I have a few other drives (partitions) should I scan those too?
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-05-02 22:06:33
Windows 5.0.2195 Service Pack 4
---- Kernel code sections - GMER 1.0.15 ----
.text ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
---- User code sections - GMER 1.0.15 ----
.text C:\WINNT\system32\winlogon.exe[224] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\winlogon.exe[224] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\winlogon.exe[224] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\winlogon.exe[224] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\services.exe[256] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FF84493
.text C:\WINNT\system32\services.exe[256] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FF84522
.text C:\WINNT\system32\services.exe[256] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FF84518
.text C:\WINNT\system32\services.exe[256] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FF84570
.text C:\WINNT\system32\lsass.exe[268] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\lsass.exe[268] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\lsass.exe[268] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\lsass.exe[268] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Java\jre6\bin\jqs.exe[524] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Java\jre6\bin\jqs.exe[524] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Java\jre6\bin\jqs.exe[524] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Java\jre6\bin\jqs.exe[524] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE[652] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE[652] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE[652] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE[652] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\System32\svchost.exe[704] C:\WINNT\System32\svchost.exe section is writeable [0x01001000, 0x14A8, 0xE0000060]
.rsrc C:\WINNT\System32\svchost.exe[704] C:\WINNT\System32\svchost.exe section is executable [0x01004000, 0x6400, 0xE0000040]
.text C:\WINNT\System32\svchost.exe[704] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\System32\svchost.exe[704] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\System32\svchost.exe[704] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\System32\svchost.exe[704] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\PROGRA~1\MTS\ENTERN~1\app\pppoeservice.exe[724] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\PROGRA~1\MTS\ENTERN~1\app\pppoeservice.exe[724] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\PROGRA~1\MTS\ENTERN~1\app\pppoeservice.exe[724] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\PROGRA~1\MTS\ENTERN~1\app\pppoeservice.exe[724] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\regsvc.exe[768] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\regsvc.exe[768] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\regsvc.exe[768] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\regsvc.exe[768] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\System32\tcpsvcs.exe[788] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\System32\tcpsvcs.exe[788] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\System32\tcpsvcs.exe[788] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\System32\tcpsvcs.exe[788] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[804] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[804] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[804] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe[804] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\stisvc.exe[816] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\stisvc.exe[816] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\stisvc.exe[816] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\stisvc.exe[816] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\WFXSVC.EXE[852] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\WFXSVC.EXE[852] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\WFXSVC.EXE[852] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\WFXSVC.EXE[852] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Symantec\WinFax\WFXMOD32.EXE[908] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\Explorer.EXE[960] Explorer.EXE 00408199 5 Bytes [FF, 15, 70, 11, 40]
.text C:\WINNT\Explorer.EXE[960] C:\WINNT\Explorer.EXE section is writeable [0x00401000, 0x19546, 0xE0000060]
.reloc C:\WINNT\Explorer.EXE[960] C:\WINNT\Explorer.EXE section is executable [0x0043C000, 0x8000, 0xE2000040]
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\WINNT\Explorer.EXE[960] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\Explorer.EXE[960] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text C:\WINNT\Explorer.EXE[960] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text C:\WINNT\Explorer.EXE[960] WS2_32.DLL!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text C:\WINNT\Explorer.EXE[960] WS2_32.DLL!WSASend 75031525 5 Bytes CALL 7FFA5650
.text C:\WINNT\Explorer.EXE[960] WS2_32.DLL!send 75031BCC 5 Bytes JMP 7FFA57EC
.text C:\WINNT\system32\svchost.exe[1032] C:\WINNT\system32\svchost.exe section is writeable [0x01001000, 0x14A8, 0xE0000060]
.rsrc C:\WINNT\system32\svchost.exe[1032] C:\WINNT\system32\svchost.exe section is executable [0x01004000, 0x6400, 0xE0000040]
.text C:\WINNT\system32\svchost.exe[1032] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\svchost.exe[1032] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\svchost.exe[1032] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\svchost.exe[1032] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\WINNT\system32\wfxsnt40.exe[1128] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\QuickTime\qttask.exe[1136] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] WS2_32.DLL!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] WS2_32.DLL!WSASend 75031525 5 Bytes CALL 7FFA5650
.text H:\Program Files\QUICKENW\QAGENT.EXE[1148] WS2_32.DLL!send 75031BCC 5 Bytes JMP 7FFA57EC
