jeremiah
Topic Starter
I have a Windows Vista Home Premium computer infected with a Hijacker
virus. It is protected by Microsoft Security Essentials and scans were
also done with Malwarebytes and Micro Trend House Call. All report no
infections.
The hijacker shows-up whenever a Yahoo search is performed with Internet
Explorer 8, which is the client's preference.
Below are the contents of DDS.txt, followed by the contents of Gmer.txt. I have
also attached the Attach.txt file.
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 13:37:36.83 on Thu 04/22/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.894.407 [GMT -4:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\lxdiserv.exe
C:\Windows\system32\lxdicoms.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\bobby\Documents\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html
uStart Page = hxxp://yahoo.com/
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
uURLSearchHooks: MyIdentityDefender: {a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} - c:\users\bobby\appdata\locallow\cyberdefender\cdmyidd.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: MyIdentityDefender: {a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} - c:\users\bobby\appdata\locallow\cyberdefender\cdmyidd.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MyIdentityDefender: {a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} - c:\users\bobby\appdata\locallow\cyberdefender\cdmyidd.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [DVDAgent] "c:\program files\hewlett-packard\media\dvd\DVDAgent.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\picturemover\bin\PictureMover.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
IFEO: image file execution options - svchost.exe
IFEO: mrt.exe - svchost.exe
Hosts: 74.125.45.100 safebrowsing-cache.google.com
Hosts: 74.125.45.100 urs.microsoft.com
Hosts: 74.125.45.100 protected.maxisoftwaremart.com
Hosts: [removed] google.com
Hosts: [removed] google.com.au
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [2007-6-11 99248]
R3 HSXHWBS3;HSXHWBS3;c:\windows\system32\drivers\HSXHWBS3.sys [2009-2-13 206336]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-18 1343400]
=============== Created Last 30 ================
2010-04-22 02:34:38 0 —-a-w- c:\users\bobby\defogger_reenable
2010-04-20 19:51:32 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-20 19:51:30 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 19:51:30 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 12:46:55 2292 —-a-w- c:\users\bobby\_viminfo
2010-04-19 12:45:12 0 d—–w- c:\program files\Vim
2010-04-19 01:37:39 0 d—–w- c:\program files\Trend Micro
2010-04-19 01:26:54 218759758 —-a-w- c:\windows\MEMORY.DMP
2010-04-18 22:46:36 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2010-04-18 21:45:43 0 d—–w- c:\windows\pss
2010-04-18 20:42:13 0 d—–w- c:\program files\common files\Windows Live
2010-04-18 20:38:25 705536 —-a-w- c:\windows\system32\cohelper.dll
2010-04-18 20:38:25 6136 —-a-w- c:\windows\system32\drivers\nvphy.bin
2010-04-18 20:17:30 0 d—–w- c:\windows\system32\Wat
2010-04-14 22:35:30 1645320 —-a-w- c:\windows\system32\gdiplus.dll
2010-04-14 22:34:30 0 d—–w- c:\program files\Lexmark 3500-4500 Series
2010-04-14 22:24:47 0 d—–w- c:\program files\Driver Robot
2010-04-14 22:20:55 3954568 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 22:20:55 3899280 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 22:20:54 427520 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 22:20:53 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 22:20:53 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 22:20:53 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 22:18:48 132608 —-a-w- c:\windows\system32\cabview.dll
2010-04-14 22:18:40 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-11 02:22:24 0 d—–w- c:\windows\Panther
2010-04-11 02:12:57 0 d–h–w- C:\$WINDOWS.~Q
2010-04-11 02:08:19 0 d–h–w- C:\$INPLACE.~TR
2010-04-11 00:11:01 0 d—–w- c:\program files\Microsoft Security Essentials
2010-04-10 23:58:27 257024 —-a-w- c:\windows\system32\msv1_0.dll
2010-04-10 23:48:57 34816 —-a-w- c:\windows\system32\msasn1.dll
2010-04-10 23:48:57 285696 —-a-w- c:\windows\system32\winlogon.exe
2010-04-10 23:48:57 2614272 —-a-w- c:\windows\explorer.exe
2010-04-10 23:48:44 70656 —-a-w- c:\windows\system32\fontsub.dll
2010-04-10 23:48:44 293888 —-a-w- c:\windows\system32\atmfd.dll
2010-04-10 23:48:44 108544 —-a-w- c:\windows\system32\t2embed.dll
2010-04-10 23:47:46 41984 —-a-w- c:\windows\system32\drivers\usbehci.sys
2010-04-10 23:47:46 292864 —-a-w- c:\windows\system32\apphelp.dll
2010-04-10 23:47:46 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2010-04-10 23:47:45 2048 —-a-w- c:\windows\system32\tzres.dll
2010-04-10 23:46:31 641536 —-a-w- c:\windows\system32\CPFilters.dll
2010-04-10 23:46:31 417792 —-a-w- c:\windows\system32\msdri.dll
2010-04-10 23:46:31 204288 —-a-w- c:\windows\system32\MSNP.ax
2010-04-10 23:46:30 465408 —-a-w- c:\windows\system32\psisdecd.dll
2010-04-10 23:46:19 369152 —-a-w- c:\windows\system32\secproc.dll
