Gmerauto:
GMER 1.0.15.14972 -
http://www.gmer.net
Autostart scan 2009-06-17 21:07:21
Windows 5.1.2600 Service Pack 3
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
@Taskmanc:\windows\system32\rundll32.exe = c:\windows\system32\rundll32.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
!SASWinLogon@DLLName = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
AtiExtEvent@DLLName = Ati2evxx.dll
dimsntfy@DLLName = %SystemRoot%\System32\dimsntfy.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
.norton2009Reset@ = C:\Documents and Settings\All Users\Application Data\Norton\Norton2009Reset.exe /*file not found*/
aawservice@ = "C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe"
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
ehRecvr@ = C:\WINDOWS\eHome\ehRecvr.exe
ehSched@ = C:\WINDOWS\eHome\ehSched.exe
gusvc@ = "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
hpqwmiex@ = C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
JavaQuickStarterService@ = "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
LightScribeService@ = "C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe"
LVPrcSrv@ = "C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe"
LVSrvLauncher@ = C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
McrdSvc@ = C:\WINDOWS\ehome\mcrdsvc.exe
MDM@ = "C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE"
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SeaPort@ = "C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ehTrayC:\WINDOWS\ehome\ehtray.exe = C:\WINDOWS\ehome\ehtray.exe
@ATIPTA"C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
@RecGuardC:\Windows\SMINST\RecGuard.exe = C:\Windows\SMINST\RecGuard.exe
@SunJavaUpdateSched"C:\Program Files\Java\jre6\bin\jusched.exe" = "C:\Program Files\Java\jre6\bin\jusched.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run@ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} = C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Extension Affichage Panorama du Panneau de configuration*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\system32\twext.dll = C:\WINDOWS\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\system32\twext.dll = C:\WINDOWS\system32\twext.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{2F603045-309F-11CF-9774-0020AFD0CFF6} /*Synaptics Control Panel*/C:\Program Files\Synaptics\SynTP\SynTPCpl.dll = C:\Program Files\Synaptics\SynTP\SynTPCpl.dll
@{7F67036B-66F1-411A-AD85-759FB9C5B0DB} /*ShellViewRTF*/C:\WINDOWS\system32\ShellvRTF.dll = C:\WINDOWS\system32\ShellvRTF.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/c:\WINDOWS\system32\dfshim.dll = c:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/c:\WINDOWS\system32\dfshim.dll = c:\WINDOWS\system32\dfshim.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Dossiers Web*/C:\PROGRA~1\FICHIE~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FICHIE~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Program Files\iTunes\iTunesMiniPlayer.dll = C:\Program Files\iTunes\iTunesMiniPlayer.dll
@{36D94110-787C-4828-9C1B-0DAFEBC36069} /*EditPlus 3*/C:\Program Files\EditPlus 3\eppshell.dll = C:\Program Files\EditPlus 3\eppshell.dll
@{0563DB41-F538-4B37-A92D-4659049B7766} /*WLMD Message Handler*/C:\Program Files\Windows Live\Mail\mailcomm.dll = C:\Program Files\Windows Live\Mail\mailcomm.dll
@{06A2568A-CED6-4187-BB20-400B8C02BE5A} /**/(null) =
@{00F33137-EE26-412F-8D71-F84E4C2C6625} /**/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} /*Windows Live Photo Gallery Autoplay Drop Target*/(null) =
@{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} /*Windows Live Photo Gallery Viewer Drop Target*/(null) =
@{00F374B7-B390-4884-B372-2FC349F2172B} /*Windows Live Photo Gallery Editor Drop Target*/(null) =
@{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} /*Windows Live Photo Gallery Viewer Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} /*Windows Live Photo Gallery Editor Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00F30F90-3E96-453B-AFCD-D71989ECC2C7} /*Windows Live Photo Gallery Autoplay Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{11016101-E366-4D22-BC06-4ADA335C892B} /*IE History and Feeds Shell Data Source for Windows Search*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{8856f961-340a-11d0-a96b-00c04fd705a2} /*Microsoft Web Browser*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/(null) =
