 15144]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 ohciusb;Open Host Controller Miniport USB Driver; [x]
=============== Created Last 30 ================
2010-04-12 21:06 664 a——- c:\windows\system32\d3d9caps.dat
2010-04-12 21:06 1,409 a——- c:\windows\QTFont.for
2010-04-12 21:06 54,156 a—h— c:\windows\QTFont.qfn
2010-04-12 09:50 411,368 a——- c:\windows\system32\deploytk.dll
2010-04-12 09:50 73,728 a——- c:\windows\system32\javacpl.cpl
2010-04-12 09:36 –d—– c:\program files\SpywareBlaster
2010-04-12 01:11 –d—– c:\windows\system32\wbem\Repository
2010-04-11 21:04 -cd—– C:\RootkitNO
2010-04-11 20:47 –d—– c:\program files\UnHackMe
2010-04-10 14:41 12,872 a——- c:\windows\system32\bootdelete.exe
2010-04-10 00:47 15,944 a——- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-10 00:46 –d—– c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-04-10 00:46 –d—– c:\program files\Hitman Pro 3.5
2010-04-09 20:55 –d—– c:\documents and settings\andil\DoctorWeb
2010-04-08 13:22 279,552 a——- c:\windows\system32\swreg.exe
2010-04-08 13:22 109,056 a——- c:\windows\catchme.exe
2010-04-08 13:22 212,480 a——- c:\windows\system32\swxcacls.exe
2010-04-08 13:22 -cd—– C:\ComboFix
2010-04-08 01:19 –d—– c:\program files\CCleaner
2010-04-08 01:19 –d—– c:\docume~1\alluse~1\applic~1\avG
2010-03-31 00:44 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2010-03-19 01:22 61,224 a——- c:\documents and settings\andil\GoToAssistDownloadHelper.exe
==================== Find3M ====================
2010-04-12 23:34 4 a——- c:\docume~1\andil\applic~1\EXText Diagnostic Upload Queue.dat
2010-04-11 20:49 95,360 a——- c:\windows\system32\drivers\atapi.sys
2010-04-07 15:30 141,199 a——- c:\windows\hpoins14.dat
2010-03-30 09:32 365,440 ac—— c:\docume~1\andil\applic~1\GDIPFONTCACHEV1.DAT
2010-03-30 01:46 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 01:45 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-03-29 00:18 365,440 a——- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-30 19:49 84,992 a——- c:\windows\system32\atl70.dll
2010-01-14 22:30 60,744 a——- c:\documents and settings\andil\g2mdlhlpx.exe
2005-09-19 13:30 774,144 a——- c:\program files\RngInterstitial.dll
2005-05-07 22:49 6,132 ac—— c:\program files\top52–0047.htm
2005-05-07 22:48 6,132 ac—— c:\program files\top52–0028.htm
2005-05-07 22:47 1,039,189 ac—— c:\program files\01mp3ins.exe
2005-04-17 13:07 1,584,088 ac—— c:\program files\earpro4setup.exe
2005-03-27 21:08 10,831,584 ac—— c:\program files\PestPatrolv5.exe
2004-10-20 22:18 376,672 ac—— c:\program files\DLM_2200043_ENU.exe
2004-06-22 22:03 411,329 ac—— c:\program files\slimlist.exe
2004-05-04 12:50 8,029,451 ac—— c:\program files\SetupPestPatrolHome.exe
2004-04-07 10:28 2,736,029 ac—— c:\program files\treepadplus.zip
2004-02-20 00:15 457 ac—— c:\program files\INSTALL.LOG
2003-05-21 20:10 3,662,787 ac—— c:\program files\spybotsd12.exe
2003-05-15 12:17 2,838,184 ac—— c:\program files\ica32.exe
2003-05-14 00:30 260,684 ac—— c:\program files\ICQMessageArchive.exe
2003-05-13 19:14 1,897,672 ac—— c:\program files\winzip81.exe
2003-05-12 23:51 660,696 ac—— c:\program files\rednotebook19b.exe
2003-05-12 19:55 5,082,328 ac—— c:\program files\cuteftppro.exe
2003-05-12 19:48 3,025,408 ac—— c:\program files\cuteftp.exe
2003-05-12 19:16 3,978,384 ac—— c:\program files\icqpro2003a.exe
============= FINISH: 10:06:09.98 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-13 13:52:24
Windows 5.1.2600 Service Pack 2
Running: ryjnihwn.exe; Driver: C:\DOCUME~1\AndiL\LOCALS~1\Temp\pxtdrpod.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEE0766B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEE076574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEE076A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEE07614C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEE07664E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEE07608C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEE0760F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEE07676E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEE07672E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEE0768AE]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwCreateProcess [0xEE305878]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwCreateProcessEx [0xEE3059BC]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwCreateSection [0xEE305556]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwLoadDriver [0xEE3053FE]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) ZwSetSystemInformation [0xEE30536C]
Code \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) NtCreateSection
—- Kernel code sections - GMER 1.0.15 —-
PAGE ntoskrnl.exe!NtCreateSection 8056469B 7 Bytes JMP EE30555A \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwCreateProcessEx 80581F0E 7 Bytes JMP EE3059C0 \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwSetSystemInformation 805A26F4 5 Bytes JMP EE305370 \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwLoadDriver 805A410A 7 Bytes JMP EE305402 \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
PAGE ntoskrnl.exe!ZwCreateProcess 805B0B34 5 Bytes JMP EE30587C \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER)
? dhmcf.sys The system cannot find the file specified. !
