gmr1
GMER 1.0.12.12086 -
http://www.gmer.net
Rootkit scan 2007-04-11 20:23:11
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT 84544678 ZwAllocateVirtualMemory
SSDT 845E7E00 ZwCreateKey
SSDT 84544BA0 ZwCreateProcess
SSDT 84544B28 ZwCreateProcessEx
SSDT 84544948 ZwCreateThread
SSDT 845CFC90 ZwDeleteKey
SSDT 84544C18 ZwDeleteValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT 845446F0 ZwQueueApcThread
SSDT 84544588 ZwReadVirtualMemory
SSDT 8456E3B8 ZwRenameKey
SSDT 845447E0 ZwSetContextThread
SSDT 84544D08 ZwSetInformationKey
SSDT 84544A38 ZwSetInformationProcess
SSDT 84544858 ZwSetInformationThread
SSDT 84544C90 ZwSetValueKey
SSDT 845449C0 ZwSuspendProcess
SSDT 84544768 ZwSuspendThread
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT 845448D0 ZwTerminateThread
SSDT 84544600 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.12 ----
.text C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe[1812] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ AB, FA, C3, 83 ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!NlsMbOemCodePageTag + FFF84FE8 7C901000 23 Bytes [ A1, AC, DE, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlEnterCriticalSection + 13 7C901018 37 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlEnterCriticalSection + 39 7C90103E 74 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlEnterCriticalSection + 84 7C901089 3 Bytes [ FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlEnterCriticalSection + 8B 7C901090 51 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlEnterCriticalSection + BF 7C9010C4 2 Bytes [ FF, FF ]
.text ...
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlLeaveCriticalSection + 7 7C9010F4 8 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlLeaveCriticalSection + 10 7C9010FD 34 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlLeaveCriticalSection + 33 7C901120 16 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlTryEnterCriticalSection + 9 7C901134 55 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlTryEnterCriticalSection + 41 7C90116C 2 Bytes [ FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlTryEnterCriticalSection + 44 7C90116F 44 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!LdrInitializeThunk + 1E 7C90119C 2 Bytes [ FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!LdrInitializeThunk + 21 7C90119F 2 Bytes [ FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!LdrInitializeThunk + 24 7C9011A2 2 Bytes [ FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!LdrInitializeThunk + 27 7C9011A5 17 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlActivateActivationContextUnsafeFast + 2 7C9011B7 29 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlActivateActivationContextUnsafeFast + 20 7C9011D5 38 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 2 7C9011FC 55 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!DbgBreakPoint + 4 7C901234 9 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!DbgUserBreakPoint + 5 7C90123E 49 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitString + 14 7C901270 4 Bytes [ FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitString + 19 7C901275 8 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitString + 23 7C90127F 5 Bytes [ FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitString + 2A 7C901286 38 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitAnsiString + 14 7C9012AD 4 Bytes [ FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitAnsiString + 19 7C9012B2 8 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitAnsiString + 23 7C9012BC 5 Bytes [ FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitAnsiString + 2A 7C9012C3 38 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitUnicodeString + 14 7C9012EA 4 Bytes [ FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitUnicodeString + 19 7C9012EF 12 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitUnicodeString + 26 7C9012FC 6 Bytes [ FF, FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!RtlInitUnicodeString + 2D 7C901303 71 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!cos + 20 7C90134B 54 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!cos + 57 7C901382 10 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!cos + 63 7C90138E 63 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!log + 4 7C9013CE 118 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIlog + 73 7C901446 41 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIlog + 9E 7C901471 64 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!pow + 5 7C9014B2 241 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIpow + EE 7C9015A5 30 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIpow + 10E 7C9015C5 71 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIpow + 158 7C90160F 5 Bytes [ FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIpow + 15F 7C901616 10 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_CIpow + 16B 7C901622 7 Bytes [ FF, FF, FF, FF, FF, FF, FF ]
.text ...
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!sin + 53 7C901732 122 Bytes [ F3, F0, 75, AD, CF, 1B, 74, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!sqrt + 1B 7C9017AD 52 Bytes [ AF, 1C, 79, B5, 1D, 82, C0, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!sqrt + 51 7C9017E3 40 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!sqrt + 7A 7C90180C 813 Bytes [ 74, D1, 91, 55, BC, 7E, 46, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_allshr + 14 7C901B3A 262 Bytes [ BC, 78, E0, A0, 60, CA, 8A, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_aulldvrm + 88 7C901C41 276 Bytes [ 54, 27, 93, 5A, 2A, A0, 64, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!_memccpy + 39 7C901D56 35 Bytes [ FF, FF, FF, FF, D0, 86, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!atan + 5 7C901D7A 33 Bytes [ 45, 96, FF, 57, A7, FF, 69, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!atan + 27 7C901D9C 57 Bytes [ 86, 51, 25, 8B, 55, 28, 95, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!atan + 62 7C901DD7 237 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!ceil + A7 7C901EC5 38 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!ceil + CE 7C901EEC 84 Bytes [ 54, F2, 1C, 4E, E4, 63, 7E, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!ceil + 123 7C901F41 99 Bytes [ FF, FF, FF, 7B, 9F, F6, 42, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!floor + 48 7C901FA5 30 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!floor + 67 7C901FC4 204 Bytes [ 45, 94, FF, 4B, 98, FF, 44, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!floor + 134 7C902091 115 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memchr + 60 7C902105 7 Bytes [ FF, FF, FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memchr + 68 7C90210D 193 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcmp + 80 7C9021CF 28 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcmp + 9D 7C9021EC 5 Bytes [ FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcmp + A3 7C9021F2 67 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcpy + 36 7C902236 23 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcpy + 4E 7C90224E 6 Bytes [ FF, FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcpy + 55 7C902255 7 Bytes [ FF, FF, FF, FF, FF, FF, FF ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcpy + 5D 7C90225D 53 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text C:\Program Files\WinRAR\WinRAR.exe[3940] ntdll.dll!memcpy + 93 7C902293 37 Bytes [ FF, FF, FF, FF, FF, FF, FF, ... ]
.text ...