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} /*UnlockerShellExtension*/C:\Program Files\Unlocker\UnlockerCOM.dll = C:\Program Files\Unlocker\UnlockerCOM.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
EditPlus 3@{36D94110-787C-4828-9C1B-0DAFEBC36069} = C:\Program Files\EditPlus 3\eppshell.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
MBAMShlExt@{57CE581A-0CB6-4266-9CA0-19364C90A0B3} = C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
UnlockerShellExtension@{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} = C:\Program Files\Unlocker\UnlockerCOM.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{02478D38-C3F9-4efb-9B51-7695ECA05670}C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll = C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
@{18DF081C-E8AD-4283-A596-FA578C2EBDC3}C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll = C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
@{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}C:\Program Files\AVG\AVG8\avgssie.dll /*file not found*/ = C:\Program Files\AVG\AVG8\avgssie.dll /*file not found*/
@{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll = C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
@{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll = C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
@{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dll = C:\Program Files\Java\jre6\bin\jp2ssv.dll
@{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}C:\Program Files\Windows Live\Toolbar\wltcore.dll = C:\Program Files\Windows Live\Toolbar\wltcore.dll
@{E7E6F031-17CE-4C07-BC86-EABFE594F69C}C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll = C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
@{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll = C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\system32\ssmypics.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft.com/fwlink/?LinkId=69157
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://google.ca/ =
http://google.ca/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
linkscanner@CLSID = C:\Program Files\AVG\AVG8\avgpp.dll /*file not found*/
livecall@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll
HKLM\Software\Classes\PROTOCOLS\Handler\wlmailhtml@CLSID = C:\Program Files\Windows Live\Mail\mailcomm.dll
---- EOF - GMER 1.0.15 ----
Gmerroot:
{\rtf1\ansi\ansicpg1252\deff0\deflang3084{\fonttbl{\f0\fswiss\fcharset0 Arial;}}
{\*\generator Msftedit 5.41.15.1515;}\viewkind4\uc1\pard\f0\fs20 GMER 1.0.15.14972 -
http://www.gmer.net\par
Rootkit scan 2009-06-17 21:06:22\par
Windows 5.1.2600 Service Pack 3\par
\par
\par
---- System - GMER 1.0.15 ----\par
\par
SSDT spjl.sys ZwCreateKey [0xF74120E0] <-- ROOTKIT !!!\par
SSDT spjl.sys ZwEnumerateKey [0xF7430CA2] <-- ROOTKIT !!!\par
SSDT spjl.sys ZwEnumerateValueKey [0xF7431030] <-- ROOTKIT !!!\par
SSDT spjl.sys ZwOpenKey [0xF74120C0] <-- ROOTKIT !!!\par
SSDT spjl.sys ZwQueryKey [0xF7431108] <-- ROOTKIT !!!\par
SSDT spjl.sys ZwQueryValueKey [0xF7430F88] <-- ROOTKIT !!!\par
SSDT spjl.sys ZwSetValueKey [0xF743119A] <-- ROOTKIT !!!\par
\par
INT 0x62 ? 8676CBF8\par
INT 0x82 ? 8676CBF8\par
INT 0xB4 ? 864ECBF8\par
INT 0xB4 ? 864ECBF8\par
INT 0xB4 ? 864ECBF8\par
INT 0xB4 ? 864ECBF8\par
\par
Code 860CA2D0 ZwFlushInstructionCache\par
Code 860B12D6 IofCallDriver\par
Code 860B5A76 IofCompleteRequest\par
\par
---- Kernel code sections - GMER 1.0.15 ----\par
\par
.text ntkrnlpa.exe!IofCallDriver 804EE130 5 Bytes JMP 860B12DB \par
.text ntkrnlpa.exe!IofCompleteRequest 804EE1C0 5 Bytes JMP 860B5A7B \par
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805ABEC4 5 Bytes JMP 860CA2D4 \par
? spjl.sys Le fichier sp\'e9cifi\'e9 est introuvable. !\par
.text USBPORT.SYS!DllUnload F699F8AC 5 Bytes JMP 864EC1D8 \par
\par
---- User code sections - GMER 1.0.15 ----\par
