GMER 1.0.12.12011 - http://www.gmer.net Rootkit scan 2009-07-09 18:26:54 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.12 ---- Code 895651C0 ZwEnumerateKey Code 89B62218 ZwFlushInstructionCache Code 00000000 pIofCallDriver Code 895513D6 IofCallDriver Code 89C7EEDE IofCompleteRequest ---- Kernel code sections - GMER 1.0.12 ---- .text TUKERNEL.EXE!IofCallDriver 804E13A7 5 Bytes JMP 895513DB .text TUKERNEL.EXE!IofCompleteRequest 804E17BD 5 Bytes JMP 89C7EEE3 PAGE TUKERNEL.EXE!ZwEnumerateKey 80578E14 5 Bytes JMP 895651C4 PAGE TUKERNEL.EXE!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 89B6221C ---- User code sections - GMER 1.0.12 ---- .text C:\WINDOWS\system32\nvsvc32.exe[184] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 006A000A .text C:\WINDOWS\explorer.exe[360] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B5000A .text C:\WINDOWS\explorer.exe[360] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 023B1040 C:\Program Files\Stardock\CursorFX\CurXP0.dll .text C:\WINDOWS\explorer.exe[360] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 023B11E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll .text C:\WINDOWS\explorer.exe[360] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 023B1120 C:\Program Files\Stardock\CursorFX\CurXP0.dll .text C:\Program Files\Spyware Terminator\sp_rsser.exe[500] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0072000A .text C:\WINDOWS\arservice.exe[628] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0083000A .text C:\WINDOWS\system32\TUProgSt.exe[636] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0074000A .text C:\WINDOWS\ehome\ehrecvr.exe[772] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 005F000A .text C:\WINDOWS\ehome\ehSched.exe[900] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 005D000A .text ... .text C:\Documents and Settings\HP_Administrator\desktop\gmer\gmer.exe[2832] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003B000A .text C:\Documents and Settings\HP_Administrator\desktop\gmer\gmer.exe[2832] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 014F1040 .text C:\Documents and Settings\HP_Administrator\desktop\gmer\gmer.exe[2832] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 014F11E0 .text C:\Documents and Settings\HP_Administrator\desktop\gmer\gmer.exe[2832] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 014F1120 .text C:\Program Files\Stardock\ObjectDock\ObjectDock.exe[2884] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 02D71040 C:\Program Files\Stardock\CursorFX\CurXP0.dll .text C:\Program Files\Stardock\ObjectDock\ObjectDock.exe[2884] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 02D711E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll .text C:\Program Files\Stardock\ObjectDock\ObjectDock.exe[2884] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 02D71120 C:\Program Files\Stardock\CursorFX\CurXP0.dll .text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3764] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00EA000A .text C:\WINDOWS\system32\wscntfy.exe[3836] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00D5000A ---- Devices - GMER 1.0.12 ---- Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [AB9505C0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [AB9505C0] vsdatant.sys ---- Registry - GMER 1.0.12 ---- Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75344743-7046-7BF3-D3F5-CBC6A86E8EEA}@dbjffhcfchpcambhepfmiaicggopcicefiacmbnb 0x6A 0x61 0x6F 0x66 ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75344743-7046-7BF3-D3F5-CBC6A86E8EEA}@cbhflolaallhfddghnpjifklgenhbceighhdgm 0x6A 0x61 0x6F 0x66 ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75344743-7046-7BF3-D3F5-CBC6A86E8EEA}@abndnelnbgljolpkahkdhpmnedcgijbdop 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{75344743-7046-7BF3-D3F5-CBC6A86E8EEA}@maodcdjfffddanencdldmfohag 