trigun1127
2008-06-13, 22:48
didnt exactly do this in order i did gmer first
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-06-12 15:40:58
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
Code 89DE59F8 ZwCreateSection
Code 89E09648 ZwDuplicateObject
Code 89DEB018 ZwSetInformationFile
Code 89E24CE8 ZwSetSystemInformation
Code 89DE93D8 ZwWriteFile
Code 89DE59F7 NtCreateSection
Code 89E09647 NtDuplicateObject
Code 89DEB017 NtSetInformationFile
Code 89DE93D7 NtWriteFile
---- Kernel code sections - GMER 1.0.14 ----
PAGE ntkrnlpa.exe!IoGetBootDiskInformation + 66F 805757A5 7 Bytes JMP 89DD0D44
PAGE ntkrnlpa.exe!NtSetInformationFile 80579E38 7 Bytes JMP 89DEB01C
PAGE ntkrnlpa.exe!NtWriteFile 8057BCF6 7 Bytes JMP 89DE93DC
PAGE ntkrnlpa.exe!NtCreateSection 805A9E9E 7 Bytes JMP 89DE59FC
PAGE ntkrnlpa.exe!ObCloseHandle + 17 805BAF5F 7 Bytes JMP 89DD78F4
PAGE ntkrnlpa.exe!NtDuplicateObject 805BC940 7 Bytes JMP 89E0964C
PAGE ntkrnlpa.exe!ZwSetSystemInformation 8060DBEA 5 Bytes JMP 89E24CEC
PAGE Fastfat.SYS AABF6948 7 Bytes JMP 89E0E01C
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.14 ----
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[208] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\alg.exe[208] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, EB, 83 ]
.text C:\WINDOWS\System32\alg.exe[208] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 20, 84 ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe[616] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 7A, 84 ]
.text C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe[664] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[812] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[812] KERNEL32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, A8, 84 ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[844] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[844] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, BF, 84 ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[888] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[888] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 25, 84 ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[900] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[900] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 61, 84 ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1068] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 86, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1088] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 1B, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1136] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 46, 84 ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1212] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 39, 85 ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 2F, 84 ]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1280] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1300] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\Explorer.EXE[1300] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 46, 84 ]
.text C:\WINDOWS\Explorer.EXE[1300] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, E2, 83 ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1372] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, AB, 84 ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1420] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, EF, 83 ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1716] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 3E, 84 ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe[1860] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 3D, 84 ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 4B, 84 ]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[1896] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\iolo\common\lib\ioloServiceManager.exe[1980] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 98, 84 ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\PnkBstrA.exe[2040] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 1F, 84 ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
trigun1127
2008-06-13, 22:48
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 23, 84 ]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2164] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] KERNEL32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 26, 84 ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[2168] KERNEL32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 22, 84 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe[2180] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 61, 84 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe[2260] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, A4, 84 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe[2268] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 1E, 84 ]
.text C:\WINDOWS\system32\ctfmon.exe[2288] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 4C, 84 ]
.text C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe[2296] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] KERNEL32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 26, 84 ]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[2436] KERNEL32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, B9, 83 ]
.text C:\Documents and Settings\Trigun1127\Desktop\gmer\gmer.exe[3016] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, F5, 83 ]
.text C:\WINDOWS\system32\wuauclt.exe[3640] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtCreateProcess 7C90D754 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtCreateProcess + 4 7C90D758 2 Bytes [ 0E, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtCreateProcessEx 7C90D769 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 2 Bytes [ 11, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtResumeThread 7C90E45F 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtResumeThread + 4 7C90E463 2 Bytes [ 14, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtSuspendProcess 7C90E83A 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtSuspendProcess + 4 7C90E83E 2 Bytes [ 0B, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtTerminateProcess 7C90E88E 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] ntdll.dll!NtTerminateProcess + 4 7C90E892 2 Bytes [ 05, 5F ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 3A, 84 ]
.text C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe[3808] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, EF, F4 ]
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E1D600] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E1D600] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E1D600] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [B9E1D600] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E1D600] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [B9E1D410] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E1D600] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [B9E1D650] xpacket.sys (iolo Firewall Kernel Module/iolo technologies, LLC)
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Fastfat \FatCdrom Code 89E0E018
Device \FileSystem\Fastfat \Fat Code 89E0E018
---- Files - GMER 1.0.14 ----
File C:\Documents and Settings\Trigun1127\Local Settings\Temporary Internet Files\Content.IE5\1890BZOI\in-0[2] 999 bytes
File C:\Documents and Settings\Trigun1127\Local Settings\Temporary Internet Files\Content.IE5\HYDKEXJ2\in-7[1] 1446 bytes
---- EOF - GMER 1.0.14 ----
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
then i did hijack this and fixed the 2 problems here's the log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Logfile of HijackThis v1.99.1
Scan saved at 3:45:20 PM, on 6/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe
C:\Program Files\WUSB54G Wireless-G Adapter\WUSB54G.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe
C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKLM\..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe"
O4 - HKLM\..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1208391304045
O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - https://bill.netgame.com/mglaunch_USAv1002.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: WUSB54GSVC - Unknown owner - C:\Program Files\WUSB54G Wireless-G Adapter\WLService.exe" "WUSB54G.exe (file missing)