\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 40D851D5 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 40E5D2C4 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!DialogBoxIndirectParamW 7E3B2072 5 Bytes JMP 40F7B6CB C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!MessageBoxIndirectA 7E3BA082 5 Bytes JMP 40F7B5FD C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!DialogBoxParamA 7E3BB144 5 Bytes JMP 40F7B668 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!MessageBoxExW 7E3D0838 5 Bytes JMP 40F7B4CE C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!MessageBoxExA 7E3D085C 5 Bytes JMP 40F7B530 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!DialogBoxIndirectParamA 7E3D6D7D 5 Bytes JMP 40F7B72E C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[472] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 40F7B592 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 40D851D5 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 40E5D2C4 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!DialogBoxIndirectParamW 7E3B2072 5 Bytes JMP 40F7B6CB C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!MessageBoxIndirectA 7E3BA082 5 Bytes JMP 40F7B5FD C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!DialogBoxParamA 7E3BB144 5 Bytes JMP 40F7B668 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!MessageBoxExW 7E3D0838 5 Bytes JMP 40F7B4CE C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!MessageBoxExA 7E3D085C 5 Bytes JMP 40F7B530 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!DialogBoxIndirectParamA 7E3D6D7D 5 Bytes JMP 40F7B72E C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[1524] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 40F7B592 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 40D851D5 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!SetWindowsHookExW 7E3A820F 5 Bytes JMP 40E59261 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!CallNextHookEx 7E3AB3C6 5 Bytes JMP 40E4C8A9 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 40E5D2C4 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!UnhookWindowsHookEx 7E3AD5F3 5 Bytes JMP 40DC4254 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!DialogBoxIndirectParamW 7E3B2072 5 Bytes JMP 40F7B6CB C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!MessageBoxIndirectA 7E3BA082 5 Bytes JMP 40F7B5FD C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!DialogBoxParamA 7E3BB144 5 Bytes JMP 40F7B668 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!MessageBoxExW 7E3D0838 5 Bytes JMP 40F7B4CE C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!MessageBoxExA 7E3D085C 5 Bytes JMP 40F7B530 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!DialogBoxIndirectParamA 7E3D6D7D 5 Bytes JMP 40F7B72E C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 40F7B592 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] ole32.dll!CoCreateInstance 774C057E 5 Bytes JMP 40E5D320 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] WS2_32.dll!getaddrinfo 719F2A6F 5 Bytes JMP 46CAE71D C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 46CAEEE9 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] WS2_32.dll!socket 719F4211 5 Bytes JMP 46CAE59E C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] WS2_32.dll!connect 719F4A07 5 Bytes JMP 46CAE62A C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] WS2_32.dll!send 719F4C27 5 Bytes JMP 46CAE9ED C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] WS2_32.dll!recv 719F676F 5 Bytes JMP 46CAF1C3 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 40D851D5 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!SetWindowsHookExW 7E3A820F 5 Bytes JMP 40E59261 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!CallNextHookEx 7E3AB3C6 5 Bytes JMP 40E4C8A9 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 40E5D2C4 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!UnhookWindowsHookEx 7E3AD5F3 5 Bytes JMP 40DC4254 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!DialogBoxIndirectParamW 7E3B2072 5 Bytes JMP 40F7B6CB C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!MessageBoxIndirectA 7E3BA082 5 Bytes JMP 40F7B5FD C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!DialogBoxParamA 7E3BB144 5 Bytes JMP 40F7B668 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!MessageBoxExW 7E3D0838 5 Bytes JMP 40F7B4CE