DDS.txt
*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 8:24:38.90 on 21/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.231 [GMT 4:00]
AV: Norton AntiVirus Online *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
D:\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRunOnce: [SpybotDeletingB951] command /c del "c:\windows\SchedLgU.Txt"
uRunOnce: [SpybotDeletingD2868] cmd /c del "c:\windows\SchedLgU.Txt"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Etisalat Modem Protector] c:\program files\etisalat modem protector\Modem Protector.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\WECPUpdate.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRunOnce: [SpybotDeletingC3094] cmd /c del "c:\windows\SchedLgU.Txt"
mRunOnce: [SpybotDeletingA6511] command /c del "c:\windows\SchedLgU.Txt"
dRunOnce: [<NO NAME>]
mExplorerRun: [<NO NAME>] 1 (0x1)
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\SHORTC~1.LNK -
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: InternetConnection - {B1A95BA3-3827-4F63-A75E-009E2B48A48F} - No File
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090820.022\NAVENG.SYS [2009-8-21 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090820.022\NAVEX15.SYS [2009-8-21 875728]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-8-30 23888]
=============== Created Last 30 ================
2009-08-15 11:10 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-08-15 11:10 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 11:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-15 11:10 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-15 11:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 13:46 <DIR> --d----- c:\docume~1\admini~1\applic~1\Symantec
2009-08-02 05:41 <DIR> --ds---- C:\ComboFix
2009-08-01 19:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-01 19:52 <DIR> a-dshr-- C:\cmdcons
2009-08-01 19:47 219,648 a------- c:\windows\PEV.exe
2009-08-01 19:47 161,792 a------- c:\windows\SWREG.exe
2009-08-01 19:47 98,816 a------- c:\windows\sed.exe
2009-07-29 05:35 <DIR> --d----- c:\program files\Trend Micro
2009-07-28 05:47 82 a------- c:\windows\wininit.ini
==================== Find3M ====================
2009-07-20 12:54 737,280 a------- c:\windows\iun6002.exe
2009-07-19 22:37 98,304 a------- c:\windows\system32\CmdLineExt.dll
============= FINISH: 8:25:34.31 ===============
Attach.txt
*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-07-30.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 10/9/2008 8:09:41 PM
System Uptime: 8/15/2009 1:07:21 PM (139 hours ago)
Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2993/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 71 GiB total, 2.179 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 55.742 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
H: is Removable
I: is FIXED (FAT32) - 466 GiB total, 207.791 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP203: 5/23/2009 8:32:52 AM - System Checkpoint
RP204: 5/24/2009 9:24:30 AM - System Checkpoint
RP205: 5/25/2009 10:06:12 AM - System Checkpoint
RP206: 5/26/2009 10:38:11 AM - System Checkpoint
RP207: 5/27/2009 2:02:21 PM - System Checkpoint
RP208: 5/28/2009 2:48:30 PM - System Checkpoint
RP209: 5/29/2009 2:58:14 PM - System Checkpoint
RP210: 5/30/2009 4:44:02 PM - System Checkpoint
RP211: 5/31/2009 6:35:21 PM - System Checkpoint
RP212: 6/1/2009 7:51:51 PM - System Checkpoint
RP213: 6/2/2009 9:37:39 PM - System Checkpoint
RP214: 6/3/2009 10:35:43 PM - System Checkpoint
RP215: 6/4/2009 11:15:23 PM - System Checkpoint
RP216: 6/6/2009 12:20:57 AM - System Checkpoint
RP217: 6/7/2009 12:31:58 AM - System Checkpoint
RP218: 6/8/2009 1:07:24 AM - System Checkpoint
RP219: 6/9/2009 2:07:30 AM - System Checkpoint