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[1180] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\WINNT\system32\hkcmd.exe[1188] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\system32\hkcmd.exe[1188] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text C:\WINNT\system32\hkcmd.exe[1188] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text C:\WINNT\system32\hkcmd.exe[1188] WS2_32.DLL!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text C:\WINNT\system32\hkcmd.exe[1188] WS2_32.DLL!WSASend 75031525 5 Bytes CALL 7FFA5650
.text C:\WINNT\system32\hkcmd.exe[1188] WS2_32.DLL!send 75031BCC 5 Bytes JMP 7FFA57EC
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[1196] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Java\jre6\bin\jusched.exe[1212] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\WINNT\system32\VT100.EXE[1224] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\system32\VT100.EXE[1224] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text C:\WINNT\system32\VT100.EXE[1224] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text C:\WINNT\system32\VT100.EXE[1224] WS2_32.DLL!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text C:\WINNT\system32\VT100.EXE[1224] WS2_32.DLL!WSASend 75031525 5 Bytes CALL 7FFA5650
.text C:\WINNT\system32\VT100.EXE[1224] WS2_32.DLL!send 75031BCC 5 Bytes JMP 7FFA57EC
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] WS2_32.DLL!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] WS2_32.DLL!WSASend 75031525 5 Bytes CALL 7FFA5650
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe[1228] WS2_32.DLL!send 75031BCC 5 Bytes JMP 7FFA57EC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[1248] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text D:\Program Files\Adobe Pro 6\Distillr\acrotray.exe[1276] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Symantec\WinFax\WFXCTL32.EXE[1304] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!LdrLoadDll 77F85B2C 5 Bytes JMP 7FFA5090
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe[1352] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] WS2_32.DLL!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] WS2_32.DLL!WSASend 75031525 5 Bytes CALL 7FFA5650
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe[1364] WS2_32.DLL!send 75031BCC 5 Bytes JMP 7FFA57EC
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtCreateFile 77F88278 5 Bytes CALL 7FFA4493
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtCreateProcess 77F88308 5 Bytes CALL 7FFA4522
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtEnumerateValueKey 77F88448 5 Bytes JMP 7FFA511C
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtOpenFile 77F886AC 5 Bytes CALL 7FFA4518
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtQueryDirectoryFile 77F8883C 5 Bytes JMP 7FFA5324
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtQueryInformationProcess 77F888CC 5 Bytes CALL 7FFA4570
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtQuerySystemInformation 77F889DC 5 Bytes JMP 7FFA5420
.text C:\WINNT\system32\mrtMngr.EXE[1420] ntdll.dll!NtVdmControl 77F88EE8 5 Bytes JMP 7FFA53A4
.text C:\WINNT\system32\mrtMngr.EXE[1420] USER32.dll!GetWindowTextA 77E176C6 5 Bytes JMP 7FFA58A4
.text C:\WINNT\system32\mrtMngr.EXE[1420] USER32.dll!GetWindowTextW 77E2F254 5 Bytes JMP 7FFA59D8
.text C:\WINNT\system32\mrtMngr.EXE[1420] WS2_32.dll!WSARecv 7503138E 5 Bytes CALL 7FFA574C
.text C:\WINNT\system32\mrtMngr.EXE[1420] WS2_32.dll!WSASend 75031525 5 Bytes CALL 7FFA5650
.text C:\WINNT\system32\mrtMngr.EXE[1420] WS2_32.dll!send 75031BCC 5 Bytes JMP 7FFA57EC
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\Explorer.EXE [KERNEL32.DLL!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!CreateProcessA] [23021346] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\ADVAPI32.DLL [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\Secur32.dll [KERNEL32.DLL!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\Secur32.dll [KERNEL32.DLL!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\Secur32.dll [KERNEL32.DLL!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\Secur32.dll [KERNEL32.DLL!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\GDI32.DLL [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryExA] [732E78DE] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!CreateProcessA] [23021346] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHLWAPI.DLL [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [23021346] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\OLE32.DLL [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!CreateProcessW] [230214FD] C:\WINNT\AppPatch\AcLayers.DLL (Windows 2000 Shim Accessory DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\USERENV.DLL [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\NETAPI32.DLL [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WS2_32.DLL [KERNEL32.DLL!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WS2HELP.DLL [KERNEL32.DLL!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [732E786F] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [732E771E] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [732E7800] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [732E7955] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [732E78DE] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[960] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] [732E7A04] C:\WINNT\system32\shim.dll (Shim Engine DLL/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 PGPsdk.sys (PGP Software Development Kit NT Driver/PGP Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [8:160] 8156A470
---- Processes - GMER 1.0.15 ----
Process C:\WINNT\system32\VT100.EXE (*** hidden *** ) 1224
Library C:\WINNT\system32\VT100.EXE (*** hidden *** ) @ C:\WINNT\system32\VT100.EXE [1224] 0x00400000
---- Files - GMER 1.0.15 ----
File C:\WINNT\system32\VT100.EXE
File C:\WINNT\system32\mmsg32.DLL
File C:\WINNT\system32\ms2chk.DLL
File C:\WINNT\system32\mspnd.DLL
File C:\WINNT\system32\msdone.DLL
File C:\Documents and Settings\Administrator\Local Settings\Temp\mmsg32.DLL
File C:\Documents and Settings\Administrator\Local Settings\Temp\ms2chk.DLL
File C:\Documents and Settings\Administrator\Local Settings\Temp\mspnd.DLL
File C:\Documents and Settings\Administrator\Local Settings\Temp\msdone.DLL
---- EOF - GMER 1.0.15 ----