2010-04-10 23:46:19 365568 —-a-w- c:\windows\system32\secproc_isv.dll
2010-04-10 23:46:18 85504 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-04-10 23:46:18 85504 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-04-10 23:46:18 324608 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-04-10 23:46:18 320512 —-a-w- c:\windows\system32\RMActivate.exe
2010-04-10 23:46:18 280064 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-04-10 23:46:18 277504 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-04-10 23:43:36 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-04-10 23:24:43 20 –sh–w- c:\users\bobby\ntuser.ini
2010-04-10 23:23:46 0 d-sh–w- C:\Recovery
2010-04-10 23:02:25 713888 —-a-w- c:\windows\system32\PerfStringBackup.INI
2010-04-10 23:00:44 0 d—–w- c:\windows\system32\wbem\Performance
2010-04-10 22:46:21 21316 —-a-w- c:\windows\system32\emptyregdb.dat
2010-04-10 22:25:51 9712 —ha-w- c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2010-04-10 22:25:51 9712 —ha-w- c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2010-04-10 22:25:29 0 d—–w- c:\program files\CONEXANT
2010-04-10 22:25:14 0 d—–w- c:\windows\system32\RTCOM
2010-04-10 20:37:56 74 —-a-w- c:\windows\st_affiliate.ini
2010-04-10 20:27:10 1890 —-a-w- c:\windows\diagwrn.xml
2010-04-10 20:27:10 1890 —-a-w- c:\windows\diagerr.xml
2010-04-02 18:39:38 0 d—–w- c:\programdata\Sun
2010-04-02 18:38:52 0 d—–w- c:\program files\Carbonite
2010-03-29 22:10:13 0 d—–w- c:\programdata\WindowsSearch
2010-03-26 01:29:10 0 d—–w- c:\users\bobby\appdata\roaming\Malwarebytes
2010-03-26 01:28:39 0 d—–w- c:\programdata\Malwarebytes
2010-03-25 21:51:49 0 d-sh–w- c:\programdata\CUHGBXA
2010-03-25 21:51:26 0 d-sh–w- c:\programdata\18d8e0a
==================== Find3M ====================
2010-03-22 20:35:55 2578 —-a-w- c:\users\bobby\appdata\roaming\wklnhst.dat
2010-03-09 08:28:20 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-24 14:16:06 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-23 07:56:00 977920 —-a-w- c:\windows\system32\wininet.dll
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 13:38:27.47 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-22 13:19:31
Windows 6.1.7600
Running: 9y1smdyt.exe; Driver: C:\Users\bobby\AppData\Local\Temp\pwlcypow.sys
—- System - GMER 1.0.15 —-
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E283F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E10634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E10898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E281DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E286F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E291A8
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E88599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EACF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text peauth.sys 946B2C9D 28 Bytes [84, BA, 61, DC, F8, E5, 6F, …]
.text peauth.sys 946B2CC1 28 Bytes [84, BA, 61, DC, F8, E5, 6F, …]
—- User code sections - GMER 1.0.15 —-
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtCreateFile + 6 772E4A16 4 Bytes [28, 00, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtCreateFile + B 772E4A1B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenFile + 6 772E5126 4 Bytes [68, 00, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenFile + B 772E512B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcess + 6 772E51D6 4 Bytes [A8, 01, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcess + B 772E51DB 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcessToken + B 772E51EB 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcessTokenEx + 6 772E51F6 4 Bytes [A8, 02, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcessTokenEx + B 772E51FB 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThread + 6 772E5256 4 Bytes [68, 01, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThread + B 772E525B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThreadToken + 6 772E5266 4 Bytes [68, 02, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThreadToken + B 772E526B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThreadTokenEx + B 772E527B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtQueryAttributesFile + 6 772E5386 4 Bytes [A8, 00, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtQueryAttributesFile + B 772E538B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtQueryFullAttributesFile + B 772E543B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationFile + 6 772E5A86 4 Bytes [28, 01, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationFile + B 772E5A8B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationThread + 6 772E5AE6 4 Bytes [28, 02, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationThread + B 772E5AEB 1 Byte [E2]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000003e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- EOF - GMER 1.0.15 —-
virus. It is protected by Microsoft Security Essentials and scans were
also done with Malwarebytes and Micro Trend House Call. All report no
infections.