RP220: 6/10/2009 2:08:30 AM - System Checkpoint
RP221: 6/11/2009 3:07:31 AM - System Checkpoint
RP222: 6/12/2009 3:38:41 AM - System Checkpoint
RP223: 6/13/2009 4:43:26 AM - System Checkpoint
RP224: 6/14/2009 6:44:01 AM - System Checkpoint
RP225: 6/15/2009 7:30:34 AM - System Checkpoint
RP226: 6/16/2009 7:30:43 AM - System Checkpoint
RP227: 6/17/2009 8:31:47 AM - System Checkpoint
RP228: 6/18/2009 9:10:58 AM - System Checkpoint
RP229: 6/19/2009 9:12:02 AM - System Checkpoint
RP230: 6/20/2009 9:37:03 AM - System Checkpoint
RP231: 6/21/2009 11:24:05 AM - System Checkpoint
RP232: 6/22/2009 12:40:36 PM - System Checkpoint
RP233: 6/23/2009 5:47:23 PM - System Checkpoint
RP234: 6/24/2009 7:43:50 PM - System Checkpoint
RP235: 6/25/2009 11:01:49 PM - System Checkpoint
RP236: 6/26/2009 11:55:31 PM - System Checkpoint
RP237: 6/28/2009 12:11:22 AM - System Checkpoint
RP238: 6/29/2009 12:12:27 AM - System Checkpoint
RP239: 6/30/2009 1:12:30 AM - System Checkpoint
RP240: 7/1/2009 1:23:13 AM - System Checkpoint
RP241: 7/2/2009 2:16:16 AM - System Checkpoint
RP242: 7/3/2009 2:36:23 AM - System Checkpoint
RP243: 7/4/2009 3:18:09 AM - System Checkpoint
RP244: 7/5/2009 4:16:18 AM - System Checkpoint
RP245: 7/6/2009 5:16:16 AM - System Checkpoint
RP246: 7/7/2009 5:24:46 AM - System Checkpoint
RP247: 7/8/2009 6:17:11 AM - System Checkpoint
RP248: 7/9/2009 7:16:06 AM - System Checkpoint
RP249: 7/10/2009 8:16:10 AM - System Checkpoint
RP250: 7/11/2009 8:51:05 AM - System Checkpoint
RP251: 7/12/2009 10:21:36 AM - System Checkpoint
RP252: 7/13/2009 2:07:11 PM - System Checkpoint
RP253: 7/14/2009 5:41:18 PM - System Checkpoint
RP254: 7/15/2009 6:20:42 PM - System Checkpoint
RP255: 7/16/2009 8:16:00 PM - System Checkpoint
RP256: 7/17/2009 8:49:18 PM - System Checkpoint
RP257: 7/18/2009 7:36:39 PM - Installed Hitman Blood Money
RP258: 7/18/2009 7:52:32 PM - Installed DirectX
RP259: 7/18/2009 7:57:24 PM - Installed GameShadow
RP260: 7/19/2009 9:00:32 PM - System Checkpoint
RP261: 7/19/2009 10:40:42 PM - Installed Hitman Blood Money
RP262: 7/19/2009 10:41:31 PM - Removed GameShadow
RP263: 7/19/2009 10:43:23 PM - Removed Hitman Blood Money
RP264: 7/20/2009 10:41:45 PM - Installed Hitman Blood Money
RP265: 7/20/2009 10:51:17 PM - Installed DirectX
RP266: 7/20/2009 11:00:55 PM - Removed Hitman Blood Money
RP267: 7/21/2009 11:13:48 PM - System Checkpoint
RP268: 7/23/2009 12:57:21 AM - System Checkpoint
RP269: 7/24/2009 1:39:21 AM - System Checkpoint
RP270: 7/25/2009 2:13:41 AM - System Checkpoint
RP271: 7/26/2009 2:13:51 AM - System Checkpoint
RP272: 7/27/2009 3:13:48 AM - System Checkpoint
RP273: 7/28/2009 4:13:49 AM - System Checkpoint
RP274: 7/29/2009 5:22:37 AM - System Checkpoint
RP275: 7/30/2009 5:50:17 AM - System Checkpoint
RP276: 7/31/2009 6:50:10 AM - System Checkpoint
RP277: 8/1/2009 7:01:11 AM - System Checkpoint
RP278: 8/2/2009 7:01:45 AM - System Checkpoint
RP279: 8/3/2009 7:49:24 AM - System Checkpoint
RP280: 8/4/2009 8:49:26 AM - System Checkpoint
RP281: 8/5/2009 9:20:56 AM - System Checkpoint
RP282: 8/6/2009 9:49:21 AM - System Checkpoint
RP283: 8/7/2009 10:49:24 AM - System Checkpoint
RP284: 8/8/2009 10:52:58 AM - System Checkpoint
RP285: 8/9/2009 12:00:54 PM - System Checkpoint
RP286: 8/10/2009 12:30:20 PM - System Checkpoint
RP287: 8/11/2009 3:46:13 PM - System Checkpoint
RP288: 8/12/2009 3:59:56 PM - System Checkpoint
RP289: 8/13/2009 4:48:54 PM - System Checkpoint
RP290: 8/14/2009 5:50:38 PM - System Checkpoint
RP291: 8/15/2009 6:22:54 PM - System Checkpoint
RP292: 8/16/2009 7:11:42 PM - System Checkpoint
RP293: 8/17/2009 8:03:07 PM - System Checkpoint
RP294: 8/18/2009 8:12:45 PM - System Checkpoint
RP295: 8/19/2009 9:11:42 PM - System Checkpoint