C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!MessageBoxExA 7E3D085C 5 Bytes JMP 40F7B530 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!DialogBoxIndirectParamA 7E3D6D7D 5 Bytes JMP 40F7B72E C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 40F7B592 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] ole32.dll!CoCreateInstance 774C057E 5 Bytes JMP 40E5D320 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] WS2_32.dll!getaddrinfo 719F2A6F 5 Bytes JMP 46CAE71D C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 46CAEEE9 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] WS2_32.dll!socket 719F4211 5 Bytes JMP 46CAE59E C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] WS2_32.dll!connect 719F4A07 5 Bytes JMP 46CAE62A C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] WS2_32.dll!send 719F4C27 5 Bytes JMP 46CAE9ED C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] WS2_32.dll!recv 719F676F 5 Bytes JMP 46CAF1C3 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 40D851D5 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!SetWindowsHookExW 7E3A820F 5 Bytes JMP 40E59261 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!CallNextHookEx 7E3AB3C6 5 Bytes JMP 40E4C8A9 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 40E5D2C4 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!UnhookWindowsHookEx 7E3AD5F3 5 Bytes JMP 40DC4254 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!DialogBoxIndirectParamW 7E3B2072 5 Bytes JMP 40F7B6CB C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!MessageBoxIndirectA 7E3BA082 5 Bytes JMP 40F7B5FD C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!DialogBoxParamA 7E3BB144 5 Bytes JMP 40F7B668 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!MessageBoxExW 7E3D0838 5 Bytes JMP 40F7B4CE C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!MessageBoxExA 7E3D085C 5 Bytes JMP 40F7B530 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!DialogBoxIndirectParamA 7E3D6D7D 5 Bytes JMP 40F7B72E C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 40F7B592 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] ole32.dll!CoCreateInstance 774C057E 5 Bytes JMP 40E5D320 C:\\WINDOWS\\system32\\IEFRAME.dll (Internet Explorer/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] WS2_32.dll!getaddrinfo 719F2A6F 5 Bytes JMP 46CAE71D C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 46CAEEE9 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] WS2_32.dll!socket 719F4211 5 Bytes JMP 46CAE59E C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] WS2_32.dll!connect 719F4A07 5 Bytes JMP 46CAE62A C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] WS2_32.dll!send 719F4C27 5 Bytes JMP 46CAE9ED C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
.text C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] WS2_32.dll!recv 719F676F 5 Bytes JMP 46CAF1C3 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)\par
\par
---- Kernel IAT/EAT - GMER 1.0.15 ----\par
\par
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7413040] spjl.sys\par
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F741313C] spjl.sys\par
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74130BE] spjl.sys\par
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74137FC] spjl.sys\par
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74136D2] spjl.sys\par
IAT \\SystemRoot\\system32\\DRIVERS\\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7423048] spjl.sys\par
\par
---- User IAT/EAT - GMER 1.0.15 ----\par
\par
IAT C:\\WINDOWS\\Explorer.EXE[1872] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtCreateFile] [017F2F20] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\WINDOWS\\Explorer.EXE[1872] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [017F2C90] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\WINDOWS\\Explorer.EXE[1872] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtClose] [017F2CF0] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\WINDOWS\\Explorer.EXE[1872] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtDuplicateObject] [017F2CC0] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\Program Files\\Internet Explorer\\iexplore.exe[2672] @ C:\\WINDOWS\\system32\\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00CF1A7B] C:\\Program Files\\Internet Explorer\\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)\par