The hijacker shows-up whenever a Yahoo search is performed with Internet
Explorer 8, which is the client's preference.
Below are the contents of DDS.txt, followed by the contents of Gmer.txt. I have
also attached the Attach.txt file.
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 13:37:36.83 on Thu 04/22/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.894.407 [GMT -4:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\lxdiserv.exe
C:\Windows\system32\lxdicoms.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\bobby\Documents\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html
uStart Page = hxxp://yahoo.com/
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
uURLSearchHooks: MyIdentityDefender: {a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} - c:\users\bobby\appdata\locallow\cyberdefender\cdmyidd.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: MyIdentityDefender: {a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} - c:\users\bobby\appdata\locallow\cyberdefender\cdmyidd.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: MyIdentityDefender: {a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} - c:\users\bobby\appdata\locallow\cyberdefender\cdmyidd.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [DVDAgent] "c:\program files\hewlett-packard\media\dvd\DVDAgent.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\picturemover\bin\PictureMover.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
IFEO: image file execution options - svchost.exe
IFEO: mrt.exe - svchost.exe
Hosts: 74.125.45.100 safebrowsing-cache.google.com
Hosts: 74.125.45.100 urs.microsoft.com
Hosts: 74.125.45.100 protected.maxisoftwaremart.com
Hosts: [removed] google.com
Hosts: [removed] google.com.au
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [2007-6-11 99248]
R3 HSXHWBS3;HSXHWBS3;c:\windows\system32\drivers\HSXHWBS3.sys [2009-2-13 206336]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-18 1343400]
=============== Created Last 30 ================
2010-04-22 02:34:38 0 —-a-w- c:\users\bobby\defogger_reenable
2010-04-20 19:51:32 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-20 19:51:30 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 19:51:30 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 12:46:55 2292 —-a-w- c:\users\bobby\_viminfo
2010-04-19 12:45:12 0 d—–w- c:\program files\Vim
2010-04-19 01:37:39 0 d—–w- c:\program files\Trend Micro
2010-04-19 01:26:54 218759758 —-a-w- c:\windows\MEMORY.DMP
2010-04-18 22:46:36 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2010-04-18 21:45:43 0 d—–w- c:\windows\pss
2010-04-18 20:42:13 0 d—–w- c:\program files\common files\Windows Live
2010-04-18 20:38:25 705536 —-a-w- c:\windows\system32\cohelper.dll
2010-04-18 20:38:25 6136 —-a-w- c:\windows\system32\drivers\nvphy.bin
2010-04-18 20:17:30 0 d—–w- c:\windows\system32\Wat
2010-04-14 22:35:30 1645320 —-a-w- c:\windows\system32\gdiplus.dll
2010-04-14 22:34:30 0 d—–w- c:\program files\Lexmark 3500-4500 Series
2010-04-14 22:24:47 0 d—–w- c:\program files\Driver Robot
2010-04-14 22:20:55 3954568 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 22:20:55 3899280 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 22:20:54 427520 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 22:20:53 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 22:20:53 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 22:20:53 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 22:18:48 132608 —-a-w- c:\windows\system32\cabview.dll
2010-04-14 22:18:40 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-11 02:22:24 0 d—–w- c:\windows\Panther
2010-04-11 02:12:57 0 d–h–w- C:\$WINDOWS.~Q
2010-04-11 02:08:19 0 d–h–w- C:\$INPLACE.~TR
2010-04-11 00:11:01 0 d—–w- c:\program files\Microsoft Security Essentials
2010-04-10 23:58:27 257024 —-a-w- c:\windows\system32\msv1_0.dll
2010-04-10 23:48:57 34816 —-a-w- c:\windows\system32\msasn1.dll
2010-04-10 23:48:57 285696 —-a-w- c:\windows\system32\winlogon.exe
2010-04-10 23:48:57 2614272 —-a-w- c:\windows\explorer.exe
2010-04-10 23:48:44 70656 —-a-w- c:\windows\system32\fontsub.dll
2010-04-10 23:48:44 293888 —-a-w- c:\windows\system32\atmfd.dll
2010-04-10 23:48:44 108544 —-a-w- c:\windows\system32\t2embed.dll
2010-04-10 23:47:46 41984 —-a-w- c:\windows\system32\drivers\usbehci.sys
2010-04-10 23:47:46 292864 —-a-w- c:\windows\system32\apphelp.dll
2010-04-10 23:47:46 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2010-04-10 23:47:45 2048 —-a-w- c:\windows\system32\tzres.dll
2010-04-10 23:46:31 641536 —-a-w- c:\windows\system32\CPFilters.dll
2010-04-10 23:46:31 417792 —-a-w- c:\windows\system32\msdri.dll
2010-04-10 23:46:31 204288 —-a-w- c:\windows\system32\MSNP.ax
2010-04-10 23:46:30 465408 —-a-w- c:\windows\system32\psisdecd.dll
2010-04-10 23:46:19 369152 —-a-w- c:\windows\system32\secproc.dll
2010-04-10 23:46:19 365568 —-a-w- c:\windows\system32\secproc_isv.dll
