gmer.... pt 1 of 3
GMER 1.0.13.12551 -
http://www.gmer.net
Rootkit scan 2007-11-09 01:27:06
Windows 6.0.6000
---- System - GMER 1.0.13 ----
SSDT \??\C:\Windows\system32\windrvNT.sys ZwCreateFile
SSDT \??\C:\Windows\system32\windrvNT.sys ZwOpenFile
SSDT \??\C:\Windows\system32\windrvNT.sys ZwQueryDirectoryFile
SSDT \??\C:\Windows\system32\windrvNT.sys ZwQueryInformationProcess
SSDT \??\C:\Windows\system32\windrvNT.sys ZwSetInformationFile
---- Kernel code sections - GMER 1.0.13 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 63A 81C8095E 2 Bytes [ 23, 83 ]
---- User IAT/EAT - GMER 1.0.13 ----
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[236] @ C:\Windows\system32\psapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [017B7376] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\Program Files\Mozilla Firefox\firefox.exe[696] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [017B73CC] C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [71E31923] C:\Windows\AppPatch\AcLayers.DLL
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\WINDOWS\System32\USERENV.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\WINDOWS\System32\Secur32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [71F44618] C:\Windows\system32\ShimEng.dll
IAT C:\WINDOWS\System32\rundll32.exe[1004] @ C:\WINDOWS\System32\SAMLIB.dll [KERNEL32.dll!GetProcAddress]