RP296: 8/20/2009 9:35:39 PM - System Checkpoint
==== Installed Programs ======================
7-Zip 4.57
AAC Decoder
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1.2
AppCore
ATI - Software Uninstall Utility
ATI Parental Control
AutoUpdate
Backspin Billiards
ccCommon
Component Framework
Conexant D850 56K V.9x DFVc Modem
Data Lifeguard Diagnostic for Windows
Dell Resource CD
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
DVD Suite
ERUNT 1.1j
getPlus(R) for Adobe
H.264 Decoder
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
Java(TM) 6 Update 13
LiveUpdate (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
Modem Protector - Stops your PC calling unwanted numbers
Mozilla Firefox (3.0.13)
MSN
MSVC80_x86
MSXML 4.0 SP2 (KB954430)
Nero 7 Essentials
neroxml
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Norton AntiVirus
Norton AntiVirus Help
Norton AntiVirus Online (Symantec Corporation)
Norton Protection Center
PC Connectivity Solution
PowerDVD
Security Update for Windows Media Player (KB952069)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960714)
SigmaTel Audio
SPBBC 32bit
Spybot - Search & Destroy
Symantec Real Time Storage Protection Component
SymNet
Update for Windows XP (KB955839)
VC80CRTRedist - 8.0.50727.762
WebFldrs XP
Winamp
Windows Driver Package - Nokia Modem (05/22/2008 3.8)
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)
Windows Driver Package - Nokia Modem (06/01/2009 4.1)
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Essentials Media Codec Pack 2.2
Windows Genuine Advantage Notifications (KB905474)
Windows Media Format Runtime
Windows XP Service Pack 3
Xvid 1.1.3 final uninstall
==== End Of File ===========================
GMER
*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
GMER 1.0.15.15011 [gmer.exe] -
http://www.gmer.net
Rootkit scan 2009-08-21 08:46:42
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT 82AFE008 ZwAlertResumeThread
SSDT 82B03008 ZwAlertThread
SSDT 82B42008 ZwAllocateVirtualMemory
SSDT 8294C408 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xAACB5020]
SSDT 82C2FCD8 ZwCreateMutant
SSDT 82B046A0 ZwCreateThread
SSDT 82C1E6E8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xAACB52A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAACB5800]
SSDT spnt.sys ZwEnumerateKey [0xF8415CA2]
SSDT spnt.sys ZwEnumerateValueKey [0xF8416030]
SSDT 8293F380 ZwFreeVirtualMemory
SSDT 82C37200 ZwImpersonateAnonymousToken
SSDT 82ABB008 ZwImpersonateThread
SSDT 82AF26E0 ZwMapViewOfSection
SSDT 82C1A558 ZwOpenEvent
SSDT spnt.sys ZwOpenKey [0xF83F80C0]
SSDT 82A49290 ZwOpenProcessToken
SSDT 82C1E610 ZwOpenSection
SSDT 82AAAAF0 ZwOpenThreadToken
SSDT spnt.sys ZwQueryKey [0xF8416108]
SSDT spnt.sys ZwQueryValueKey [0xF8415F88]
SSDT 829C4140 ZwResumeThread
SSDT 82B8D008 ZwSetContextThread
SSDT 82AB1310 ZwSetInformationProcess
SSDT 82A8AED8 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAACB5A50]
SSDT 82C1D458 ZwSuspendProcess
SSDT 82B3C008 ZwSuspendThread
SSDT 82A76CD0 ZwTerminateProcess
SSDT 82B47008 ZwTerminateThread
SSDT 82A340F0 ZwUnmapViewOfSection
SSDT 82AB8008 ZwWriteVirtualMemory
INT 0x62 ? 82D74BF8
INT 0x63 ? 82D74BF8
INT 0x63 ? 82D74BF8
INT 0x63 ? 82D74BF8
INT 0x84 ? 82BE7BF8
INT 0x94 ? 82BE7BF8
INT 0xA4 ? 82BE7BF8
INT 0xB4 ? 82BE7BF8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2448 80501C80 4 Bytes CALL E2D2DE6B
? spnt.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F80468AC 5 Bytes JMP 82BE71D8
.text a0p32s6r.SYS F7DCC384 1 Byte [20]
.text a0p32s6r.SYS F7DCC384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text a0p32s6r.SYS F7DCC3AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text a0p32s6r.SYS F7DCC3C4 3 Bytes [00, 00, 00]
.text a0p32s6r.SYS F7DCC3C9 1 Byte [00]
.text ...