IAT C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[2988] @ C:\\WINDOWS\\system32\\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00CF1A7B] C:\\Program Files\\Internet Explorer\\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)\par
IAT C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe[3184] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtCreateFile] [011C2F20] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe[3184] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [011C2C90] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe[3184] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtClose] [011C2CF0] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe[3184] @ C:\\WINDOWS\\system32\\kernel32.dll [ntdll.dll!NtDuplicateObject] [011C2CC0] C:\\WINDOWS\\TEMP\\logishrd\\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)\par
IAT C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE[3232] @ C:\\WINDOWS\\system32\\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00CF1A7B] C:\\Program Files\\Internet Explorer\\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)\par
\par
---- Devices - GMER 1.0.15 ----\par
\par
Device \\FileSystem\\Ntfs \\Ntfs 8676B1F8\par
Device \\FileSystem\\Fastfat \\FatCdrom 864601F8\par
Device \\FileSystem\\Udfs \\UdfsCdRom 85F56500\par
Device \\FileSystem\\Udfs \\UdfsDisk 85F56500\par
\par
AttachedDevice \\Driver\\Kbdclass \\Device\\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)\par
AttachedDevice \\Driver\\Kbdclass \\Device\\KeyboardClass0 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)\par
AttachedDevice \\Driver\\Kbdclass \\Device\\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)\par
AttachedDevice \\Driver\\Kbdclass \\Device\\KeyboardClass1 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)\par
\par
Device \\Driver\\usbohci \\Device\\USBPDO-0 865971F8\par
Device \\Driver\\sptd \\Device\\2956931500 spjl.sys\par
Device \\Driver\\dmio \\Device\\DmControl\\DmIoDaemon 867DA1F8\par
Device \\Driver\\dmio \\Device\\DmControl\\DmConfig 867DA1F8\par
Device \\Driver\\dmio \\Device\\DmControl\\DmPnP 867DA1F8\par
Device \\Driver\\dmio \\Device\\DmControl\\DmInfo 867DA1F8\par
Device \\Driver\\usbohci \\Device\\USBPDO-1 865971F8\par
Device \\Driver\\usbehci \\Device\\USBPDO-2 864E01F8\par
\par
AttachedDevice \\Driver\\Tcpip \\Device\\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)\par
\par
Device \\Driver\\NetBT \\Device\\NetBT_Tcpip_\{73DB523D-89C5-43E9-96B5-BFB1B8412A94\} 860C8500\par
Device \\Driver\\Ftdisk \\Device\\HarddiskVolume1 8676D1F8\par
Device \\Driver\\Ftdisk \\Device\\HarddiskVolume2 8676D1F8\par
Device \\Driver\\Cdrom \\Device\\CdRom0 865831F8\par
Device \\Driver\\Ftdisk \\Device\\HarddiskVolume3 8676D1F8\par
Device \\Driver\\NetBT \\Device\\NetBt_Wins_Export 860C8500\par
Device \\Driver\\PCI_PNP6500 \\Device\\0000004a spjl.sys\par
Device \\Driver\\NetBT \\Device\\NetbiosSmb 860C8500\par
Device \\Driver\\NetBT \\Device\\NetBT_Tcpip_\{97B23597-C1DC-44A7-B352-43DC930AB013\} 860C8500\par
Device \\Driver\\usbohci \\Device\\USBFDO-0 865971F8\par
Device \\Driver\\usbohci \\Device\\USBFDO-1 865971F8\par
Device \\FileSystem\\MRxSmb \\Device\\LanmanDatagramReceiver 86090500\par
Device \\Driver\\usbehci \\Device\\USBFDO-2 864E01F8\par
Device \\FileSystem\\MRxSmb \\Device\\LanmanRedirector 86090500\par
Device \\Driver\\Ftdisk \\Device\\FtControl 8676D1F8\par
Device \\Driver\\ajsenn8v \\Device\\Scsi\\ajsenn8v1 863E51F8\par
Device \\Driver\\ajsenn8v \\Device\\Scsi\\ajsenn8v1Port3Path0Target0Lun0 863E51F8\par
Device \\FileSystem\\Fastfat \\Fat 864601F8\par
\par
AttachedDevice \\FileSystem\\Fastfat \\Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)\par
\par
Device \\FileSystem\\Cdfs \\Cdfs 864F8500\par
---- Processes - GMER 1.0.15 ----\par
\par
Library \\\\?\\globalroot\\systemroot\\system32\\MSIVXucqldmxnyvbmgqnufxilltimouetpqqk.dll (*** hidden *** ) @ C:\\WINDOWS\\system32\\svchost.exe [1100] 0x10000000 \par
\par
---- Services - GMER 1.0.15 ----\par
\par