.rsrc C:\WINDOWS\System32\DRIVERS\imapi.sys entry point in ".rsrc" section [0xF789C214]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\Explorer.EXE[976] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 008C000A
.text C:\WINDOWS\Explorer.EXE[976] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 008D000A
.text C:\WINDOWS\Explorer.EXE[976] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 008B000C
.text C:\WINDOWS\system32\wuauclt.exe[3416] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 003B000A
.text C:\WINDOWS\system32\wuauclt.exe[3416] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 003C000A
.text C:\WINDOWS\system32\wuauclt.exe[3416] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 003A000C
.text C:\WINDOWS\System32\svchost.exe[3956] ntdll.dll!NtProtectVirtualMemory 7C90DEB6 5 Bytes JMP 003A000A
.text C:\WINDOWS\System32\svchost.exe[3956] ntdll.dll!NtWriteVirtualMemory 7C90EA32 5 Bytes JMP 003B000A
.text C:\WINDOWS\System32\svchost.exe[3956] ntdll.dll!KiUserExceptionDispatcher 7C90EAEC 5 Bytes JMP 0039000C
.text C:\WINDOWS\System32\svchost.exe[3956] USER32.dll!GetCursorPos 77D4BD76 5 Bytes JMP 00DC000A
.text C:\WINDOWS\System32\svchost.exe[3956] ole32.dll!CoCreateInstance 774FFAC3 3 Bytes JMP 00DB000A
.text C:\WINDOWS\System32\svchost.exe[3956] ole32.dll!CoCreateInstance + 4 774FFAC7 1 Byte [89]
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device -> \Driver\atapi \Device\Harddisk0\DR0 83D51AC8
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Control.dll 499712 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\dirapi.dll 1490944 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\DynaPlayer.dll 24576 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\iml32.dll 630784 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Install.log 77819 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Plugin.dll 249856 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\PluginPing.dll 397312 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Proj.dll 151552 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\QuitRemote.exe 45056 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr 9622 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwInit.exe 77824 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwLogo.bmp 42040 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwMenu.dll 86016 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\SwOnce.dll 98304 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\UNWISE.EXE 149504 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\autodownload.txt 2379 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\CBrowser.x32 28672 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc\AnimatedGIFAssetw32 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc\MixServices 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\download\MacromediaInc\PNGImportExport 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\INetURL.x32 40960 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Multiusr.x32 159744 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Netfile.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Netlingo.x32 49152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\Xtras\Speech.x32 53248 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Control.dll 483328 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\dirapi.dll 1097728 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\dirapi.mch 41493 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Download.dll 65536 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Download.exe 40960 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\DswMedia 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\DynaPlayer.dll 24576 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\iml32.dll 561152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Install.log 35929 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Plugin.dll 249856 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\PluginPing.dll 380928 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Prefs 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Proj.dll 159744 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\QuitRemote.exe 45056 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Shockwave Log 82542 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwInit.exe 77824 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwLogo.bmp 15414 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwMenu.dll 90112 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\SwOnce.dll 94208 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\UNWISE.EXE 162304 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras 0 bytes
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\CBrowser.x32 28672 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\DirectSound.x32 32768 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Flash Asset.x32 753664 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Font Asset.x32 69632 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Font Xtra.x32 282624 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\INetURL.x32 49152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\MacroMix.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Multiusr.x32 159744 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Netfile.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Netlingo.x32 49152 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Shockwave 3d Asset.x32 1560576 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Shockwave Updater.x32 61440 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Sound Control.x32 53248 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Speech.x32 57344 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Swadcmpr.x32 69632 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Swastrm.x32 57344 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\Text Asset.x32 98304 bytes executable
File C:\WINDOWS\SYSTEM32\Macromed\Shockwave 8\Xtras\TextXtra.x32 348160 bytes executable
File C:\WINDOWS\System32\DRIVERS\imapi.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-