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@bbookcneollpcocbacidibbpoibccaibckoa 0x6A 0x61 0x62 0x6D ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@abeadmdogkadbclhmjbjeicpfkdndphagh 0x6A 0x61 0x63 0x6D ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@iaookcneollpcocbac 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@haeadmdogkadbclh 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@iaccjohidgpneophjl 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@abccjnodnibecjgbhpogadgjgnnmgdegig 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CFB34A0-51BF-17DC-DBDE-CC0F8C08A70D}@madclfboofkdldhdhdhhciglma 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@bbaeggmdknolaaniklpjcjcecphpmgnlbpan 0x6A 0x61 0x70 0x65 ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@abkcapamoajfcimchacnimkemmobhlaomf 0x6A 0x61 0x6D 0x64 ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@iaaeggmdknolaanikl 0x61 0x61 0x00 0x01 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@hakcapamoajfcimc 0x61 0x61 0x00 0x01 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@iambgddeefmgegcpeo 0x61 0x61 0x00 0x01 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@abmbgalgnahdbbgjjohfcdgbecmnhchikj 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@mancdclknleffddbadnamohlnf 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@dbaeggmdknolaaniklpjcjcecphplgadheglhkeh 0x6A 0x61 0x6E 0x65 ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D7AE9A4D-9F8C-9214-AF34-A6A475C11010}@cbkcapamoajfcimchacnimkemmlbmchbceildi 0x6A 0x61 0x6E 0x65 ... Reg \Registry\USER\S-1-5-21-1205235177-2945868235-3455966947-1007\Software\TrendMicro\TrendProtect\1.0\TrustedEntries@http://adultfriendfinder.com/p/imc/view_video.cgi?who=UmFuZG9tSVYEpNElUR9ZkTy8haeHZ8_4M3tMqi3UP0IqYJ755qFPxL0_TiV5j9qOIhb7T15Vt8S4aaM_3MNsDfjv82I/fYVQtj8tpAGeZKPiI757SFW_l4xqR1MzcLB0ps37bNTZ1Dx_4g/H2UIkvNveIjRvO_aX1_nJrocMiZxUyF55g441tBV4RaA_d2pkh5pVFJpIiLxNUeRFf6EYubqZWl5QSrdMp1FEwAVjlL7Vpg15oGYaiAoyW8roIsm9i8191hoepG3pwVUEP4R8O4rt_YrwyMKy2OKjbd_yV7F/hJ2UDjN9Wam8jV92YiW0uPttD5d73bP4hPGTzmxgrQ--&m=35749863_26375&site=ffadult 0 ---- Files - GMER 1.0.12 ---- ADS C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 ADS C:\Documents and Settings\HP_Administrator\Favorites\CBS.com - Innertube.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\EarthLink - Welcome to myEarthLink.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\eBay - New & used electronics, cars, apparel, collectibles, sporting goods & more at low prices.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\Entertainment\Member Home Page on Adult FriendFinder - Adult Personals and Swingers Directory.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\Entertainment\yuvutu - The home of adult amateur videos.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\Links\Amazon Mechanical Turk - Dashboard.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\Links\EarthLink - Welcome to myEarthLink.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\Links\Suggested Sites.url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\Links\Yahoo! Mail Beta (chuckfr1).url:favicon ADS C:\Documents and Settings\HP_Administrator\Favorites\SatelliteGuys.US.url:favicon ADS ... File C:\WINDOWS\system32\drivers\hjgruitwqjxlij.sys File C:\WINDOWS\system32\hjgruiefkvjrxj.dll File C:\WINDOWS\system32\hjgruiktxtscid.dat File C:\WINDOWS\system32\hjgruincmomhyv.dat File C:\WINDOWS\system32\hjgruitqhdqrek.dll File C:\WINDOWS\Temp\hjgruiajsuekskkb.tmp File C:\WINDOWS\Temp\hjgruibfbktqduyx.tmp File C:\WINDOWS\Temp\hjgruifwxlvtixuw.tmp File C:\WINDOWS\Temp\hjgruinppydstxph.tmp File C:\WINDOWS\Temp\hjgruinwrydpxshd.tmp File C:\WINDOWS\Temp\hjgruipywtvauach.tmp File C:\WINDOWS\Temp\hjgruismjphyhasl.tmp File C:\WINDOWS\Temp\hjgruiugsbmhoovq.tmp File C:\WINDOWS\Temp\hjgruivaumniapya.tmp File C:\WINDOWS\Temp\hjgruixgeiuxnrtr.tmp ---- EOF - GMER 1.0.12 ----