Service C:\\WINDOWS\\system32\\drivers\\MSIVXcokwfhcstriwwsbtaijjtkmcqmahkbju.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <-- ROOTKIT !!!\par
\par
---- Registry - GMER 1.0.15 ----\par
\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys \par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys@start 1\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys@type 1\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys@imagepath \\systemroot\\system32\\drivers\\MSIVXcokwfhcstriwwsbtaijjtkmcqmahkbju.sys\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys@group file system\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys\\modules \par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys\\modules@MSIVXserv \\\\?\\globalroot\\systemroot\\system32\\drivers\\MSIVXcokwfhcstriwwsbtaijjtkmcqmahkbju.sys\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys\\modules@MSIVXl \\\\?\\globalroot\\systemroot\\system32\\MSIVXucqldmxnyvbmgqnufxilltimouetpqqk.dll\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\MSIVXserv.sys\\modules@MSIVXclk \\\\?\\globalroot\\systemroot\\system32\\MSIVXgwhyefyymqcsqviadnvexakdqotcjgoa.dll\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg@s1 771343423\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg@s2 285507792\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg@h0 1\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4 \par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4@p0 C:\\Program Files\\DAEMON Tools Lite\\\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4@h0 0\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4@khjeh 0xCD 0x6A 0x00 0x22 ...\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001 \par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001@a0 0x20 0x01 0x00 0x00 ...\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001@khjeh 0xD0 0x61 0xA9 0x71 ...\par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001\\0Jf40 \par
Reg HKLM\\SYSTEM\\CurrentControlSet\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001\\0Jf40@khjeh 0x12 0xE3 0xDB 0xFF ...\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys \par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys@start 1\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys@type 1\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys@imagepath \\systemroot\\system32\\drivers\\MSIVXcokwfhcstriwwsbtaijjtkmcqmahkbju.sys\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys@group file system\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys\\modules \par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys\\modules@MSIVXserv \\\\?\\globalroot\\systemroot\\system32\\drivers\\MSIVXcokwfhcstriwwsbtaijjtkmcqmahkbju.sys\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys\\modules@MSIVXl \\\\?\\globalroot\\systemroot\\system32\\MSIVXucqldmxnyvbmgqnufxilltimouetpqqk.dll\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\MSIVXserv.sys\\modules@MSIVXclk \\\\?\\globalroot\\systemroot\\system32\\MSIVXgwhyefyymqcsqviadnvexakdqotcjgoa.dll\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4 \par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4@p0 C:\\Program Files\\DAEMON Tools Lite\\\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4@h0 0\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4@khjeh 0xCD 0x6A 0x00 0x22 ...\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001 \par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001@a0 0x20 0x01 0x00 0x00 ...\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001@khjeh 0xD0 0x61 0xA9 0x71 ...\par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001\\0Jf40 \par
Reg HKLM\\SYSTEM\\ControlSet003\\Services\\sptd\\Cfg\\19659239224E364682FA4BAF72C53EA4\\00000001\\0Jf40@khjeh 0x12 0xE3 0xDB 0xFF ...\par
\par
---- Files - GMER 1.0.15 ----\par
\par
File C:\\WINDOWS\\system32\\drivers\\MSIVXcokwfhcstriwwsbtaijjtkmcqmahkbju.sys 80384 bytes executable <-- ROOTKIT !!!\par
File C:\\WINDOWS\\system32\\MSIVXcount 4 bytes\par
File C:\\WINDOWS\\system32\\MSIVXgwhyefyymqcsqviadnvexakdqotcjgoa.dll 52224 bytes executable\par
File C:\\WINDOWS\\system32\\MSIVXucqldmxnyvbmgqnufxilltimouetpqqk.dll 26624 bytes executable\par
\par
---- EOF - GMER 1.0.15 ----\par
}