2010-04-10 23:46:18 85504 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-04-10 23:46:18 85504 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-04-10 23:46:18 324608 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-04-10 23:46:18 320512 —-a-w- c:\windows\system32\RMActivate.exe
2010-04-10 23:46:18 280064 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-04-10 23:46:18 277504 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-04-10 23:43:36 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-04-10 23:24:43 20 –sh–w- c:\users\bobby\ntuser.ini
2010-04-10 23:23:46 0 d-sh–w- C:\Recovery
2010-04-10 23:02:25 713888 —-a-w- c:\windows\system32\PerfStringBackup.INI
2010-04-10 23:00:44 0 d—–w- c:\windows\system32\wbem\Performance
2010-04-10 22:46:21 21316 —-a-w- c:\windows\system32\emptyregdb.dat
2010-04-10 22:25:51 9712 —ha-w- c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2010-04-10 22:25:51 9712 —ha-w- c:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2010-04-10 22:25:29 0 d—–w- c:\program files\CONEXANT
2010-04-10 22:25:14 0 d—–w- c:\windows\system32\RTCOM
2010-04-10 20:37:56 74 —-a-w- c:\windows\st_affiliate.ini
2010-04-10 20:27:10 1890 —-a-w- c:\windows\diagwrn.xml
2010-04-10 20:27:10 1890 —-a-w- c:\windows\diagerr.xml
2010-04-02 18:39:38 0 d—–w- c:\programdata\Sun
2010-04-02 18:38:52 0 d—–w- c:\program files\Carbonite
2010-03-29 22:10:13 0 d—–w- c:\programdata\WindowsSearch
2010-03-26 01:29:10 0 d—–w- c:\users\bobby\appdata\roaming\Malwarebytes
2010-03-26 01:28:39 0 d—–w- c:\programdata\Malwarebytes
2010-03-25 21:51:49 0 d-sh–w- c:\programdata\CUHGBXA
2010-03-25 21:51:26 0 d-sh–w- c:\programdata\18d8e0a
==================== Find3M ====================
2010-03-22 20:35:55 2578 —-a-w- c:\users\bobby\appdata\roaming\wklnhst.dat
2010-03-09 08:28:20 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-24 14:16:06 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-23 07:56:00 977920 —-a-w- c:\windows\system32\wininet.dll
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 13:38:27.47 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-22 13:19:31
Windows 6.1.7600
Running: 9y1smdyt.exe; Driver: C:\Users\bobby\AppData\Local\Temp\pwlcypow.sys
—- System - GMER 1.0.15 —-
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E283F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E10634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E10898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E281DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E286F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E28F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E291A8
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E88599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EACF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text peauth.sys 946B2C9D 28 Bytes [84, BA, 61, DC, F8, E5, 6F, …]
.text peauth.sys 946B2CC1 28 Bytes [84, BA, 61, DC, F8, E5, 6F, …]
—- User code sections - GMER 1.0.15 —-
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtCreateFile + 6 772E4A16 4 Bytes [28, 00, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtCreateFile + B 772E4A1B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenFile + 6 772E5126 4 Bytes [68, 00, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenFile + B 772E512B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcess + 6 772E51D6 4 Bytes [A8, 01, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcess + B 772E51DB 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcessToken + B 772E51EB 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcessTokenEx + 6 772E51F6 4 Bytes [A8, 02, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenProcessTokenEx + B 772E51FB 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThread + 6 772E5256 4 Bytes [68, 01, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThread + B 772E525B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThreadToken + 6 772E5266 4 Bytes [68, 02, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThreadToken + B 772E526B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtOpenThreadTokenEx + B 772E527B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtQueryAttributesFile + 6 772E5386 4 Bytes [A8, 00, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtQueryAttributesFile + B 772E538B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtQueryFullAttributesFile + B 772E543B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationFile + 6 772E5A86 4 Bytes [28, 01, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationFile + B 772E5A8B 1 Byte [E2]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationThread + 6 772E5AE6 4 Bytes [28, 02, 06, 00]
.text C:\Users\bobby\AppData\Local\Google\Chrome\Application\chrome.exe[3188] ntdll.dll!NtSetInformationThread + B 772E5AEB 1 Byte [E2]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000003e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- EOF - GMER 1.0.15 —-