MagicMike
2007-11-18, 14:44
Hi!
I am trying to help a close friend whose computer has been invaded by adware and popups entitled fp.pc-on-internet.com. The popups only appear when on-line. He is based in UK using Windows XP Home(still on dial-up). I found an earlier thread connecting this infection to Navipromo. I have followed the instructions given by Shaba in Finland and have downloaded GMER and BFU. But I cannot find the same filename of C:\WINDOWS\system32\kdgubtic.exe. But below is the latest scan by GMER. Can anyone throw some light on the offending files please. Many Thanks! Mike C.
Here is the first half of latest GMER scan. I will have to post the other half separately because of size.GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-11-17 21:46:20
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT 83C09FD0 ZwAlertResumeThread
SSDT 83FC4168 ZwAlertThread
SSDT 83FC7748 ZwAllocateVirtualMemory
SSDT 83FFDFB0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwCreateKey
SSDT 83C09D40 ZwCreateMutant
SSDT 83FC4BA8 ZwCreateThread
SSDT 83C099C0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteValueKey
SSDT 83FC49C8 ZwFreeVirtualMemory
SSDT 83C09E30 ZwImpersonateAnonymousToken
SSDT 83C09F10 ZwImpersonateThread
SSDT 83FC48C8 ZwMapViewOfSection
SSDT 83C09C60 ZwOpenEvent
SSDT 83FE3E18 ZwOpenProcessToken
SSDT 83C09AA0 ZwOpenSection
SSDT 83FC4640 ZwOpenThreadToken
SSDT 83FE3D40 ZwResumeThread
SSDT 83FC4560 ZwSetContextThread
SSDT 83FC4730 ZwSetInformationProcess
SSDT 83FC4470 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwSetValueKey
SSDT 83C09B80 ZwSuspendProcess
SSDT 83FC42B0 ZwSuspendThread
SSDT 83FE3CD0 ZwTerminateProcess
SSDT 83FC4390 ZwTerminateThread
SSDT 83FE0CE8 ZwUnmapViewOfSection
SSDT 83FC4AB8 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D9200E
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D91DAF
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D91CF2
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D9191B
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BE200E
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BE1DAF
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BE1CF2
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BE191B
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00C7200E
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00C71DAF
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00C71CF2
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00C7191B
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00FC200E
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00FC1DAF
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00FC1CF2
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00FC191B
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0098200E
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00981DAF
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00981CF2
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0098191B
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0099200E
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00991DAF
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00991CF2
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0099191B
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00EB200E
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00EB1DAF
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00EB1CF2
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00EB191B
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0097200E
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00971DAF
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00971CF2
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0097191B
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01AA200E
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01AA1DAF
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01AA1CF2
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01AA191B
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 009A200E
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 009A1DAF
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009A1CF2
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009A191B
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0166200E
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01661DAF
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01661CF2
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0166191B
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D7200E
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D71DAF
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D71CF2
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D7191B
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A5200E
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A51DAF
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A51CF2
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A5191B
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BB200E
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BB1DAF
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BB1CF2
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BB191B
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BA200E
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BA1DAF
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BA1CF2
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BA191B
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00AE200E
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00AE1DAF
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00AE1CF2
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00AE191B
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D6200E
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D61DAF
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D61CF2
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D6191B
I am trying to help a close friend whose computer has been invaded by adware and popups entitled fp.pc-on-internet.com. The popups only appear when on-line. He is based in UK using Windows XP Home(still on dial-up). I found an earlier thread connecting this infection to Navipromo. I have followed the instructions given by Shaba in Finland and have downloaded GMER and BFU. But I cannot find the same filename of C:\WINDOWS\system32\kdgubtic.exe. But below is the latest scan by GMER. Can anyone throw some light on the offending files please. Many Thanks! Mike C.
Here is the first half of latest GMER scan. I will have to post the other half separately because of size.GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-11-17 21:46:20
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT 83C09FD0 ZwAlertResumeThread
SSDT 83FC4168 ZwAlertThread
SSDT 83FC7748 ZwAllocateVirtualMemory
SSDT 83FFDFB0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwCreateKey
SSDT 83C09D40 ZwCreateMutant
SSDT 83FC4BA8 ZwCreateThread
SSDT 83C099C0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteValueKey
SSDT 83FC49C8 ZwFreeVirtualMemory
SSDT 83C09E30 ZwImpersonateAnonymousToken
SSDT 83C09F10 ZwImpersonateThread
SSDT 83FC48C8 ZwMapViewOfSection
SSDT 83C09C60 ZwOpenEvent
SSDT 83FE3E18 ZwOpenProcessToken
SSDT 83C09AA0 ZwOpenSection
SSDT 83FC4640 ZwOpenThreadToken
SSDT 83FE3D40 ZwResumeThread
SSDT 83FC4560 ZwSetContextThread
SSDT 83FC4730 ZwSetInformationProcess
SSDT 83FC4470 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwSetValueKey
SSDT 83C09B80 ZwSuspendProcess
SSDT 83FC42B0 ZwSuspendThread
SSDT 83FE3CD0 ZwTerminateProcess
SSDT 83FC4390 ZwTerminateThread
SSDT 83FE0CE8 ZwUnmapViewOfSection
SSDT 83FC4AB8 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[220] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D9200E
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D91DAF
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D91CF2
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[360] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D9191B
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BE200E
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BE1DAF
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BE1CF2
.text C:\WINDOWS\SOUNDMAN.EXE[460] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BE191B
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00C7200E
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00C71DAF
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00C71CF2
.text C:\WINDOWS\sm56hlpr.exe[492] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00C7191B
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe[520] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00FC200E
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00FC1DAF
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00FC1CF2
.text C:\Acer\Empowering Technology\eRecovery\Monitor.exe[532] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00FC191B
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0098200E
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00981DAF
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00981CF2
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[536] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0098191B
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0099200E
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00991DAF
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00991CF2
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[560] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0099191B
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00EB200E
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00EB1DAF
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00EB1CF2
.text C:\Program Files\Picasa2\PicasaMediaDetector.exe[580] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00EB191B
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0097200E
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00971DAF
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00971CF2
.text C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE[620] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0097191B
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01AA200E
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01AA1DAF
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01AA1CF2
.text C:\Program Files\Seekmo\bin\10.0.345.0\SeekmoSA.exe[672] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01AA191B
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 009A200E
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 009A1DAF
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009A1CF2
.text C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe[708] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 009A191B
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\csrss.exe[720] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\services.exe[788] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[968] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\System32\svchost.exe[1092] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 0166200E
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01661DAF
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01661CF2
.text C:\windows\system32\kamkuz.exe[1352] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0166191B
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D7200E
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D71DAF
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D71CF2
.text C:\Program Files\Messenger\msmsgs.exe[1508] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D7191B
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\spoolsv.exe[1632] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A5200E
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A51DAF
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A51CF2
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[1664] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A5191B
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BB200E
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BB1DAF
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BB1CF2
.text C:\WINDOWS\Explorer.EXE[1740] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BB191B
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00BA200E
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00BA1DAF
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00BA1CF2
.text C:\WINDOWS\system32\sistray.exe[1868] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00BA191B
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00AE200E
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00AE1DAF
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00AE1CF2
.text C:\WINDOWS\system32\rundll32.exe[3072] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00AE191B
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\wuauclt.exe[3236] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00D6200E
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00D61DAF
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D61CF2
.text C:\Documents and Settings\dads accounts\Desktop\gmer.exe[3460] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00D6191B