? C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[828] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\hkcmd.exe[1044] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\igfxpers.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Program Files\Etisalat Modem Protector\Modem Protector.exe[1192] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[1296] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text ...
.text C:\WINDOWS\system32\ctfmon.exe[2080] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2196] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2196] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\Internet Explorer\iexplore.exe[2576] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[2576] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\PC Connectivity Solution\ServiceLayer.exe[3056] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe[3116] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe[3144] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\WINDOWS\System32\svchost.exe[3228] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[3268] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[3268] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe[3672] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F83F9040] spnt.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F83F913C] spnt.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F83F90BE] spnt.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F83F97FC] spnt.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F83F96D2] spnt.sys
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
---- Devices - GMER 1.0.15 ----
Device 82D731F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device 82B14500
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{5D9E4213-3B81-4EA4-8778-2B34842E2707} 825BA1F8
Device \Driver\usbehci \Device\USBPDO-0 82BB91F8
Device \Driver\usbuhci \Device\USBPDO-1 82BE61F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 82DE11F8
Device \Driver\dmio \Device\DmControl\DmConfig 82DE11F8
Device \Driver\dmio \Device\DmControl\DmPnP 82DE11F8
Device \Driver\dmio \Device\DmControl\DmInfo 82DE11F8
Device \Driver\usbuhci \Device\USBPDO-2 82BE61F8
Device \Driver\usbuhci \Device\USBPDO-3 82BE61F8
Device \Driver\usbuhci \Device\USBPDO-4 82BE61F8
Device \Driver\PCI_PNP0338 \Device\00000055 spnt.sys
Device \Driver\PCI_PNP0338 \Device\00000055 spnt.sys
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\USBSTOR \Device\00000070 82905500
Device \Driver\Ftdisk \Device\HarddiskVolume1 82D751F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 82D751F8
Device \Driver\Cdrom \Device\CdRom0 82BA91F8
Device \Driver\Cdrom \Device\CdRom1 82BA91F8
Device \Driver\USBSTOR \Device\00000073 82905500
Device \Driver\Ftdisk \Device\HarddiskVolume3 82D751F8
Device \Driver\sptd \Device\3480291588 spnt.sys
Device \Driver\sptd \Device\3480291588 spnt.sys
Device \Driver\Ftdisk \Device\HarddiskVolume4 82D751F8
Device \Driver\Cdrom \Device\CdRom2 82BA91F8
Device \Driver\Ftdisk \Device\HarddiskVolume5 82D751F8
Device \Driver\USBSTOR \Device\00000075 82905500
Device \Driver\USBSTOR \Device\00000076 82905500
Device \Driver\NetBT \Device\NetBt_Wins_Export 825BA1F8
Device \Driver\NetBT \Device\NetbiosSmb 825BA1F8
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 82BE61F8
Device \Driver\usbuhci \Device\USBFDO-1 82BE61F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 82B90500
Device \Driver\usbuhci \Device\USBFDO-2 82BE61F8
Device \Driver\usbuhci \Device\USBFDO-3 82BE61F8
Device \Driver\usbehci \Device\USBFDO-4 82BB91F8
Device \Driver\Ftdisk \Device\FtControl 82D751F8
Device \Driver\a0p32s6r \Device\Scsi\a0p32s6r1Port3Path0Target0Lun0 82AE4340
Device \Driver\a0p32s6r \Device\Scsi\a0p32s6r1 82AE4340
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 82B12500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0x98 0xAE 0x7D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xA4 0xAB 0xB8 0x77 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0xEF 0x70 0x92 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0x98 0xAE 0x7D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xA4 0xAB 0xB8 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBF 0x91 0xED 0xF7 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0x98 0xAE 0x7D ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xA4 0xAB 0xB8 0x77 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0xEF 0x70 0x92 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECCEE0F8-2389-DBF0-CD44-27A089191EA6}
---- EOF - GMER 1.0.15 ----